Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 25, 2009, 03:59:46 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
345179
Posts
38110
Topics
86540
Members
Latest Member:
viruslover
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Leak Testing/Attacks/Vulnerability Research
Rootkit-driver install not intercepted?
« previous
next »
Poll
Question:
MOD NOTICE:
Since it could prove useful to specifically focus on the topic at hand,
all OT comments were splitted to
Re: Rootkit-driver install not intercepted?
0 (0%)
Please post OT comments there
0 (0%)
Total Voters: 0
Pages:
[
1
]
2
Author
Topic: Rootkit-driver install not intercepted? (Read 7646 times)
aigle
Comodo's Hero
Offline
Posts: 504
Rootkit-driver install not intercepted?
«
on:
August 01, 2008, 07:00:18 AM »
I tried to install a rootkit driver manually via w2k_loqd.exe. CFP gave SCM access alert. I denied it but driver seems to be loaded as shwon by rootrepeal. While EQS stops it from loading. Can anyone confirm. Thanks
Tested on a fresh snapshot of Eaz-Fix , XP Home SP2, no other security software installed at all. Fresh install of CFP with paranoid settings. Used shadowSurfer for testing though.
Logged
Vettetech
Guest
Re: Rootkit-driver install not intercepted?
«
Reply #1 on:
August 01, 2008, 07:07:09 AM »
What happens when you use "safe mode" and have remember checked off?
Logged
aigle
Comodo's Hero
Offline
Posts: 504
Re: Rootkit-driver install not intercepted?
«
Reply #2 on:
August 01, 2008, 07:14:28 AM »
I always checked off remember( snasphots of popups taken before that just on appearing of pop ups). Did not try safe mode but it must be same as safe mode is less secure or atleast same as paranoid.
Logged
Swordfish
Newbie
Offline
Posts: 14
Re: Rootkit-driver install not intercepted?
«
Reply #3 on:
August 02, 2008, 12:35:43 PM »
I have the same situation here (as I did comment on Wilders).
Here you go with some screenshots:
http://img363.imageshack.us/my.php?i...0199228vx2.jpg
http://img357.imageshack.us/my.php?i...7694241wa1.jpg
http://img80.imageshack.us/img80/5084/19469594ex6.jpg
http://img185.imageshack.us/img185/264/92335083pq3.jpg
http://img208.imageshack.us/img208/4665/32048945pf5.jpg
Regards,
a.
Logged
--
"Non quia difficilia sunt non audemus, sed quia non audemus, difficilia sunt."
Security setup: CIS + GesWall + SRWare Iron + Prevx + Avira...
HW setup: E4500 2.2[at]3.01 GHz rock solid w. Noctua NH-U12, Asus P5K, A-Data Extreme 1066, WD Raptor
aigle
Comodo's Hero
Offline
Posts: 504
Re: Rootkit-driver install not intercepted?
«
Reply #4 on:
August 02, 2008, 01:44:32 PM »
Thanks for confirming my findings.
Seems detection of service/ driver isntall/ loading is one of the areas where CFP needs to be improved a lot. Sadly I have not got any response from developers though I have post about atleast five threads where CFP seems to fail or seems buggy( 3 about driver loading/ install, one about physical memory access and one about file creation).
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2151
Re: Rootkit-driver install not intercepted?
«
Reply #5 on:
August 02, 2008, 01:52:58 PM »
Quote from: aigle on August 02, 2008, 01:44:32 PM
Sadly I have not got any response from developers though I have post about atleast five threads where CFP seems to fail or seems buggy( 3 about driver loading/ install, one about physical memory access and one about file creation).
Can you please put all of your proof of concepts into one archive and post here? And let me see what is going on..
Thx,
Egemen
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2151
Re: Rootkit-driver install not intercepted?
«
Reply #6 on:
August 02, 2008, 02:06:31 PM »
I am afraid i can not verify your finding. CFP is intercepting the attempts successfully. Plus, w2k_load.exe does not use any fancy techniques to load the drivers.
Well i am sure you are aware of the fact that, once you install and load a rootkit driver, the tests you perform later is meaningless.
You have to use a clean PC to see if your rootkit is loaded again. Once you load it, do not assume it is going to go away...
EDIT: I was using the development snapshot and hence could not verify the issue. The build 378 does have this bug in Windows XP. Just verified. It will be fixed with the planned release in a couple of weeks.
«
Last Edit: August 02, 2008, 02:37:37 PM by egemen
»
Logged
aigle
Comodo's Hero
Offline
Posts: 504
Re: Rootkit-driver install not intercepted?
«
Reply #7 on:
August 02, 2008, 04:20:26 PM »
Hi egemen, thanks for your confirmation.
Can you verify these three issues as well.
1- Driver install not intercepted
http://forums.comodo.com/leak_testingattacksvulnerability_research/d_give_a_great_alert_about_dns_trojan_dropper_test-t25570.0.html
http://www.wilderssecurity.com/showthread.php?t=216706
2- No alert for physical memory access
http://forums.comodo.com/leak_testingattacksvulnerability_research/phideexe_rootkit_bypassed_defence_plus-t25537.0.html
3- Wrong file creation alert
http://forums.comodo.com/leak_testingattacksvulnerability_research/false_file_creation_alert_is_ita_ghost_file_or_a_serious_bug-t25509.0.html
Thanks for your time
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2151
Re: Rootkit-driver install not intercepted?
«
Reply #8 on:
August 02, 2008, 07:05:02 PM »
Quote from: aigle on August 02, 2008, 04:20:26 PM
Hi egemen, thanks for your confirmation.
Can you verify these three issues as well.
1- Driver install not intercepted
http://forums.comodo.com/leak_testingattacksvulnerability_research/d_give_a_great_alert_about_dns_trojan_dropper_test-t25570.0.html
http://www.wilderssecurity.com/showthread.php?t=216706
2- No alert for physical memory access
http://forums.comodo.com/leak_testingattacksvulnerability_research/phideexe_rootkit_bypassed_defence_plus-t25537.0.html
3- Wrong file creation alert
http://forums.comodo.com/leak_testingattacksvulnerability_research/false_file_creation_alert_is_ita_ghost_file_or_a_serious_bug-t25509.0.html
Thanks for your time
2 is not a case. Please have a fresh XP instalation without any security software and try again. Vettech already posted screenshots. CFP intercepts and catches properly. But if you send me your version of the binary, i can verify again.
EDIT: I have just verified that this can happen in some computers. It is a rare bug. Fixed. Probably many other products have it.
3 there are many cases in which it can happen. CFP approves but later in the file system stack the request fails etc. It is not a serious issue or a bug.
«
Last Edit: August 02, 2008, 08:30:21 PM by egemen
»
Logged
aigle
Comodo's Hero
Offline
Posts: 504
Re: Rootkit-driver install not intercepted?
«
Reply #9 on:
August 02, 2008, 10:04:48 PM »
Hmmmm........ and what about no.1.
Many thanks
Logged
ailef
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 699
Re: Rootkit-driver install not intercepted?
«
Reply #10 on:
August 03, 2008, 02:47:32 AM »
some stupid question, what's your explorer setting in D+ ?
where to find this exploit?
Logged
xps M1330[at]T9500 - Windows 7 ultimate 64bit - comodo 3.13 build 574 - KAV 2010 build 736
aigle
Comodo's Hero
Offline
Posts: 504
Re: Rootkit-driver install not intercepted?
«
Reply #11 on:
August 03, 2008, 06:32:19 AM »
What is the relation of explorer in this driver install? Driver is loaded by windows installer, not explorer. Explorer has custom policy BTW.
Logged
ailef
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 699
Re: Rootkit-driver install not intercepted?
«
Reply #12 on:
August 03, 2008, 03:49:10 PM »
i ask that cause with explorer rule "windows system application", device driver installation is allowed.
update : i dled the file, aigle, thanks.
i don't have the same files like on the top of the topic, maybe u posted the wrong archive?
«
Last Edit: August 03, 2008, 04:07:12 PM by ailef
»
Logged
xps M1330[at]T9500 - Windows 7 ultimate 64bit - comodo 3.13 build 574 - KAV 2010 build 736
egemen
Administrator
Comodo's Hero
Offline
Posts: 2151
Re: Rootkit-driver install not intercepted?
«
Reply #13 on:
August 03, 2008, 08:08:59 PM »
Quote from: aigle on August 02, 2008, 10:04:48 PM
Hmmmm........ and what about no.1.
Many thanks
You can get the same alerts from CFP if you modify the policy. You can remove msiexec.exe from the default policy and CFP will just act like the hips you compare it.
However, there is something else there. A COM interface access. So asking the users about a legitimate system applications is not really a protection. MSIEXEC is DOING what it is supposed to do. COM interface access must be intercepted before the trojan controls msiexec service. So when we have time, we will analyze it and see what is going on.
Logged
aigle
Comodo's Hero
Offline
Posts: 504
Re: Rootkit-driver install not intercepted?
«
Reply #14 on:
August 04, 2008, 10:16:24 AM »
Quote from: egemen on August 03, 2008, 08:08:59 PM
You can get the same alerts from CFP if you modify the policy. You can remove msiexec.exe from the default policy and CFP will just act like the hips you compare it.
I removed all default rules/ policy for msiexec.exe and unfoirtunately no alerts for a driver install/ load. CFP does not at all behaves like other HIPS here.
See my thread here for some more explanation.
http://www.wilderssecurity.com/showthread.php?t=216750
Thanks
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.999 seconds with 21 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com