Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 19, 2010, 09:21:10 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373063
Posts
41378
Topics
94054
Members
Latest Member:
concon
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Leak Testing/Attacks/Vulnerability Research
Rootkit-driver install not intercepted?
« previous
next »
Poll
Question:
MOD NOTICE:
Since it could prove useful to specifically focus on the topic at hand,
all OT comments were splitted to
Re: Rootkit-driver install not intercepted?
0 (0%)
Please post OT comments there
0 (0%)
Total Voters: 0
Pages:
[
1
]
2
Author
Topic: Rootkit-driver install not intercepted? (Read 8708 times)
aigle
Comodo's Hero
Offline
Posts: 521
Rootkit-driver install not intercepted?
«
on:
August 01, 2008, 07:00:18 AM »
I tried to install a rootkit driver manually via w2k_loqd.exe. CFP gave SCM access alert. I denied it but driver seems to be loaded as shwon by rootrepeal. While EQS stops it from loading. Can anyone confirm. Thanks
Tested on a fresh snapshot of Eaz-Fix , XP Home SP2, no other security software installed at all. Fresh install of CFP with paranoid settings. Used shadowSurfer for testing though.
Logged
Vettetech
Guest
Re: Rootkit-driver install not intercepted?
«
Reply #1 on:
August 01, 2008, 07:07:09 AM »
What happens when you use "safe mode" and have remember checked off?
Logged
aigle
Comodo's Hero
Offline
Posts: 521
Re: Rootkit-driver install not intercepted?
«
Reply #2 on:
August 01, 2008, 07:14:28 AM »
I always checked off remember( snasphots of popups taken before that just on appearing of pop ups). Did not try safe mode but it must be same as safe mode is less secure or atleast same as paranoid.
Logged
Swordfish
Newbie
Offline
Posts: 14
Re: Rootkit-driver install not intercepted?
«
Reply #3 on:
August 02, 2008, 12:35:43 PM »
I have the same situation here (as I did comment on Wilders).
Here you go with some screenshots:
http://img363.imageshack.us/my.php?i...0199228vx2.jpg
http://img357.imageshack.us/my.php?i...7694241wa1.jpg
http://img80.imageshack.us/img80/5084/19469594ex6.jpg
http://img185.imageshack.us/img185/264/92335083pq3.jpg
http://img208.imageshack.us/img208/4665/32048945pf5.jpg
Regards,
a.
Logged
--
"Non quia difficilia sunt non audemus, sed quia non audemus, difficilia sunt."
Security setup: CIS + GesWall + SRWare Iron + Prevx + Avira...
HW setup: E4500 2.2[at]3.01 GHz rock solid w. Noctua NH-U12, Asus P5K, A-Data Extreme 1066, WD Raptor
aigle
Comodo's Hero
Offline
Posts: 521
Re: Rootkit-driver install not intercepted?
«
Reply #4 on:
August 02, 2008, 01:44:32 PM »
Thanks for confirming my findings.
Seems detection of service/ driver isntall/ loading is one of the areas where CFP needs to be improved a lot. Sadly I have not got any response from developers though I have post about atleast five threads where CFP seems to fail or seems buggy( 3 about driver loading/ install, one about physical memory access and one about file creation).
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2191
Re: Rootkit-driver install not intercepted?
«
Reply #5 on:
August 02, 2008, 01:52:58 PM »
Quote from: aigle on August 02, 2008, 01:44:32 PM
Sadly I have not got any response from developers though I have post about atleast five threads where CFP seems to fail or seems buggy( 3 about driver loading/ install, one about physical memory access and one about file creation).
Can you please put all of your proof of concepts into one archive and post here? And let me see what is going on..
Thx,
Egemen
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2191
Re: Rootkit-driver install not intercepted?
«
Reply #6 on:
August 02, 2008, 02:06:31 PM »
I am afraid i can not verify your finding. CFP is intercepting the attempts successfully. Plus, w2k_load.exe does not use any fancy techniques to load the drivers.
Well i am sure you are aware of the fact that, once you install and load a rootkit driver, the tests you perform later is meaningless.
You have to use a clean PC to see if your rootkit is loaded again. Once you load it, do not assume it is going to go away...
EDIT: I was using the development snapshot and hence could not verify the issue. The build 378 does have this bug in Windows XP. Just verified. It will be fixed with the planned release in a couple of weeks.
«
Last Edit: August 02, 2008, 02:37:37 PM by egemen
»
Logged
aigle
Comodo's Hero
Offline
Posts: 521
Re: Rootkit-driver install not intercepted?
«
Reply #7 on:
August 02, 2008, 04:20:26 PM »
Hi egemen, thanks for your confirmation.
Can you verify these three issues as well.
1- Driver install not intercepted
http://forums.comodo.com/leak_testingattacksvulnerability_research/d_give_a_great_alert_about_dns_trojan_dropper_test-t25570.0.html
http://www.wilderssecurity.com/showthread.php?t=216706
2- No alert for physical memory access
http://forums.comodo.com/leak_testingattacksvulnerability_research/phideexe_rootkit_bypassed_defence_plus-t25537.0.html
3- Wrong file creation alert
http://forums.comodo.com/leak_testingattacksvulnerability_research/false_file_creation_alert_is_ita_ghost_file_or_a_serious_bug-t25509.0.html
Thanks for your time
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2191
Re: Rootkit-driver install not intercepted?
«
Reply #8 on:
August 02, 2008, 07:05:02 PM »
Quote from: aigle on August 02, 2008, 04:20:26 PM
Hi egemen, thanks for your confirmation.
Can you verify these three issues as well.
1- Driver install not intercepted
http://forums.comodo.com/leak_testingattacksvulnerability_research/d_give_a_great_alert_about_dns_trojan_dropper_test-t25570.0.html
http://www.wilderssecurity.com/showthread.php?t=216706
2- No alert for physical memory access
http://forums.comodo.com/leak_testingattacksvulnerability_research/phideexe_rootkit_bypassed_defence_plus-t25537.0.html
3- Wrong file creation alert
http://forums.comodo.com/leak_testingattacksvulnerability_research/false_file_creation_alert_is_ita_ghost_file_or_a_serious_bug-t25509.0.html
Thanks for your time
2 is not a case. Please have a fresh XP instalation without any security software and try again. Vettech already posted screenshots. CFP intercepts and catches properly. But if you send me your version of the binary, i can verify again.
EDIT: I have just verified that this can happen in some computers. It is a rare bug. Fixed. Probably many other products have it.
3 there are many cases in which it can happen. CFP approves but later in the file system stack the request fails etc. It is not a serious issue or a bug.
«
Last Edit: August 02, 2008, 08:30:21 PM by egemen
»
Logged
aigle
Comodo's Hero
Offline
Posts: 521
Re: Rootkit-driver install not intercepted?
«
Reply #9 on:
August 02, 2008, 10:04:48 PM »
Hmmmm........ and what about no.1.
Many thanks
Logged
ailef
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 742
Re: Rootkit-driver install not intercepted?
«
Reply #10 on:
August 03, 2008, 02:47:32 AM »
some stupid question, what's your explorer setting in D+ ?
where to find this exploit?
Logged
xps M1330[at]T9500 - Windows 7 ultimate 64bit - comodo 3.13 build 574 - KAV 2010 build 736
aigle
Comodo's Hero
Offline
Posts: 521
Re: Rootkit-driver install not intercepted?
«
Reply #11 on:
August 03, 2008, 06:32:19 AM »
What is the relation of explorer in this driver install? Driver is loaded by windows installer, not explorer. Explorer has custom policy BTW.
Logged
ailef
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 742
Re: Rootkit-driver install not intercepted?
«
Reply #12 on:
August 03, 2008, 03:49:10 PM »
i ask that cause with explorer rule "windows system application", device driver installation is allowed.
update : i dled the file, aigle, thanks.
i don't have the same files like on the top of the topic, maybe u posted the wrong archive?
«
Last Edit: August 03, 2008, 04:07:12 PM by ailef
»
Logged
xps M1330[at]T9500 - Windows 7 ultimate 64bit - comodo 3.13 build 574 - KAV 2010 build 736
egemen
Administrator
Comodo's Hero
Offline
Posts: 2191
Re: Rootkit-driver install not intercepted?
«
Reply #13 on:
August 03, 2008, 08:08:59 PM »
Quote from: aigle on August 02, 2008, 10:04:48 PM
Hmmmm........ and what about no.1.
Many thanks
You can get the same alerts from CFP if you modify the policy. You can remove msiexec.exe from the default policy and CFP will just act like the hips you compare it.
However, there is something else there. A COM interface access. So asking the users about a legitimate system applications is not really a protection. MSIEXEC is DOING what it is supposed to do. COM interface access must be intercepted before the trojan controls msiexec service. So when we have time, we will analyze it and see what is going on.
Logged
aigle
Comodo's Hero
Offline
Posts: 521
Re: Rootkit-driver install not intercepted?
«
Reply #14 on:
August 04, 2008, 10:16:24 AM »
Quote from: egemen on August 03, 2008, 08:08:59 PM
You can get the same alerts from CFP if you modify the policy. You can remove msiexec.exe from the default policy and CFP will just act like the hips you compare it.
I removed all default rules/ policy for msiexec.exe and unfoirtunately no alerts for a driver install/ load. CFP does not at all behaves like other HIPS here.
See my thread here for some more explanation.
http://www.wilderssecurity.com/showthread.php?t=216750
Thanks
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.212 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com