Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 20, 2013, 09:24:03 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663215
Posts
70507
Topics
145165
Members
Latest Member:
djrmbrider
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
« previous
next »
Pages:
1
[
2
]
3
4
...
13
Author
Topic: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown (Read 34908 times)
Budda
Comodo Loves me
Offline
Posts: 147
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #15 on:
August 10, 2009, 12:51:06 PM »
This is an old thread previously discussed.
http://forums.comodo.com/leak_testingattacksvulnerability_research/process_hacker_can_terminate_cis_processes_a_concern-t38772.0.html
Logged
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #16 on:
August 10, 2009, 01:14:53 PM »
Quote from: Budda on August 10, 2009, 12:51:06 PM
This is an old thread previously discussed.
http://forums.comodo.com/leak_testingattacksvulnerability_research/process_hacker_can_terminate_cis_processes_a_concern-t38772.0.html
I was unaware of this thread until last night, consequently, it is not old to me
. However, I still have the same question what is being done about it? Are the engineers of Comodo still working on a solution?
Peace.
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
OmeletGuy
Back for a while.
Global Moderator
Comodo's Hero
Offline
Posts: 2905
Dragon Theme Maker
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #17 on:
August 10, 2009, 01:17:55 PM »
Quote from: Jaki on August 10, 2009, 01:14:53 PM
I was unaware of this thread until last night, consequently, it is not old to me
. However, I still have the same question what is being done about it? Are the engineers of Comodo still working on a solution?
Peace.
Maybe V4 will have a fix, since it got the Behavior Blocker.
Logged
Comodo Dragon themes, including windows Aero options. Download
Here
System Details: W7-64bit | 4GB DDR2 | Intel Core 2 Extreme X6800 | CIS 5.10 | Geforce 560 GTX 1
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #18 on:
August 10, 2009, 01:21:36 PM »
Quote from: OmeletGuy on August 10, 2009, 01:17:55 PM
Maybe V4 will have a fix, since it got the Behavior Blocker.
I hope so. I'm keeping my fingers crossed while praying to God.
Peace.
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
Endymion
Comodo's Hero
Offline
Posts: 1362
Reality is subordinate to perception.
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #19 on:
August 10, 2009, 02:03:48 PM »
Quote from: Jaki on August 10, 2009, 12:35:49 PM
You probably forgot that Process Hacker is not a rogue application. It is an application that allows someone to test his or her security apparatus. How can you really test a security apparatus if you do not allow the testing application to be fully loaded.
Whenever not a rogue Process Hacker rely on a system driver to carry the termination.
The reason that security app can protect the user is the use of
such drivers which have more privileges that any unknown usermode (ring 3) application
.
Allowing a driver to be loaded mean that the driver will be able to obtain the same privileges/rights of the security software drivers.
Quote from: wj32 on July 23, 2009, 08:01:39 AM
More generally, it's impossible to stop kernel-code from doing whatever it wants, so the best way to stop it is by preventing it from loading.
As Process hacker developer noted, it would be possible to bypass any security using kernel drivers thus prevention ought to be carried by denying those drivers to be installed/loaded.
Whenever some other app may attempt to restart itself it is likely that a driver might be used to prevent this backup mechanism from occurring.
Though adding
\Device\KprocessHacker
to
My protected files
will provide a way to prevent termination, in order to use D+ properly it is important to be aware that driver install/loading should not be overlooked.
Indeed like for a termination driver it would unreasonable to allow a
kernel rootkit
and expect the system to be protected and this is the reason HIPSes focus on preventing these attempts...
«
Last Edit: August 10, 2009, 02:59:25 PM by Endymion
»
Logged
I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #20 on:
August 10, 2009, 03:00:19 PM »
Quote from: Endymion on August 10, 2009, 02:03:48 PM
Whenever not a rogue Process Hacker rely on a system driver to carry the termination.
The reason that security app can protect the user is the use of such kernel drivers which have more privileges that any unknown usermode application.
Allowing a driver to be loaded mean that the driver will be able to obtain the same privileges/rights of the security software drivers.
As Process hacker developer noted, it would be possible to bypass any security using kernel drivers thus prevention ought to be carried by denying those drivers to be installed/loaded.
Whenever some other app may attempt to restart itself it is likely that a driver may prevent this backup mechanism from occurring.
Though adding
\Device\KprocessHacker
to
My protected files
will provide a way to prevent termination, in order to use D+ properly it is important to be aware that driver install/loading should not be overlooked.
Indeed like for a termination driver it would unreasonable to allow a kernel rootkit and expect the system to be protected and this is the reason HIPSes focus on preventing these attempts...
It is not always true. While Hacker Process Kernel was fully loaded OSS 2009 did protect its core process. Howe could you explain that?
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 476
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #21 on:
August 10, 2009, 03:12:41 PM »
It's not important. I guess with little modifying of Process Hackers driver it could also kill OSS.
The weakness of CIS lies rather in its warning pop ups than in theoretically passing almost all leaktest like dangers. A pop up like services.exe or processhacker.exe wants to create registry keys bla bla is totally wrong for novice users. Kaspersky IS does it how it should be with red warning pop ups that explain what exactly happens and that KIS can't control the application's activity anymore once the driver is loaded.
Logged
Endymion
Comodo's Hero
Offline
Posts: 1362
Reality is subordinate to perception.
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #22 on:
August 10, 2009, 03:14:44 PM »
Quote from: Jaki on August 10, 2009, 03:00:19 PM
It is not always true. While Hacker Process Kernel was fully loaded OSS 2009 did protect its core process. Howe could you explain that?
AFAIK you claimed the core process "went back up right away". Does protect mean
restarting
that process?
«
Last Edit: August 10, 2009, 03:24:10 PM by Endymion
»
Logged
I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Endymion
Comodo's Hero
Offline
Posts: 1362
Reality is subordinate to perception.
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #23 on:
August 10, 2009, 03:18:50 PM »
Quote from: evil_religion on August 10, 2009, 03:12:41 PM
Kaspersky IS does it how it should be with red warning pop ups that explain what exactly happens and that KIS can't control the application's activity anymore once the driver is loaded.
CIS provide a
red warning alert too
and can also be configured to
control the application activity once the driver is loaded
. Eventually changing the description would be trivial.
«
Last Edit: August 10, 2009, 03:20:28 PM by Endymion
»
Logged
I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #24 on:
August 10, 2009, 03:22:02 PM »
Quote from: evil_religion on August 10, 2009, 03:12:41 PM
It's not important. I guess with little modifying of Process Hackers driver it could also kill OSS.
The weakness of CIS lies rather in its warning pop ups than in theoretically passing almost all leaktest like dangers. A pop up like services.exe or processhacker.exe wants to create registry keys bla bla is totally wrong for novice users. Kaspersky IS does it how it should be with red warning pop ups that explain what exactly happens and that KIS can't control the application's activity anymore once the driver is loaded.
I will test KIS 2010 tonight or tomorrow along with NIS 2010 and see how they will handle Process Hacker. Stay tune
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #25 on:
August 10, 2009, 03:29:43 PM »
Quote from: Endymion on August 10, 2009, 03:14:44 PM
AFAIK you claimed the core process "went back up right away". Does it mean that the protection was the
restart
of that process?
Yes indeed and it is not only that, when I Tried Process Hacker Terminator OSS core process did prevail. Also in order for me to make sure, I used regtest from Ghost Security. The first test was trying to modify some registry keys and I couldn't just like CIS in default deny mode, OSS did successfully defended the system. The only exception was that OSS core process was still alive.
Peace.
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #26 on:
August 10, 2009, 03:46:02 PM »
Thus far here are the applications that I have tested with Hacker Process:
CIS 3.10
OA Free 3.5
OSS 2009
Results:
CIS 3.10
All CIS processes were killed; However, CIS went to a default deny mode and successfully defended the system. I went to PCflank in order to test my ports and all of them were still stealth and I also perfromed regtest from Ghost security and I was not even able to run it. CIS successfully defended the system.
OA Free 3.5
OA free did put up a fight. Nonetheless, all its proccesses succombed to Process Hacker. My ports were not stealth anymore once OA processes were killed. I ran as well regtest and I was able to successfully modify some registry entries. But at the booting process OA caught the regtest and asked to delete it, and I did.
OSS 2009
OSS 2009 successfuly defended at least its core process, not the gui. In the end OSS 2009 core process prevailed and all my ports were still stealth and I was not able to run regtest.
OSS 2009 was the only security software that I have tested thus far to successfully defended its core process without my system being compromised.
Peace.
«
Last Edit: August 10, 2009, 07:25:43 PM by Jaki
»
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
Endymion
Comodo's Hero
Offline
Posts: 1362
Reality is subordinate to perception.
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #27 on:
August 10, 2009, 03:47:15 PM »
Quote from: Jaki on August 10, 2009, 03:29:43 PM
Yes indeed and it is not only that, when I Tried Process Hacker Terminator OSS core process did prevail. Also in order for me to make sure, I used regtest from Ghost Security. The first test was trying to modify some registry keys and I couldn't just like CIS in default deny mode, OSS did successfully defended the system. The only exception was that OSS core process was still alive.
Though restarting acs.exe to keep it
alive
would be pointless since that OSS 2009 core process was
killed
(and thereafter restarted unlike the OSS gui), wasn't it?
In the end restarting a killed core component is by no mean a protection against
what a Kernel driver could do
.
«
Last Edit: August 10, 2009, 05:16:51 PM by Endymion
»
Logged
I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #28 on:
August 10, 2009, 07:21:08 PM »
Quote from: Endymion on August 10, 2009, 03:47:15 PM
Though restarting acs.exe to keep it
alive
would be pointless since that OSS 2009 core process was
killed
(and thereafter restarted unlike the OSS gui), wasn't it?
In the end restarting a killed core component is by no mean a protection against
what a Kernel driver could do
.
No you've got it wrong. I did not restart it nor was the computer rebooted, the process itself restarted immediately and brought itself back to life on its own with no intervention whatsoever from me. As a matter of fact the point the test was to terminate all of OSS 2009 processes. The gui went dead while the core process was alive and well.
Peace
«
Last Edit: August 10, 2009, 07:30:30 PM by Jaki
»
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #29 on:
August 10, 2009, 07:35:30 PM »
Quote from: Endymion on August 10, 2009, 03:47:15 PM
Though restarting acs.exe to keep it
alive
would be pointless since that OSS 2009 core process was
killed
(and thereafter restarted unlike the OSS gui), wasn't it?
In the end restarting a killed core component is by no mean a protection against
what a Kernel driver could do
.
My very first post on this thread was to eventually ask for help. So in order to see what I'm talking about, please download virtualbox and perform the test yourself with OSS 2009 in order to verify my findings. That's what I wanted to do in the first place, to compare my results with someone else, whether they could be similar or different.
Peace.
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
Tags:
Pages:
1
[
2
]
3
4
...
13
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.054 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com