Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2013, 02:06:13 PM

Login with username, password and session length

664069 Posts
70633 Topics
145262 Members

Latest Member: EricNorris

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  Why Usermode Hooking Sucks – Bypassing Comodo Internet Security
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Why Usermode Hooking Sucks – Bypassing Comodo Internet Security  (Read 9405 times)
gjf
Comodo Family Member
***
Offline Offline

Posts: 58


Fuimus - non sumus... Carpe diem!


« on: May 13, 2012, 07:57:27 AM »

I just found some interesting article in Internet. Looks like there is a way of overcoming HIPS in Comodo products. Author has contacted Comodo representatives already (about 5 months ago) and looks like there is no any reaction.

Is it possible to get some answer from authorities here?

Quote
Conclusions

To conclude with, we’d like to stress that we do not hate the Comodo HIPS product. The bypassing method presented in this post is rather remote and applies only on SysWoW64 ( 32bit ) applications running on a 64bit Windows version. Attached you will find a proof of concept application that automates the process of generating executable that can bypass the installation of hooks throughout the process address space. Thank you for reading.
Logged

VirusInfo / Defendium / VirusNet Helpers Crew
RejZoR
Comodo's Hero
*****
Offline Offline

Posts: 1045


« Reply #1 on: May 13, 2012, 09:30:21 AM »

Only question here is, does this also include "Enhanced protection mode" (in Defense+) or only without it?
Logged
gjf
Comodo Family Member
***
Offline Offline

Posts: 58


Fuimus - non sumus... Carpe diem!


« Reply #2 on: May 13, 2012, 09:37:32 AM »

The article includes compiled PoC and sources. You can check everything at your system and respond with results here.

Sorry  - cannot help: have no x64 at home.
Logged

VirusInfo / Defendium / VirusNet Helpers Crew
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #3 on: May 13, 2012, 11:00:25 AM »

I'll test this out and let you know what I find.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
Chiron
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5589



« Reply #4 on: May 13, 2012, 12:42:25 PM »

Only question here is, does this also include "Enhanced protection mode" (in Defense+) or only without it?
It looks like enhanced protection was introduced in Version 5.8, which was released on October 11, 2011.

Thus it was at least present in the program at the time.
Logged

RejZoR
Comodo's Hero
*****
Offline Offline

Posts: 1045


« Reply #5 on: May 13, 2012, 01:42:03 PM »

Well, present yes, but is disabled by default.
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #6 on: May 13, 2012, 02:24:06 PM »

I can't reproduce it, sorry
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
Chiron
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5589



« Reply #7 on: May 13, 2012, 02:37:53 PM »

I can't reproduce it, sorry
Do you mean that even under default settings you can't reproduce the bypass?
Logged

languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



« Reply #8 on: May 13, 2012, 02:42:22 PM »

Do you mean that even under default settings you can't reproduce the bypass?

yup, they did not include the keylogger to test with so I can't get it to work.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
gjf
Comodo Family Member
***
Offline Offline

Posts: 58


Fuimus - non sumus... Carpe diem!


« Reply #9 on: May 13, 2012, 04:16:32 PM »

What do you mean "keylogger"? For what? The video was included in the article to present how to get process address space.

http://www.youtube.com/watch?v=Ar1SXYbKlm0
Logged

VirusInfo / Defendium / VirusNet Helpers Crew
OmeletGuy
Back for a while.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2905


Dragon Theme Maker


« Reply #10 on: May 13, 2012, 05:12:10 PM »

What do you mean "keylogger"? For what? The video was included in the article to present how to get process address space.

http://www.youtube.com/watch?v=Ar1SXYbKlm0

Quote
This is the example POC program in action. sswhk.exe is a simple keylogger program. First run is the original program which gets detected by the paranoid security settings of Comodo. Next, the AddTLSSection.exe program is executed to generate the code required to bypass comodo. A new program is created and executed sswhk_.exe and is successfully capturing keystrokes without comodo detecting it.

Description of the video on YouTube. We would need sswhk.exe to test with, it is not included.
Logged

Comodo Dragon themes, including windows Aero options. Download  Here

System Details: W7-64bit | 4GB DDR2 | Intel Core 2 Extreme X6800 | CIS 5.10 | Geforce 560 GTX 1
gjf
Comodo Family Member
***
Offline Offline

Posts: 58


Fuimus - non sumus... Carpe diem!


« Reply #11 on: May 13, 2012, 05:22:11 PM »

You can use any malware for this test. If you want a keylogger, you can try a trial of Refog as an instance.
Logged

VirusInfo / Defendium / VirusNet Helpers Crew
loverboy
Comodo's Hero
*****
Offline Offline

Posts: 402



« Reply #12 on: May 14, 2012, 01:15:32 PM »

Quote from: blacknight
I'm not sure to have understood, Comodo HIPS doesn't install itself at the kernel level ? As EqSesure done.
Quote from: tomazyk
Not on 64 bit Windows. MS does not allow it. On 32 bit it does.
http://www.wilderssecurity.com/showthread.php?p=2055870#post2055870

Is this the reason of the "enhanced protection mode"?
Logged

Windows 7 Home Premium 64bit SP1
NOD32 Antivirus 4.2.71.2
COMODO CIS 5.10.228257.2253
Configuration: Proactive Security
Firewall Security Level: Custom Policy Mode
Defense+ Security Level: Clean PC Mode
Sandbox: Disabled
gjf
Comodo Family Member
***
Offline Offline

Posts: 58


Fuimus - non sumus... Carpe diem!


« Reply #13 on: May 14, 2012, 01:49:04 PM »

Quote
Not on 64 bit Windows. MS does not allow it. On 32 bit it does.
Very interesting. So it means TDL4 installs itself in kernelmode at x64 in some mysterious way that none of vendors knows? Or possibly none of vendors can sign drivers in a correct way so Wx64 will allow to load it?

Will anybody from developers respond here or we still continue discussing nonsense?
Logged

VirusInfo / Defendium / VirusNet Helpers Crew
vix123
Comodo Loves me
****
Offline Offline

Posts: 110

2000 years old according to Comodo


« Reply #14 on: May 15, 2012, 11:59:59 AM »

Will anybody from developers respond here or we still continue discussing nonsense?

Unfortunately he is right. Perhaps the forum needs an advanced section where such issues can be discussed with a lower noise to signal ratio.
Logged

Tags: usermode  cis  HIPS  bypassing 
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.049 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com