Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 23, 2013, 09:45:50 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663843
Posts
70591
Topics
145225
Members
Latest Member:
rafacand
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
« previous
next »
Pages:
[
1
]
2
Author
Topic: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security (Read 9386 times)
gjf
Comodo Family Member
Offline
Posts: 58
Fuimus - non sumus... Carpe diem!
Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
on:
May 13, 2012, 07:57:27 AM »
I just found
some interesting article in Internet
. Looks like there is a way of overcoming HIPS in Comodo products. Author has contacted Comodo representatives already (about 5 months ago) and looks like there is no any reaction.
Is it possible to get some answer from authorities here?
Quote
Conclusions
To conclude with, weβd like to stress that we do not hate the Comodo HIPS product. The bypassing method presented in this post is rather remote and applies only on SysWoW64 ( 32bit ) applications running on a 64bit Windows version. Attached you will find a proof of concept application that automates the process of generating executable that can bypass the installation of hooks throughout the process address space. Thank you for reading.
Logged
VirusInfo
/
Defendium
/
VirusNet
Helpers Crew
RejZoR
Comodo's Hero
Offline
Posts: 1045
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #1 on:
May 13, 2012, 09:30:21 AM »
Only question here is, does this also include "Enhanced protection mode" (in Defense+) or only without it?
Logged
gjf
Comodo Family Member
Offline
Posts: 58
Fuimus - non sumus... Carpe diem!
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #2 on:
May 13, 2012, 09:37:32 AM »
The article includes compiled PoC and sources. You can check everything at your system and respond with results here.
Sorry - cannot help: have no x64 at home.
Logged
VirusInfo
/
Defendium
/
VirusNet
Helpers Crew
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3943
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #3 on:
May 13, 2012, 11:00:25 AM »
I'll test this out and let you know what I find.
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
Chiron
Global Moderator
Comodo's Hero
Online
Posts: 5581
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #4 on:
May 13, 2012, 12:42:25 PM »
Quote from: RejZoR on May 13, 2012, 09:30:21 AM
Only question here is, does this also include "Enhanced protection mode" (in Defense+) or only without it?
It looks like enhanced protection was introduced in
Version 5.8
, which was released on October 11, 2011.
Thus it was at least present in the program at the time.
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
RejZoR
Comodo's Hero
Offline
Posts: 1045
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #5 on:
May 13, 2012, 01:42:03 PM »
Well, present yes, but is disabled by default.
Logged
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3943
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #6 on:
May 13, 2012, 02:24:06 PM »
I can't reproduce it, sorry
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
Chiron
Global Moderator
Comodo's Hero
Online
Posts: 5581
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #7 on:
May 13, 2012, 02:37:53 PM »
Quote from: languy99 on May 13, 2012, 02:24:06 PM
I can't reproduce it, sorry
Do you mean that even under default settings you can't reproduce the bypass?
Logged
How To Install Comodo Firewall
How To Stay Safe While Online
languy99
Global Moderator
Comodo's Hero
Offline
Posts: 3943
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #8 on:
May 13, 2012, 02:42:22 PM »
Quote from: Chiron on May 13, 2012, 02:37:53 PM
Do you mean that even under default settings you can't reproduce the bypass?
yup, they did not include the keylogger to test with so I can't get it to work.
Logged
http://www.youtube.com/languy99
Software Reviews for all.
Follow me on Twitter
http://twitter.com/#!/languy99
gjf
Comodo Family Member
Offline
Posts: 58
Fuimus - non sumus... Carpe diem!
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #9 on:
May 13, 2012, 04:16:32 PM »
What do you mean "keylogger"? For what? The video was included in the article to present how to get process address space.
http://www.youtube.com/watch?v=Ar1SXYbKlm0
Logged
VirusInfo
/
Defendium
/
VirusNet
Helpers Crew
OmeletGuy
Back for a while.
Global Moderator
Comodo's Hero
Offline
Posts: 2905
Dragon Theme Maker
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #10 on:
May 13, 2012, 05:12:10 PM »
Quote from: gjf on May 13, 2012, 04:16:32 PM
What do you mean "keylogger"? For what? The video was included in the article to present how to get process address space.
http://www.youtube.com/watch?v=Ar1SXYbKlm0
Quote
This is the example POC program in action. sswhk.exe is a simple keylogger program. First run is the original program which gets detected by the paranoid security settings of Comodo. Next, the AddTLSSection.exe program is executed to generate the code required to bypass comodo.
A new program is created and executed sswhk_.exe and is successfully capturing keystrokes without comodo detecting it
.
Description of the video on YouTube. We would need sswhk.exe to test with, it is not included.
Logged
Comodo Dragon themes, including windows Aero options. Download
Here
System Details: W7-64bit | 4GB DDR2 | Intel Core 2 Extreme X6800 | CIS 5.10 | Geforce 560 GTX 1
gjf
Comodo Family Member
Offline
Posts: 58
Fuimus - non sumus... Carpe diem!
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #11 on:
May 13, 2012, 05:22:11 PM »
You can use any malware for this test. If you want a keylogger, you can try
a trial of Refog
as an instance.
Logged
VirusInfo
/
Defendium
/
VirusNet
Helpers Crew
loverboy
Comodo's Hero
Offline
Posts: 402
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #12 on:
May 14, 2012, 01:15:32 PM »
Quote from: blacknight
I'm not sure to have understood, Comodo HIPS doesn't install itself at the kernel level ? As EqSesure done.
Quote from: tomazyk
Not on 64 bit Windows. MS does not allow it. On 32 bit it does.
http://www.wilderssecurity.com/showthread.php?p=2055870#post2055870
Is this the reason of the "enhanced protection mode"?
Logged
Windows 7 Home Premium 64bit SP1
NOD32 Antivirus 4.2.71.2
COMODO CIS 5.10.228257.2253
Configuration: Proactive Security
Firewall Security Level: Custom Policy Mode
Defense+ Security Level: Clean PC Mode
Sandbox: Disabled
gjf
Comodo Family Member
Offline
Posts: 58
Fuimus - non sumus... Carpe diem!
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #13 on:
May 14, 2012, 01:49:04 PM »
Quote
Not on 64 bit Windows. MS does not allow it. On 32 bit it does.
Very interesting. So it means TDL4 installs itself in kernelmode at x64 in some mysterious way that none of vendors knows? Or possibly none of vendors can sign drivers in a correct way so Wx64 will allow to load it?
Will anybody from developers respond here or we still continue discussing nonsense?
Logged
VirusInfo
/
Defendium
/
VirusNet
Helpers Crew
vix123
Comodo Loves me
Offline
Posts: 110
2000 years old according to Comodo
Re: Why Usermode Hooking Sucks β Bypassing Comodo Internet Security
«
Reply #14 on:
May 15, 2012, 11:59:59 AM »
Quote from: gjf on May 14, 2012, 01:49:04 PM
Will anybody from developers respond here or we still continue discussing nonsense?
Unfortunately he is right. Perhaps the forum needs an advanced section where such issues can be discussed with a lower noise to signal ratio.
Logged
Windows XP /
Comodo
LITE
(just firewall and defense+ at 16% of the standard size, no antivirus, no clouds, no whitelists)
Tags:
usermode
cis
HIPS
bypassing
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback β CID
=====> Wishlist - CID
===> Help β CID
===> Bug Reports - CID
===> Beta Corner β CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback β CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback β PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Δesky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> PortuguΓͺs/Portuguese
===> RomΓ’nΔ / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> ΠΡΡΡΠΎΠΏ (OFFTOP)
=====> ΠΡΡ ΠΈΠ² / Archive
===> SlovenskΓ½ / Slovak
===> SlovenΕ‘Δina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Π£ΠΊΡΠ°ΡΠ½ΡΡΠΊΠ° / Ukrainian
===> Viα»t / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.048 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com