Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 10, 2008, 10:46:38 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199105
Posts
22882
Topics
54913
Members
Latest Member:
goldilocks85
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
General Category
Which Product do you want Comodo to develop next?
Keylogger defeater
« previous
next »
Pages:
1
[
2
]
3
Author
Topic: Keylogger defeater (Read 6328 times)
Luketan
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 194
Re: Keylogger defeater
«
Reply #15 on:
May 08, 2008, 10:12:57 AM »
Quote from: andyman35 on May 08, 2008, 08:14:55 AM
The point about the inherent shortcomings of a prevention strategy had some validity though.The weakest point of such a method will always be the user that insists on running or installing 'abc.exe' or '123 codec' in order to run a game or video for example,despite warnings about unknown processes flashing up.
Examples are not always as clearcut as this. How about a security program, someone tells you is the newest hottest anti-rookit? You see warning about drivers installing and all that, but that's usual for this kind of program right?
How about a trusted software site being hacked and replaced with a trojanised copy (happened more than once before), or a case where something malicious accidently slipped into the code of a trusted updated program?
Also there is nothing inherently dangerous in an "unknown process". What is REALLY keying you off that something is wrong is not the "unknown" factor, but rather you are not expecting the process to run.
If you just double clicked a exe, there is nothing inherently dangerous about this "unknown process", after all you wanted it to run, so it runs.....
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 623
Re: Keylogger defeater
«
Reply #16 on:
May 08, 2008, 06:27:22 PM »
Quote from: panic on May 08, 2008, 08:24:51 AM
Categorically.
"To find out if something is truly fool-proof, first add a fool."
Quite so,I like that one
Logged
Thunderbear
Comodo Loves me
Offline
Posts: 180
The bears revenge = Thunder n Lightnin'
Re: Keylogger defeater
«
Reply #17 on:
May 08, 2008, 06:29:18 PM »
Do it fool-proof? We don't construct things for fools
Sry, I couldn't resist.
Logged
Don't be afraid, I'm very nice. Sometimes.
CFP 3.0.25, CMF 2.0.4, CBO 4.27, Avast 4.8.1229 (waiting for CAVS3), nLited XP3 Pro 32bit hidden behind a router.
Luketan
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 194
Re: Keylogger defeater
«
Reply #18 on:
May 11, 2008, 01:05:16 AM »
Quote from: Snowhawk on May 08, 2008, 06:29:18 PM
Do it fool-proof? We don't construct things for fools
Sry, I couldn't resist.
The problem with fools is that they are so 100% adamantly sure that they aren't fools...
Logged
Thunderbear
Comodo Loves me
Offline
Posts: 180
The bears revenge = Thunder n Lightnin'
Re: Keylogger defeater
«
Reply #19 on:
May 11, 2008, 02:40:26 AM »
Yes, indeed
Logged
Don't be afraid, I'm very nice. Sometimes.
CFP 3.0.25, CMF 2.0.4, CBO 4.27, Avast 4.8.1229 (waiting for CAVS3), nLited XP3 Pro 32bit hidden behind a router.
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3792
Sometimes words are meaningless indeed...
Re: Keylogger defeater
«
Reply #20 on:
May 11, 2008, 03:29:17 AM »
Quote from: Euripides
Talk sense to a fool and he calls you foolish.
«
Last Edit: May 11, 2008, 03:47:23 AM by gibran
»
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
Luketan
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 194
Re: Keylogger defeater
«
Reply #21 on:
May 11, 2008, 07:01:44 AM »
Quote from: Snowhawk on May 11, 2008, 02:40:26 AM
Yes, indeed
Well, the nice thing of not being a "moderator" or "hero" is that one doesn't have to pretend that he knows everything or is always right....
It's smart to be a bit unsure, which explains why i'm unsure if i will definitely be up to using complex hips like D+ correctly.... Compare it to the attitudes of the people in this thread, who love to thumb their noses down at people who they consider "fools" because they express doubt...
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5469
... and I say to myself, "What a wonderful world"
Re: Keylogger defeater
«
Reply #22 on:
May 11, 2008, 07:21:42 AM »
[at] luketan,
I think you may have misunderstood me. When I said
Quote
"To find out if something is truly fool-proof, first add a fool."
I was not implying that anyone was a fool, merely that no matter how well designed a product is (software, car, coffee grinder or whatever), there are always the unforseen circumstances that will arise when that product is used in an uncontrolled environment.
A lot of things work perfectly in the lab, but fail when used in the real world. This real world failure may be due to a design flaw not detected or predicted in the lab. Alternatively it could be caused by an unexpected mode of operation. Neither of these makes the user a fool.
OK?
edit : minor typo
«
Last Edit: May 11, 2008, 07:23:21 AM by panic
»
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3792
Sometimes words are meaningless indeed...
Re: Keylogger defeater
«
Reply #23 on:
May 11, 2008, 08:31:12 AM »
As for me I simply reworded Luketan sentence:
Quote from: Luketan on May 11, 2008, 01:05:16 AM
The problem with fools is that they are so 100% adamantly sure that they aren't fools...
which share the same meaning as
Quote from: Euripides
Talk sense to a fool and he calls you foolish.
Anyway all forum members should know by now that
Luketan
usually is much more willing to point out something to blame than engage in an honest and profitable discussion.
that's why anyone can often read something like this in his posts:
Quote from: Luketan on May 11, 2008, 07:01:44 AM
Well, the nice thing of not being a "moderator" or "hero" is that one doesn't have to pretend that he knows everything or is always right....
As for what panic posted I guess Luketan should be able to agree if he wrote :
Quote from: Luketan on May 04, 2008, 10:44:43 AM
Well honestly i think most security software are quite useless if you know what you are doing.
Anyway if we really have to contuinue further this OT I guess it would be useful to split this thread in two-three new ones.
«
Last Edit: May 11, 2008, 09:03:59 AM by gibran
»
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
tetsuo55
Comodo Family Member
Offline
Posts: 88
Tweaking windows for Security,Stability and Speed
Re: Keylogger defeater
«
Reply #24 on:
August 14, 2008, 09:24:00 AM »
I too think that comodo should have dedicated anti-keylogging, i think as part of the firewall.
It should have a list of known keyloggers, and detect any and all activity(on all levels) that looks like keylogging/screenshots.
Thers is a method of keylogging that can easiliy bypass every protection on the market that i currently know of
Script uses unknown exploit in browser, exploit allows script to run keylogger as part of the browser. Keylogging data is sent together with www data to keylogger creator. There is currently no way to block this behaviour other than parsing out the bad script before it reaches the browser.
Because all this happens in memory without any hooks, all the correct priveladges and no files being modified this easiliy slips pasts hips like defence+
NB: i don't have any actual samples of this kind of attack
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 623
Re: Keylogger defeater
«
Reply #25 on:
August 14, 2008, 10:19:14 AM »
Quote from: tetsuo55 on August 14, 2008, 09:24:00 AM
I too think that comodo should have dedicated anti-keylogging, i think as part of the firewall.
It should have a list of known keyloggers, and detect any and all activity(on all levels) that looks like keylogging/screenshots.
Thers is a method of keylogging that can easiliy bypass every protection on the market that i currently know of
Script uses unknown exploit in browser, exploit allows script to run keylogger as part of the browser. Keylogging data is sent together with www data to keylogger creator. There is currently no way to block this behaviour other than parsing out the bad script before it reaches the browser.
Because all this happens in memory without any hooks, all the correct priveladges and no files being modified this easiliy slips pasts hips like defence+
NB: i don't have any actual samples of this kind of attack
Do you have any links to information about this malware? You say it defeats all known methods to block the behaviour however the use of something like Keyscrambler,which encrypts the keystrokes before they reach the browser,would mean that all it'd 'log' would be scrambled data.It seems to me that something similar should be added to CFP,rather than attempting to detect loggers after the fact.
«
Last Edit: August 14, 2008, 10:23:25 AM by andyman35
»
Logged
tetsuo55
Comodo Family Member
Offline
Posts: 88
Tweaking windows for Security,Stability and Speed
Re: Keylogger defeater
«
Reply #26 on:
August 14, 2008, 10:26:05 AM »
Quote from: andyman35 on August 14, 2008, 10:19:14 AM
Do you have any links to information about this malware? You say it defeats all known methods to block the behaviour however the use of something like Keyscrambler,which encrypts the keystrokes before they reach the browser,would mean that all it'd 'log' would be random data.It seems to me that something similar should be added to CFP,rather than attempting to detect loggers after the fact.
Sorry i don't have any links, its information i gathered from several forums especially wilderssecurity.
i'm not even sure if a proof-of-concept actually exists for it.
Keyscrambler works on a certain level, many tests/forumposts have revealed taht keyscrambler can be bypassed to get the real keys. There is a working proof of concept, its called "how to impress girls vista" or something google it.
The exploit loads a malware into ram, regardless of user rights the malware will have admin rights, admin rights ARE needed to defeat keyscrambler (i doubt a limited running malware can defeat keyscrambler)
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 623
Re: Keylogger defeater
«
Reply #27 on:
August 14, 2008, 10:30:02 AM »
Another great way to defeat keyloggers is to use Neo's Safekeys when entering sensitive data.It's portable too ideal for using in internet cafes
http://www.aplin.com.au/?page_id=246
Logged
tetsuo55
Comodo Family Member
Offline
Posts: 88
Tweaking windows for Security,Stability and Speed
Re: Keylogger defeater
«
Reply #28 on:
August 14, 2008, 12:20:43 PM »
Quote from: andyman35 on August 14, 2008, 10:30:02 AM
Another great way to defeat keyloggers is to use Neo's Safekeys when entering sensitive data.It's portable too ideal for using in internet cafes
http://www.aplin.com.au/?page_id=246
that won't be able to defeat hardware loggers
Logged
andyman35
Global Moderator
Comodo's Hero
Offline
Posts: 623
Re: Keylogger defeater
«
Reply #29 on:
August 14, 2008, 02:02:51 PM »
Quote from: tetsuo55 on August 14, 2008, 12:20:43 PM
that won't be able to defeat hardware loggers
Since you're not using the physical keyboard to enter the data there'd be nothing for the logger to log so it'll certainly make those redundant.Anyway hardware loggers are a different issue,since we're concerned in this case with preventing generic malware rather than specifically targetted attacks.I have to say though that there are a lot of 'proof of concept' threats brought to the attention at various black hat conferences,etc.The majority tend to be impractical in a real world situation,where there are so many more variables.Having said that it's always a good idea to take notice of these things...just in case
«
Last Edit: August 14, 2008, 02:07:40 PM by andyman35
»
Logged
Tags:
Pages:
1
[
2
]
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.19 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com