View Full Version : defeating GSS
Devil's Advocate
October 11th, 2006, 07:02 AM
I notice the new morgud test makes a mickey out of GSS by using faked mouse clicks to kill GSS. Not that only GSS is vulnerable (they list a lot of your competitors as well), but they showcase GSS on the website with screenshots.
http://www.morgud.com/interests/security/dfk-threat-simulator-v2.asp
Any plans on adding a password option? That should handle the mouse click problems
I notice that they can beat PG even if you lock it, cos it is able to replace the files. It works for GSS too. Any defense to that? Or is it beyond the job scope of GSS ~snip~?
sukarof
October 11th, 2006, 08:10 AM
-{ Quote: "I notice the new morgud test makes a mickey out of GSS by using faked mouse clicks to kill GSS. Not that only GSS is vulnerable (they list a lot of your competitors as well), but they showcase GSS on the website with screenshots.
http://www.morgud.com/interests/security/dfk-threat-simulator-v2.asp
Any plans on adding a password option? That should handle the mouse click problems
I notice that they can beat PG even if you lock it, cos it is able to replace the files. It works for GSS too. Any defense to that? Or is it beyond the job scope of GSS and PG?" }-
I dont see the need for GSS add anything because of that simulator. Or maybe you could explain how I do the mouseclicks so that GSS gets terminated? As I posted here http://www.wilderssecurity.com/showthread.php?p=855827#post855827
-{ Quote: "I did a test with this simulator with Ghost Security Suite and I do not agree that it will bypass GSS.
I allowed the execution of Ipod-commercial.exe but on the next catch by GSS when it tried to create the projector.exe I denied and that stopped the intrusion. Of course if I let it run the temp file it will start the intrusion. So imo GSS passed since it catched the intial process creation. If I want the intrusion to happen I have to allow alot of popups from GSS." }-
Devil's Advocate
October 11th, 2006, 08:25 AM
Your reasoning is strange
-{ Quote: "
I allowed the execution of Ipod-commercial.exe but on the next catch by GSS when it tried to create the projector.exe I denied and that stopped the intrusion. Of course if I let it run the temp file it will start the intrusion. So imo GSS passed since it catched the intial process creation.
" }-
Don't tell me you belong to the school of through that believes execution control is the be all and end all of everything. Clearly the test isn't one about process creation or execution.
BTW The fact that it starts a second process is incidental it could easily have done all the dirty work without starting another process.
Anyway if you believe that all that is needed is for the app to provide protection is to stop any unwanted process from running, one wonders why you use a software that blocks process termination, changes to registry and dozen of other changes.
Surely this means that there is an expection for your security program to mitigate damage done by any malicious exe. The fact that it can be taken down so easily isn't a problem to you, really?
When the cure (or at least one of them) is so easy?
Bubba
October 11th, 2006, 08:34 AM
-{ Quote: "Or is it beyond the job scope of GSS and PG?" }-To all:
As this is not the support forum for PG....let's confine our discussion as it relates to GSS only Please....otherwise We'll need to move this thread to a more appropriate forum for that discussion.
Thanks,
Bubba
yankinNcrankin
October 11th, 2006, 01:29 PM
LOL is all I got to say. Oh wait theres more, I downloaded dfk unlocked it then ran the Ipod-commercial.exe GSS flagged it and I didnt run it. I guess any moron would initially download a exe file and put full trust in it and run it before scanning. My point, I would never let anything execute if it got flagged by my scans or I did'nt recognize the file, hence nothing starts nothing happens, and if it does then simple restore is in order. GSS gets breached simply cuz you allow it to, after testing this further It took 4 allowed executions for it to tickle my system. Show me some real life examples of GSS getting breached or bypassed with out having to allow executions then we can have a debate about GSS being made a MICKEY
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums