PDA

View Full Version : ThreatFire prevents against BufferOverflow- any other HIPS?


aigle
October 31st, 2007, 07:31 AM
See the screenshot from TF forums:

http://www.pctools.com/forum/showpost.php?p=171332&postcount=2

I wonder if anyother behave blocker/ HIPS prevents against buffer overflow. Has anybody tested TF or any other product against such type of threats.

I am not sure how I can test it.

What do u think about this?

Thanks

showtime33
October 31st, 2007, 02:17 PM
cant see the attactment unless you have a username and password for that forum....

aigle
October 31st, 2007, 02:25 PM
Ya, for ethical reasons I did not upload it here.
Snapshot is not from me, it,s from them.

Coolio10
October 31st, 2007, 07:17 PM
Comodo Memory Guardian was made for exactly that. It has proven working with .ANI cursors vulnerability in Vista and the Yahoo exploit. Here are pics the developer took himself of the yahoo exploit and .ani exploit.

bellgamin
October 31st, 2007, 09:57 PM
@Coolio- Thanks for posting the Memory Block screenshots. I note that both were executed against Internet Explorer. How about if I am using K-meleon browser (NEVER Internet Explorer - braaaack!)?

Will those same exploits affect K-mel?

aigle
November 1st, 2007, 01:38 AM
Coolio, thanks for nice pics.

solcroft
November 1st, 2007, 03:14 PM
The buffer overflow of TF needs work, TBH, as it currently fails against the ANI exploit (explorer.exe BO) and some common HTML shellcode exploits (IE BO). I've forwarded the relevent samples to the TF team, so let's see what they do about it.

Coolio10
November 1st, 2007, 04:31 PM
{QUOTE-> @Coolio- Thanks for posting the Memory Block screenshots. I note that both were executed against Internet Explorer. How about if I am using K-meleon browser (NEVER Internet Explorer - braaaack!)?

Will those same exploits affect K-mel? <-QUOTE}

KMel would probably not even be effected but cmg would be compatible with any browser as it is not a plugin.