Wilders Security Forums  

Go Back   Wilders Security Forums > Security Software > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 1st, 2008, 05:51 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,351
Default Try your anti-keylogger protection

I tried some interesting POCs from here:

http://www.zemana.com/list/list.asp?ktgr_id=413

My observations:

CFP

Key Logger Simulation Test - - - - - PASS
Screen-Logger Simulation Test - - - PASS
Webcam Logger Simulation Test - - PASS
Clipboard Logger Simulation Test - - FAIL
SSL Logger Simulation Test - - - - - POC not Available so far

EQSecure

Key Logger Simulation Test - - - - - PASS
Screen-Logger Simulation Test - - - FAIL
Webcam Logger Simulation Test - - FAIL
Clipboard Logger Simulation Test - - FAIL
SSL Logger Simulation Test - - - - - POC not Available so far

GesWall

Key Logger Simulation Test - - - - - PASS
Screen-Logger Simulation Test - - - FAIL
Webcam Logger Simulation Test - - PASS
Clipboard Logger Simulation Test - - FAIL
SSL Logger Simulation Test - - - - - POC not Available so far

SafeSpace

Key Logger Simulation Test - - - - - PASS
Screen-Logger Simulation Test - - - PASS
Webcam Logger Simulation Test - - PASS
Clipboard Logger Simulation Test - - PASS
SSL Logger Simulation Test - - - - - POC not Available so far


OA Free Run Safer

All FAIL

ThretFire

All FAIL ( Solcroft! I know what u will say and I understand and agree with you to some extent, though not fully).

Have fun!!

Anyone can try:

ProSecurity
DefenceWall
SSM
SBIE

Thanks

Edit: I have edited the reults, there were some wrong copy/ paste before.
Attached Images
 
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!

Last edited by aigle : April 1st, 2008 at 06:08 PM.
  #2  
Old April 1st, 2008, 06:04 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,058
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by aigle
OA Free Run Safer

All FAIL
LUA's kicking some ass
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #3  
Old April 1st, 2008, 08:36 PM
subset's Avatar
subset subset is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Austria
Posts: 765
Default Re: Try your anti-keylogger protection

Hi,

"You can repeat the same test by installing Zemana Antilogger into your system."
Anti Logger License Purchasing: 1 user License 39.50 USD
"Zemana AntiLogger, with its proactive protection method provides you real time , powerful protection."

Has anyone tested Zemana AntiLogger against a real keylogger?
Or does it just pass their own tests?

Cheers
__________________
"Free thought can't be bought" States Of Mind - Senser
  #4  
Old April 1st, 2008, 08:44 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,351
Default Re: Try your anti-keylogger protection

http://www.wilderssecurity.com/showp...2&postcount=64
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #5  
Old April 1st, 2008, 08:51 PM
farmerlee's Avatar
farmerlee farmerlee is offline
Very Frequent Poster
 
Join Date: Jul 2006
Posts: 2,401
Default Re: Try your anti-keylogger protection

Keyscrambler passes the keylogger simulation test.
__________________
HP Elite 190A
Windows 7 Home Premium 64 bit
  #6  
Old April 1st, 2008, 08:56 PM
CogitoErgoSum's Avatar
CogitoErgoSum CogitoErgoSum is offline
Frequent Poster
 
Join Date: Aug 2005
Location: Cerritos, California
Posts: 641
Default Re: Try your anti-keylogger protection

Under Vista 32 SP1:

DefenseWall v2.30

Key-Logger Simulation Test - Pass(*Note: Detected and gave me the option to terminate this test on the spot via the pop-up notification.)
Screen-Logger Simulation Test - Pass(*Note: Blocked silently.)
WebCam-Logger Simulation Test - Tentative Pass(*Note: Although, I do not have a webcam, I ran this test anyway and observed in DW's log that all attempts to make changes to the registry were blocked silently.)
Clipboard-Logger Simulation Test - ?(*Note: Does not appear to work when run as "untrusted". I will have to get Ilya to look at this particular test.)




Peace & Gratitude,

CogitoErgoSum
__________________
Current Vista 32 SP2 Resident Security Arsenal: (DefenseWall Personal Firewall v3.00 - KeyScrambler Pro)

DefenseWall HIPS(http://www.softsphere.com/)

*Loyal & diehard DefenseWall user since 1/06!*
~Living dangerously without a resident antivirus since late 2/07!~

Last edited by CogitoErgoSum : April 2nd, 2008 at 09:34 AM.
  #7  
Old April 1st, 2008, 09:07 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,351
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by CogitoErgoSum
WebCam-Logger Simulation Test - Tentative Pass(*Note: Although, I do not have a webcam, I ran this test anyway and observed in DW's log that all attempts to make changes to the registry were blocked silently.)
It will be best to have this test done with a web cam I think. The only way to know.

Thanks for the reults.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #8  
Old April 1st, 2008, 10:32 PM
solcroft solcroft is offline
Very Frequent Poster
 
Join Date: Jun 2006
Posts: 1,654
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by aigle
Solcroft! I know what u will say and I understand and agree with you to some extent, though not fully.
Actually, no I won't. You know the facts, and I'm beginning to sound like a broken record anyway.

I test with real malware. POCs are to behavior blockers what the EICAR test file is to antivirus software: just a weak replacement used by sissies who feel the need to trick themselves into thinking they're doing any meaningful tests. But I'm sure you already know that.
  #9  
Old April 2nd, 2008, 04:01 AM
Huupi Huupi is offline
Very Frequent Poster
 
Join Date: Sep 2006
Posts: 2,020
Default Re: Try your anti-keylogger protection

Simple as that,most all reputable antimalwares are smarter the n the users of these fakes. LOL
  #10  
Old April 2nd, 2008, 05:23 AM
Ilya Rabinovich Ilya Rabinovich is offline
Developer
 
Join Date: Sep 2005
Posts: 1,290
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by CogitoErgoSum
Clipboard-Logger Simulation Test - ?
Had no problems with it.

As about webcam- I still didn't made my mind if need to implement it. The reason is following: there are too many software nowadays (ICQ and other popular IM software, Skype and other VoIP clients) that are using webcam. Not sure if I need alert on each of it as it is impossible to automatically block it out. Also, in future, more and more software will be using webcams in order to improve its functionality. So- I'm in doubts about this point. Is it really about security?
__________________
DefenseWall HIPS developer. www.softsphere.com
  #11  
Old April 2nd, 2008, 05:12 PM
zopzop's Avatar
zopzop zopzop is offline
Frequent Poster
 
Join Date: Apr 2006
Posts: 575
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by lucas1985
LUA's kicking some ass

SRP for the win!!!!!1111
__________________
Current Security Apps -
Desktop/Laptop : SRP + LUA + KAFU, Antivir (free - on demand)

LUA+SRP+KAFU = WIN!!!111
  #12  
Old April 2nd, 2008, 07:33 PM
GES/POR's Avatar
GES/POR GES/POR is offline
Very Frequent Poster
 
Join Date: Nov 2006
Location: Armacham
Posts: 1,431
Default Re: Try your anti-keylogger protection

Can anyone test Bufferzone,Prevx and Sandboxie please.
  #13  
Old April 2nd, 2008, 10:29 PM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,253
Default Re: Try your anti-keylogger protection

With the keylogger test press alt+1, alt+2, alt+3 using the num pad on the right side of the keyboard for the numbers.

You should get ☺, ☻, and ♥ yet the keylogger shows 1, 2 and 3.

What does this mean? Don't know, just posting as a quirk that may fool some keyloggers maybe.

Sandboxie doesn't stop keylogging but they can't send that data out over the net when SB is configured for only your browser to connect out.
Alt Key Codes
__________________
Bestest Freebies - Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil, MS Virtual PC 2007, Ghost Images
  #14  
Old April 2nd, 2008, 11:01 PM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 4,238
Default Re: Try your anti-keylogger protection

Why exclude SSM & ProSecurity?

P.S. I have the same attitude toward sandboxes as does my cat.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #15  
Old April 2nd, 2008, 11:33 PM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,253
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by bellgamin
P.S. I have the same attitude toward sandboxes as does my cat.
Smart cat ya got there knowing where all the crap ends up.
__________________
Bestest Freebies - Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil, MS Virtual PC 2007, Ghost Images
  #16  
Old April 3rd, 2008, 01:04 AM
solcroft solcroft is offline
Very Frequent Poster
 
Join Date: Jun 2006
Posts: 1,654
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by Franklin
Sandboxie doesn't stop keylogging but they can't send that data out over the net when SB is configured for only your browser to connect out.
A common misconception. Sandboxie cannot stop keyloggers from manipulating your browser process and use it to connect out.
  #17  
Old April 3rd, 2008, 02:42 AM
Huupi Huupi is offline
Very Frequent Poster
 
Join Date: Sep 2006
Posts: 2,020
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by solcroft
A common misconception. Sandboxie cannot stop keyloggers from manipulating your browser process and use it to connect out.

Solcroft, Should i ditch Sandboxie because of this,or should i trust Tsuk who is actually saying that no data can escape,if configured right ?

Can you explain a bit how this can happen ?

AFAIK if the keylogger rename itself to akin like your browser,SBIE is aware of this and denies connection.

But maybe there other ways to lure SBIE in allowing connections.i dont know.

So angry waiting to teach us.

edit : none of my security fires up if i click keylogger exe,smart enough to distinguish !

Last edited by Huupi : April 3rd, 2008 at 02:53 AM.
  #18  
Old April 3rd, 2008, 03:01 AM
solcroft solcroft is offline
Very Frequent Poster
 
Join Date: Jun 2006
Posts: 1,654
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by Huupi
Solcroft, Should i ditch Sandboxie because of this,or should i trust Tsuk who is actually saying that no data can escape,if configured right ?
All I'm saying that your claim was inaccurate. And now that you know that, what you choose to do with that knowledge is your own business.

But right now, I'm trying very hard not to laugh. Oh wow, something's not absolutely flawlessly perfect, it needs to be ditched. You believed it was impenetrable just because some stranger over the Internet said so, and now you're asking another stranger if you need to ditch it. Seriously: grow up.

Quote:
Originally Posted by Huupi
Can you explain a bit how this can happen ?
Like I said, run the leaktests and see for yourself. I did it some while ago, but WB3 was one of those that broke past Sandboxie IIRC. So all a keylogger would need to do is to use the same connection techniques as the leaktests do, and there you go.
  #19  
Old April 3rd, 2008, 03:15 AM
arran's Avatar
arran arran is offline
Frequent Poster
 
Join Date: Feb 2008
Posts: 980
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by solcroft
A common misconception. Sandboxie cannot stop keyloggers from manipulating your browser process and use it to connect out.


are you saying that keyloggers inside the sandbox can take over your browser and use the browser to connect out?

wouldn't a good hips prevent a key logger from taking over your browser ?
  #20  
Old April 3rd, 2008, 03:18 AM
solcroft solcroft is offline
Very Frequent Poster
 
Join Date: Jun 2006
Posts: 1,654
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by arran
are you saying that keyloggers inside the sandbox can take over your browser and use the browser to connect out?
Yes.

Quote:
Originally Posted by arran
wouldn't a good hips prevent a key logger from taking over your browser ?
No, the HIPS won't do that. It will, however, give the smart user an opportunity to stop that from happening.
  #21  
Old April 3rd, 2008, 03:42 AM
arran's Avatar
arran arran is offline
Frequent Poster
 
Join Date: Feb 2008
Posts: 980
Default Re: Try your anti-keylogger protection

hmm well the only ways I can think of to stop keyloogers inside sandboxie.

1. use mvps hosts file and hopefully the keyloggers server is on mvps hosts file
filter list.

2. allways clean out sandboxie before go to log into your online bank or any other login place.

3. hopefully your hips will give you a popup warning to block the keylogger from taking over your browser.

Edit Actually you should be able to configure your hips to monitor your browser
inside sandboxie.

any one know of any other ways??

Last edited by arran : April 3rd, 2008 at 03:50 AM.
  #22  
Old April 3rd, 2008, 05:46 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 9,351
Default Re: Try your anti-keylogger protection

Quote:
Originally Posted by Franklin
Sandboxie doesn't stop keylogging but they can't send that data out over the net when SB is configured for only your browser to connect out.
[/url]
It might not be so straight forward. I guess that data can be sent just by loading a dll into ur browser. SBIE will not complain at all. Just a guess, I may be wrong though.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine
Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun.

I am waiting for a pop up HIPS for Ubuntu!
  #23  
Old April 3rd, 2008, 06:42 AM
Stijnson's Avatar
Stijnson Stijnson is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Paranoia Heaven
Posts: 533
Default Re: Try your anti-keylogger protection

How are keyloggers typically 'installed' on ones system? Is there one specific method or do they come in all sizes and manners?
How can one protect his system (apart from the usual AV/AS software)? Browser plugins perhaps?
  #24  
Old April 3rd, 2008, 07:11 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,253
Default Re: Try your anti-keylogger protection

Obscure methods exist to by bypass most security apps and a keylogger would have to authored specifically to bypass a configured Sandboxie to stop as such employing a parent/child process.

If anyone has a poc would you be able to post it over at Sandboxie's forum so it can be looked at?

You can only help one of the best ever security apps get better.
__________________
Bestest Freebies - Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil, MS Virtual PC 2007, Ghost Images
  #25  
Old April 3rd, 2008, 12:09 PM
controler's Avatar
controler controler is offline
Massive Poster
 
Join Date: Jun 2002
Posts: 3,271
Default Re: Try your anti-keylogger protection

Hello

A while back I did some tests with commercial key loggers. Some of you may remember.
Back then you could download all new versions for free trial use. Now the makers got smart and some of them do not give a free trial. This way at least if the AV's are going to catch them, someone will have to pay for it.
My test simply comprised of downloading the newest version and running them through Virus Total. The interesting part is only a hand full of AV' were adding them. The reasons may have been legal issues, I don't know.
I am sure most still added for ITW key loggers, I never tested that.
But of course the most common way for these to get installed is if someone has access to your computer such as an IT person, spouse, yo mama or dad ect.

Can you people tell me if HIPS have become easy to use for the home user?
 

Wilders Security Forums > Security Software > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:43 AM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums