![]() |
|
#1
|
||||
|
||||
|
I tried some interesting POCs from here:
http://www.zemana.com/list/list.asp?ktgr_id=413 My observations: CFP Key Logger Simulation Test - - - - - PASS Screen-Logger Simulation Test - - - PASS Webcam Logger Simulation Test - - PASS Clipboard Logger Simulation Test - - FAIL SSL Logger Simulation Test - - - - - POC not Available so far EQSecure Key Logger Simulation Test - - - - - PASS Screen-Logger Simulation Test - - - FAIL Webcam Logger Simulation Test - - FAIL Clipboard Logger Simulation Test - - FAIL SSL Logger Simulation Test - - - - - POC not Available so far GesWall Key Logger Simulation Test - - - - - PASS Screen-Logger Simulation Test - - - FAIL Webcam Logger Simulation Test - - PASS Clipboard Logger Simulation Test - - FAIL SSL Logger Simulation Test - - - - - POC not Available so far SafeSpace Key Logger Simulation Test - - - - - PASS Screen-Logger Simulation Test - - - PASS Webcam Logger Simulation Test - - PASS Clipboard Logger Simulation Test - - PASS SSL Logger Simulation Test - - - - - POC not Available so far OA Free Run Safer All FAIL ThretFire All FAIL ( Solcroft! I know what u will say and I understand and agree with you to some extent, though not fully). Have fun!! Anyone can try: ProSecurity DefenceWall SSM SBIE Thanks Edit: I have edited the reults, there were some wrong copy/ paste before.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
Last edited by aigle : April 1st, 2008 at 06:08 PM. |
|
#2
|
||||
|
||||
|
Quote:
![]()
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder". "Perfect is the enemy of good enough". Voltaire. |
|
#3
|
||||
|
||||
|
Hi,
"You can repeat the same test by installing Zemana Antilogger into your system." Anti Logger License Purchasing: 1 user License 39.50 USD "Zemana AntiLogger, with its proactive protection method provides you real time , powerful protection." Has anyone tested Zemana AntiLogger against a real keylogger? Or does it just pass their own tests? Cheers
__________________
"Free thought can't be bought" States Of Mind - Senser |
|
#4
|
||||
|
||||
|
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
|
#5
|
||||
|
||||
|
Keyscrambler passes the keylogger simulation test.
__________________
HP Elite 190A Windows 7 Home Premium 64 bit |
|
#6
|
||||
|
||||
|
Under Vista 32 SP1:
DefenseWall v2.30 Key-Logger Simulation Test - Pass(*Note: Detected and gave me the option to terminate this test on the spot via the pop-up notification.) Screen-Logger Simulation Test - Pass(*Note: Blocked silently.) WebCam-Logger Simulation Test - Tentative Pass(*Note: Although, I do not have a webcam, I ran this test anyway and observed in DW's log that all attempts to make changes to the registry were blocked silently.) Clipboard-Logger Simulation Test - ?(*Note: Does not appear to work when run as "untrusted". I will have to get Ilya to look at this particular test.) Peace & Gratitude, CogitoErgoSum
__________________
Current Vista 32 SP2 Resident Security Arsenal: (DefenseWall Personal Firewall v3.00 - KeyScrambler Pro) DefenseWall HIPS(http://www.softsphere.com/) *Loyal & diehard DefenseWall user since 1/06!* ~Living dangerously without a resident antivirus since late 2/07!~
Last edited by CogitoErgoSum : April 2nd, 2008 at 09:34 AM. |
|
#7
|
||||
|
||||
|
Quote:
Thanks for the reults.
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
|
#8
|
|||
|
|||
|
Quote:
![]() I test with real malware. POCs are to behavior blockers what the EICAR test file is to antivirus software: just a weak replacement used by sissies who feel the need to trick themselves into thinking they're doing any meaningful tests. But I'm sure you already know that. ![]() |
|
#9
|
|||
|
|||
|
Simple as that,most all reputable antimalwares are smarter the n the users of these fakes. LOL
![]() |
|
#10
|
|||
|
|||
|
Quote:
As about webcam- I still didn't made my mind if need to implement it. The reason is following: there are too many software nowadays (ICQ and other popular IM software, Skype and other VoIP clients) that are using webcam. Not sure if I need alert on each of it as it is impossible to automatically block it out. Also, in future, more and more software will be using webcams in order to improve its functionality. So- I'm in doubts about this point. Is it really about security?
__________________
DefenseWall HIPS developer. www.softsphere.com |
|
#11
|
||||
|
||||
|
Quote:
SRP for the win!!!!!1111 ![]()
__________________
Current Security Apps - Desktop/Laptop : SRP + LUA + KAFU, Antivir (free - on demand) LUA+SRP+KAFU = WIN!!!111 |
|
#12
|
||||
|
||||
|
Can anyone test Bufferzone,Prevx and Sandboxie please.
|
|
#13
|
||||
|
||||
|
With the keylogger test press alt+1, alt+2, alt+3 using the num pad on the right side of the keyboard for the numbers.
You should get ☺, ☻, and ♥ yet the keylogger shows 1, 2 and 3. What does this mean? Don't know, just posting as a quirk that may fool some keyloggers maybe. Sandboxie doesn't stop keylogging but they can't send that data out over the net when SB is configured for only your browser to connect out. Alt Key Codes
__________________
Bestest Freebies - Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil, MS Virtual PC 2007, Ghost Images
|
|
#14
|
||||
|
||||
|
Why exclude SSM & ProSecurity?
P.S. I have the same attitude toward sandboxes as does my cat. ![]()
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#15
|
||||
|
||||
|
Quote:
![]()
__________________
Bestest Freebies - Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil, MS Virtual PC 2007, Ghost Images
|
|
#16
|
|||
|
|||
|
Quote:
|
|
#17
|
|||
|
|||
|
Quote:
Solcroft, Should i ditch Sandboxie because of this,or should i trust Tsuk who is actually saying that no data can escape,if configured right ? Can you explain a bit how this can happen ? AFAIK if the keylogger rename itself to akin like your browser,SBIE is aware of this and denies connection. But maybe there other ways to lure SBIE in allowing connections.i dont know. So angry waiting to teach us. ![]() edit : none of my security fires up if i click keylogger exe,smart enough to distinguish ! Last edited by Huupi : April 3rd, 2008 at 02:53 AM. |
|
#18
|
|||
|
|||
|
Quote:
But right now, I'm trying very hard not to laugh. Oh wow, something's not absolutely flawlessly perfect, it needs to be ditched. You believed it was impenetrable just because some stranger over the Internet said so, and now you're asking another stranger if you need to ditch it. Seriously: grow up. ![]() Quote:
|
|
#19
|
||||
|
||||
|
Quote:
are you saying that keyloggers inside the sandbox can take over your browser and use the browser to connect out? wouldn't a good hips prevent a key logger from taking over your browser ? |
|
#20
|
|||
|
|||
|
Quote:
Quote:
|
|
#21
|
||||
|
||||
|
hmm well the only ways I can think of to stop keyloogers inside sandboxie.
1. use mvps hosts file and hopefully the keyloggers server is on mvps hosts file filter list. 2. allways clean out sandboxie before go to log into your online bank or any other login place. 3. hopefully your hips will give you a popup warning to block the keylogger from taking over your browser. Edit Actually you should be able to configure your hips to monitor your browser inside sandboxie. any one know of any other ways?? Last edited by arran : April 3rd, 2008 at 03:50 AM. |
|
#22
|
||||
|
||||
|
Quote:
__________________
MalwareDefender / CFP, GesWall, KeyScrambler - all under the umbrella of Comodo Time Machine Transition to Ubuntu with NO SECURITY SOFTWARE however VirtualBox is a great fun. ![]() I am waiting for a pop up HIPS for Ubuntu!
|
|
#23
|
||||
|
||||
|
How are keyloggers typically 'installed' on ones system? Is there one specific method or do they come in all sizes and manners?
How can one protect his system (apart from the usual AV/AS software)? Browser plugins perhaps? |
|
#24
|
||||
|
||||
|
Obscure methods exist to by bypass most security apps and a keylogger would have to authored specifically to bypass a configured Sandboxie to stop as such employing a parent/child process.
If anyone has a poc would you be able to post it over at Sandboxie's forum so it can be looked at? You can only help one of the best ever security apps get better. ![]()
__________________
Bestest Freebies - Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil, MS Virtual PC 2007, Ghost Images
|
|
#25
|
||||
|
||||
|
Hello
A while back I did some tests with commercial key loggers. Some of you may remember. Back then you could download all new versions for free trial use. Now the makers got smart and some of them do not give a free trial. This way at least if the AV's are going to catch them, someone will have to pay for it. My test simply comprised of downloading the newest version and running them through Virus Total. The interesting part is only a hand full of AV' were adding them. The reasons may have been legal issues, I don't know. I am sure most still added for ITW key loggers, I never tested that. But of course the most common way for these to get installed is if someone has access to your computer such as an IT person, spouse, yo mama or dad ect. Can you people tell me if HIPS have become easy to use for the home user? |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|