Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 16th, 2009, 07:04 AM
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 537
Default Re: PCT firewall + Leaktests

A bit OT but since we're talking about HIPS...

When you update an application already listed in Computer Security Policy (as Custom) and run it, you get no prompt that the file has changed? I believe CIS doesn't check the md5 but just remember the paths. Anyone also noticed this with CIS? What Stem reported might be applicable to CIS also.

Take note that my CIS HIPS is in Safe Mode (old config). When I update, I either turn-off CIS HIPS or use install mode. I haven't tested with Paranoid Mode. Do you think the safelist db/trusted certificates has got something to do with this?
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai

Last edited by thanatos_theos : October 16th, 2009 at 07:35 AM.
  #2  
Old October 16th, 2009, 09:10 AM
metalforlife metalforlife is offline
Regular Poster
 
Join Date: Mar 2009
Posts: 96
Default Re: PCT firewall + Leaktests

Quote:
Originally Posted by thanatos_theos
A bit OT but since we're talking about HIPS...

When you update an application already listed in Computer Security Policy (as Custom) and run it, you get no prompt that the file has changed? I believe CIS doesn't check the md5 but just remember the paths. Anyone also noticed this with CIS? What Stem reported might be applicable to CIS also.

Take note that my CIS HIPS is in Safe Mode (old config). When I update, I either turn-off CIS HIPS or use install mode. I haven't tested with Paranoid Mode. Do you think the safelist db/trusted certificates has got something to do with this?

The Image Execution Control monitors file changes in CIS. According to the help file (when Image Execution Control is enabled) CIS calculates the hash-value of a file before it loads into the memory. Going by it, file alterations - such as updates - should be detected by D+.
  #3  
Old October 16th, 2009, 09:40 AM
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 537
Default Re: PCT firewall + Leaktests

Quote:
Originally Posted by metalforlife
The Image Execution Control monitors file changes in CIS. According to the help file (when Image Execution Control is enabled) CIS calculates the hash-value of a file before it loads into the memory. Going by it, file alterations - such as updates - should be detected by D+.
Forgot about that. I'll have to check that out when I'm on the rig with CIS. It must depend on the settings set there. Maybe a prompt will appear during update but at those times I have the HIPS disabled or in install mode. Will try with HIPS on, next time. I turn-on the HIPS after the update, run the updated program I get no prompts unfortunately.

As a test, turn-on install mode or turn-off HIPS, update your Realtek HD Audio. After startup, turn-on HIPS and click Realtek systray icon. CIS should prompt you that RTHDCPL.exe has changed right? *I didn't try this yet*
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai

Last edited by thanatos_theos : October 16th, 2009 at 09:54 AM.
  #4  
Old October 16th, 2009, 10:18 AM
metalforlife metalforlife is offline
Regular Poster
 
Join Date: Mar 2009
Posts: 96
Default Re: PCT firewall + Leaktests

Quote:
Originally Posted by thanatos_theos
Forgot about that. I'll have to check that out when I'm on the rig with CIS. It must depend on the settings set there. Maybe a prompt will appear during update but at those times I have the HIPS disabled or in install mode. Will try with HIPS on, next time. I turn-on the HIPS after the update, run the updated program I get no prompts unfortunately.

As a test, turn-on install mode or turn-off HIPS, update your Realtek HD Audio. After startup, turn-on HIPS and click Realtek systray icon. CIS should prompt you that RTHDCPL.exe has changed right? *I didn't try this yet*

There was a discussion on this somewhere on the COMODO forums. I had read it, but don't recollect much of what was said there. But I do remember - vaguely though - the cheif developer of CIS (egemen) stating that CIS does not verify hashes of executables which are modified by the user himself, or something of that like.

You can search for threads on topics related to this in the COMODO forums.
  #5  
Old October 16th, 2009, 10:25 AM
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 537
Default Re: PCT firewall + Leaktests

I guess that was intended to make CIS user friendly and lessen alerts. Well, I think CIS will alert the user anyway if ever some malprocess tries to change/hijack/infect/tamper an application or it's integrity.
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai
  #6  
Old October 16th, 2009, 11:53 AM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: PCT firewall + Leaktests

As I know CIS doesn,t check for hashes, as it has real time file defence. Same is true of MD.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #7  
Old October 16th, 2009, 06:06 PM
thanatos_theos thanatos_theos is offline
Frequent Poster
 
Join Date: Apr 2007
Posts: 537
Default Re: CIS + MD5

Thank you aigle.

I just skimmed on their forums and read that Image Execution depends on the extensions set and only checks for hashes in 'real-time'. But it disregards those found in/matching those in the safelist db. Maybe in the future they can do that on-demand, on-next execution of the updated file or during start-up. I think this on-demand hash scan (for new exes) occurs in start-up when using Clean PC mode.
__________________
"O miserable shadow clad in darkness! Hurting and disdaining people, a karmic soul drowning in sin... Would you try dying for once?" - Enma Ai

Last edited by thanatos_theos : October 16th, 2009 at 06:13 PM.
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:20 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums