Should Trustware Vulnerability Test comes under the supervision of Anti-Keyloggers?

Discussion in 'other anti-malware software' started by sg09, Nov 13, 2011.

Thread Status:
Not open for further replies.
  1. sg09

    sg09 Registered Member

    Joined:
    Jul 11, 2009
    Posts:
    2,811
    Location:
    Kolkata, India
    I think D&S is just the default sensitive folder. In bufferzone you can add any folder to sensitive zone (like Sandboxie drop my rights?). I think Outpost Pro also has such an option.
     
  2. CoolWebSearch

    CoolWebSearch Registered Member

    Joined:
    Sep 30, 2007
    Posts:
    1,247
    I truly don't know what are you talking about I have tested on my own this Trojdemo.exe which is suppose to be the keylogger. Guess what, SBIE passed.
    I have manually blocked access to my documents in SBIE (D: partition), and the result was "no data steal"!
    SBIE passed this test.
    So, Sandboxie passed this key-logger test.
     
  3. CoolWebSearch

    CoolWebSearch Registered Member

    Joined:
    Sep 30, 2007
    Posts:
    1,247
    So, why is hysteria present so much about this test?
     
  4. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    maybe because it is not a real malware test
     
  5. CoolWebSearch

    CoolWebSearch Registered Member

    Joined:
    Sep 30, 2007
    Posts:
    1,247
    I've done this test again, and it actually says: No data files in "My documents"-no data steal.
    SBIE passed this key-logger test with some configuration:
    I opened "Resource access-file access-blocked access" in SBIE, and I blocked access to My documents, D: partition, folder WindowsXPPro, and I also blocked access to "Manager1 documents".
    I also have "Drop rights" enabled.
    With this configuration SBIE 3.62 passes this key-logger test (TrojDemo.exe).
     
  6. nikanthpromod

    nikanthpromod Registered Member

    Joined:
    Oct 9, 2009
    Posts:
    1,369
    Location:
    India
    it tries to read files of My documents...
    But BufferZone Pro protects My documents from reading...

    sandboxie also blocks this way
     
    Last edited: Nov 28, 2011
  7. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    I'm sure it would pass for me too, if I had sandboxie configured that way. I don't so it said that it had read My Documents. It wasn't allowed to phone home because of my internet restrictions. I wasn't saying that sandboxie failed. :rolleyes: Maybe everyone doesn't have the same configuration as you. So results may vary. Thanks for the professional approval though. :thumbd:
     
  8. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Do you have My Documents folder empty? :D Now, seriously, by design a low integrity level object can read from medium integrity level objects. Did you apply the NoReadUp flag to your My Documents folder?
     
  9. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    but the 1806 tweak trick can be very usufull when it comes to prevent malware infection:thumb: :thumb:
     
  10. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    It can, sure. I use it. But, it has no effect against something we do wish to execute. Nor a low integrity level will. If we wish to execute something, then we'll remove the low integrity level. That's always the weak spot, isn't it? :D

    The only way for something running with a medium integrity level not to read your My Documents folder/other sensitive folder, would be for this/these folder(s) to have applied a high integrity level with the NoReadUp flag, making low and medium integrity level objects blind to such folders.

    Then again, if we execute this something with administrative rights, only encryption would save your back.
     
  11. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    If you are running Sandboxie it won't say anything.

    I tested first running it in Sandboxie. It said My Documents didn't exist, but it was able to write to the other 3 programs, like tskmgr.exe. Well done sandboxie, that fact that is could write to those programs is meaning less since it did it's write in the Sandbox. The sandbox I use for this kind of test, doesn't permit any internet access.

    Outside the Sandbox, Appguard also stopped this thing.

    I run Online Armor and I have the keylogger module turned off. OA, let me see everything this trickster was doing and I'd have stopped it dead, when I saw it scanning My Document folders.

    Pete
     
  12. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,898
    Location:
    localhost
    ... and with a more recent version (ZA 10): :)

    Running the application "..."
    Capture.JPG

    Deny results:
    Capture2.JPG

    Pushing on "Attack results"
    Capture3.JPG

    Deny results:
    Capture4.JPG
     
  13. kjdemuth

    kjdemuth Registered Member

    Joined:
    Jul 29, 2005
    Posts:
    2,974
    Location:
    Boston, MA
    Yeah I tried it again today and it didn't get very far. Comodo placed it as a untrusted process and it was pretty much blocked. I did allow it to run in sandboxie and the window popped up that said it stole 690 files. Then I got a lot of beeps and it said explorer wasn't allowed to run due to restrictions and internet was denied due to restrictions as well.
    Maybe the first time I ran the test it wasn't sandboxed. Not really sure what happened. Obviously operator error on my part.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.