Stuxnet .(lnk exploit malware) versus HIPS

Discussion in 'other anti-malware software' started by aigle, Apr 20, 2011.

Thread Status:
Not open for further replies.
  1. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    You're conducting some very interesting tests. Could you please share the hash of the file you're doing the tests with? I think I might be in possession of it!
     
  2. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    To all, pls I aologize in advance that I can,t do tests on request. Anyone interested can PM me to get the sample( just PM, don,t ask openly in the thread) and do their own testing. Hope you people will not mind! :)
     
  3. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    1- No outgoing alert with FW in safe mode.
    2- Windows XP Home SP2 not fully patched
     
  4. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Yes, just like Comodo v 3 but practically you can,t use these settings, totally impractical.
     
  5. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    MD5 055a3421813caf77e1387ff77b2e2e28
     
  6. SUPERIOR

    SUPERIOR Registered Member

    Joined:
    Dec 10, 2007
    Posts:
    161
    Location:
    Syria
    umm...i run comodo version 5.3.50343.1237 on xp sp2 and it stopped the attack partially if it could be said so
    look pictures
     

    Attached Files:

    Last edited: Apr 21, 2011
  7. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Will try later with Allah,s will. I don,t expect it will pass as rundll32.exe is not involved here at all.
     
  8. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Any thing in Comodo log?

    May be it,s due to the way Comodo deals with shell32.dll, and not due to interception of malicious dll itself by Comodo. Just a wild guess.
     
  9. arran

    arran Registered Member

    Joined:
    Feb 5, 2008
    Posts:
    1,156
    Yes of course it would if configured correctly.


    Anti executable 4 would also pass, I believe AE4 intercepts dll's now
     
  10. Syobon

    Syobon Registered Member

    Joined:
    Dec 27, 2009
    Posts:
    469
  11. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Same with OA even if you allow the alerts!
     
  12. harsha_mic

    harsha_mic Registered Member

    Joined:
    Mar 11, 2009
    Posts:
    815
    Location:
    India
    i tested CFW v5.3 thru sandboxie. I can't see it loading dll except the attached alert from the execution of malware...
    I don't see malicious dll being loaded. I have verified with gmer and process explorer.
     

    Attached Files:

  13. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    I don,t think that it,s a good way to test Comodo with malware running inside SBIE.

    However I can confirm that if I run it with Comodo, malicious dll is loaded but it doesn,t loads further malicious modules( as shown by gmer- see the post above by 'superior'). Same is true if I run it with OA and allow all prompts. I don,t know what does all this mean.
     
    Last edited: Apr 22, 2011
  14. harsha_mic

    harsha_mic Registered Member

    Joined:
    Mar 11, 2009
    Posts:
    815
    Location:
    India
    thanks for the inputs aigle.
    Yes, i know that testing malware in sbie would not correctly tell the protection efficacy of comodo.
    Are you testing comodo in virtualbox?

    Thanks,
    Harsha
     
  15. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    can anyone plz test spy shelter against this? Thanks
     
  16. SUPERIOR

    SUPERIOR Registered Member

    Joined:
    Dec 10, 2007
    Posts:
    161
    Location:
    Syria
    predictable result ....epic failed :D
    i tested it i mean
     
  17. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    wow . :(
     
  18. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    No, on real system with CTM.
     
  19. Worter

    Worter Registered Member

    Joined:
    Mar 9, 2011
    Posts:
    6
    Comodo fails it?
    Do not worry. Microsoft have already fixed the bug :)
    Just install latest update for your OS.
    I have Win7 SP1 64 bit. No dll was injected. Previously it was possible to inject dll
     
    Last edited: Apr 22, 2011
  20. kwismer

    kwismer Registered Member

    Joined:
    Jan 4, 2008
    Posts:
    240
    are you offering a benign exploit of the relevant vulnerability here, or offering to distribute the actual stuxnet malware to anyone who asks in private?
     
  21. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Both, keep rest to PMs. :)
     
  22. Zyrtec

    Zyrtec Registered Member

    Joined:
    Mar 4, 2008
    Posts:
    534
    Location:
    USA

    Hi,


    Did you test Comodo using settings per this YouTube video? :


    http://www.youtube.com/watch?v=D9BPONNYk_g



    I ask because I'm running just the firewall (not the AV) alongside with ESET NOD32 v4.2 on Windows 7 Pro 32-bit and I'm kind of curious if their HIPS let this worm through.

    Thanks


    Carlos
     
  23. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Not to sound harsh, but if you're not on a pirated copy of Windows which does not allow you to update it, you're already safe from this infection. I rarely get into these kind of discussions any longer... just my two cents.
     
  24. Ranget

    Ranget Registered Member

    Joined:
    Mar 24, 2011
    Posts:
    846
    Location:
    Not Really Sure :/

    :-* it allows update

    sorry for the bad news
     
  25. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    I'm not sure I understand the meaning of your post. What is the bad news? That (your?) a pirated copy of Windows allowed you to update? Or that the actual bad news is that the infection is still valid for updated OSs? I'm not aware of that this exploit works on updated Windows machines.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.