BlackFog Privacy

Discussion in 'other anti-malware software' started by liba, Feb 2, 2018.

  1. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    I am receiving a certificate modification warning of blackfog driver (don't remember its name it was some certicate of privacy.sys or something) in the registry, is it something that blackfog would do to modify its own certificate ? I downloaded the latest version, I am worried this is some bypass attempt targeted at blackfog, does blackfog checks its own certificates for modification by third party?
     
  2. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    We would never do this. We will add some protection for this activity @lucd. Thanks for the heads up.
     
  3. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Since we get a lot of questions about our general approach we have just published an article that talks about Cyber Warfare and Data Exfiltration that might be a useful reference.

    We are also looking for beta testers in the next couple of weeks for our new macOS edition of 4.0 which will feature more universal exfiltration on the entire Mac just like with Windows. The only requirement is that you are running Catalina. Please send an email to support@blackfog.com if you would like to be added to the list.
     
  4. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    After each reboot and log in to Internet this attempt happens at root certificate change (I've seen this 10 times in 1 month), ofc I did not let the certificate be changed. The certificate key's too long to post but if you really need I can try to send full picture, I do know 360 qihoo does a certificate scan and if needed it will attempt to "fix" and download the "right" certificate, however on different pc I am not having this issue (same setup: qihoo360+blackfog), it seams this change of certificate is not coming from qihoo, since I did not ask qihoo to modify certificates (in scan results options)

    P.S. thank you for your wonderful article and looking forward for more
     

    Attached Files:

    Last edited: Feb 10, 2020
  5. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    @Darren Williams
    Since the update to 4.3.0 (b475) I have had to start the Privacy.exe manually from the start menu as it doesn't start on boot up although PrivacyScv.exe starts as normal. Although there is no icon in the Taskbar and no gui until I start Privacy.exe manually information is still being recorded to the Dashboard and Exfiltration and in the events tab. I have tried re-installing but doesn't make any difference. Any suggestions?
    Also, since the last Rules update on Jan 27 I do not get a Browser Cleaned notification for Firefox and no entry in the events list. Chrome, Vivaldi and Edge work as expected.
    Further. The notification for Vivaldi and events entry both show "Browser Clean Completed in 0 secs (0 b, 0 files). Is this because Vivaldi is not in the Forensics list?
     
  6. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @lucd I will send this to the team to the a look at to see what might be goign on here. Very unusual behavior for sure. Our certs are done by MS themselves so we know they are solid.

    @Dark Star 72 the startup is actually performed by the system scheduler, so I wonder if there is something stopping that from triggering. I will PM you a couple of things to look at for that. We will check if Firefox has changed its startup logic as thats always possible. Also haven't added Vivaldi rules yet but we have added the infrastructure, so a future rules update will mean it is automatically supported without a version change which is why you get 0.
     
  7. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    @Darren Williams
    A quick update. I updated Firefox from 72.0.1 to 72.0.2 late last night and it's now cleaning and recording in the events tab so I assume that there was something in bld 72.0.1 that was causing the problem. Must have been coincidence that I updated from 72.0.0 to 72.0.1 on the same day that the rules were updated.
     
  8. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @Dark Star: Thanks for the info. Also note that the auto start happens by adding the app to the start registry for the system. You can see it is available on Win 10, goto Settings > Apps > Startup. You will see BlackFog listed there and it should be enabled.
     
  9. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    @Darren Williams :Opened settings > Apps > Startup and BlackFog was off. Enabled it and closed settings. Opened settings again to check it was still enabled and it was off again. So opened Task Manager > Startup and it was Disabled so Enabled it there and so far it has stayed enabled over several reboots:thumb:
     
  10. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Interesting you needed to do that. Never seen that before. Might need to write a KBA on that. Thanks for finding out what it was.
     
  11. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
    Is anyone using BFP on their Windows machine having trouble with Firefox updates?

    Thanks.
     
  12. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    No Krusty, not with update to FF 73. But I used PatchMyPC silent install this time, not FF internal updater.
     
  13. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    There is a general problem with Firefox 72.x that caused grief for a lot of users. You can read about it on the Mozilla site below:

    “Users with 0patch security software may encounter crashes at startup after updating to Firefox 73. This will be fixed in a future Firefox release. As a workaround, an exclusion for firefox.exe can be added within the 0patch settings. https://www.mozilla.org/en-US/firefox/73.0/releasenotes/
     
    Last edited: Feb 13, 2020
  14. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    My BlackFog Privacy license auto-renewed without warning.

    I think one should be notified a week or so in advance, so that one has the option to cancel.
    At least my AppGuard sub did that.

    For us 'third worlders' (South Africa), $ amounts can translate to quite a bit of money on the exchange rate. :cautious:
     
    Last edited: Feb 24, 2020
  15. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
    I agree.
     
  16. faircot

    faircot Registered Member

    Joined:
    May 17, 2012
    Posts:
    228
    Location:
    UK
    I second this. I wasn't aware of BF renewing until I saw my credit card statement last week.

    Not good business practice.
     
  17. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Noted guys, we will modify this procedure going forward and make sure there is ample notification of a renewal.
     
  18. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
  19. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    any news on root CA modification involving blackfog, now qihoo360 H.I.P.S. doesn't let me choose (allow/deny of modification of binary blob), but the qihoo's window pops up and closes very fast as if someone made the decision for me to install the root CA of blackfog
    did not see any untrusted connections in the event log of blacklog so I dunno what is happening, another program affected is simplewall firewall, might be a bug, a compatibility problem, a legitimate OS action or a an attack technique, it happens only when being connected
     
    Last edited: Mar 17, 2020
  20. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    We will investigate this and see if we can repeat. Certainly, not something we would ever do.
     
  21. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    We hope everyone is staying safe at home. Note we have just released 4.3.1 with a new Privacy option to "hide hostnames" in the Windows interface. Full release notes can be found on our website.
     
  22. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I just installed a security patch update on my Samsung Galaxy J7 phone with Android version 9 and now my apps can't seem to download anything, like Twitter can't load new tweets anymore with BF running.
     
  23. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Make sure you have the latest rules operating on BlackFog (Mar 27). I just tried it myself it it seems ok from this end. PM me if you still have problems and we can set out the combination of things to make sure its working ok.
     
  24. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I clicked on update rules and still does not work. All the settings show no number counts for blocked stuff. When i view events there is nothing there. Some or all of this happened right after the android software patch. Should i uninstall and install it again. The Android update might have corrupted the BF App.
     
  25. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    We will PM you a private build to look at tomorrow. Looks like they changed a couple of things.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.