Author Topic: Security vendor by-passes PatchGuard  (Read 3609 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Security vendor by-passes PatchGuard
« on: October 25, 2006, 10:58:04 AM »
Hi malware fighters,

Unlike Symantec, McAfee and others who have demanded that Microsoft allow them to access the kernel, and who claim that the Redmond, Wash.-based software giant is blocking them from doing so to advance its own interests in the security software arena, Authentium officials said they have merely circumvented the feature.

What to think of this article?
http://www.eweek.com/article2/0,1895,2036585,00.asp

How long before malware learns this trick (these tricks)?

polonus
« Last Edit: October 25, 2006, 11:01:16 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Security vendor by-passes PatchGuard
« Reply #1 on: October 25, 2006, 01:16:33 PM »
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48838
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Security vendor by-passes PatchGuard
« Reply #2 on: October 25, 2006, 03:00:57 PM »
More comment from Alex Eckelberry here:

http://sunbeltblog.blogspot.com/2006/10/will-patchguard-be-maginot-line-of.html
Frank what does this article have to do with the information polonus posted?
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Security vendor by-passes PatchGuard
« Reply #3 on: October 25, 2006, 03:16:38 PM »
Alex Eckelberry is writing about the same subject, and even mentions the approach Authentium have taken.

Correction: he quotes from Agnitum in the blog entry I quoted:

Quote
Why is it so risky to use KPP [PatchGuard] to provide kernel security for computers running Vista x64 rather than a third-party security solution?

Here’s an analogy. Today, every house has a different lock on its front door; in the same way, you can use any security product you want to protect your computer. Now imagine if every house in your city were required to use the exact same lock on its front door. As soon as a burglar figures out how to crack that lock, he can freely enter and steal from any house. This is what 64-bit Windows security will look like with PatchGuard.

Alex Eckelberry has now picked up on the Authentium story here:

http://sunbeltblog.blogspot.com/2006/10/qed.html
« Last Edit: October 25, 2006, 05:28:30 PM by FreewheelinFrank »
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48838
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Security vendor by-passes PatchGuard
« Reply #4 on: October 25, 2006, 05:34:45 PM »
The second post, isn't the same link is it ???  ;D
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5087
Re: Security vendor by-passes PatchGuard
« Reply #5 on: October 26, 2006, 05:48:06 AM »
Nice. I have Authentium's Command Antivirus as a backup scanner (On access scanner is disabled)
"People who are really serious about software should make their own hardware." - Alan Kay

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Security vendor by-passes PatchGuard
« Reply #6 on: October 26, 2006, 09:15:07 PM »
Hi malware fighters,

Now it is not so nice, because MS is not amused about what this av-vendor did, and will patch every hack of their PatchGuard. So owners of such an av-solution might actually be at a disadvantage.
Look here: http://www.eweek.com/article2/0,1895,2037052,00.asp
So we see that MS wants to decide whats gonna run at kernel level, and off course content managment will be part of the deal later.

Hackers have already broken PatchGuard and can disable it. This means that hackers can already get malicious code into the Windows Vista kernel; while legitimate security vendors can no longer protect it. This presents a serious new risk for consumers and enterprises worldwide,” stated Oliver Friedrichs director of emerging technologies in Symantec Security Respons.

With this, Symantec is aiming to no less than discredit PatchGuard in the eyes of the consumers. In this regard, the two brands are weight in the public perspective. When put in the balance, which of Microsoft and Symantec is synonymous with security? Undoubtedly, the latter, who is leader of an industry build on offering security solutions designed for safeguarding Microsoft's products. By delivering a below the belt blow with the PatchGuard Hacking claim, Symantec has chosen to do its laundries with Microsoft in public.

“In addition, now, you may ask yourself, if hackers can bypass PatchGuard, why don’t security vendors? (We know now one did it actually.) We certainly could, if we chose to; however, Microsoft has firmly stated that any attempt to do so will result in an update to PatchGuard, which will detect these attempts. It would be foolish for Symantec to ship a product out to over 200 million desktops that may result in a BSOD on each desktop, if Microsoft decides to update PatchGuard,” commented Friedrichs.

Microsoft chose to use the only weapons readily available to them: obfuscation and misdirection.
PatchGuard isnt new, and here is a article on bypassing PatchGuard: http://uninformed.org/index.cgi?v=3&a=3

polonus
« Last Edit: October 26, 2006, 09:32:49 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!