The Coalition against Personal Firewalls

May 25, 2006 141 Replies

I have different versions. The first one is using Windows messages:

For Internet Explorer on an English Windows, you can try this:

formatting link
formatting link
(precompiled binary)

This PoC requires Internet Explorer to be opened already and to be free to communicate (like a situation, the typical Internet Explorer user has with his "Personal Firewall").

For Mozilla Firefox 1.0.x, you can try this:

formatting link
formatting link

This PoC requires Mozilla Firefox to be opened already and to be free to communicate (like a situation, the typical Mozilla Firefox user has with his "Personal Firewall").

The second one uses ActiveDesktop:

formatting link
formatting link

This PoC requires ActiveDesktop to be configured and Internet Explorer free to communicate (like the situation, which is the default configuration in Windows and nearly every "Personal Firewall").

The second one I wrote because Zone Labs implemented a Windows message filtering system. I'm using COM instead now, another basic Windows technology, to show, that this principle can be implemented with every part of Windows, which allows communication as IPC, and that the design of Windows is the problem, why a "Personal Firewall" must fail in such a way.

You can find my PoC code, too, at

formatting link
on
formatting link

On

formatting link
you can see, that there is no "Personal Firewall", who can prevent outbound communication at all. And: my two simple PoCs are only a small preview of what's on my mind - and the other guys here spent even more efforts than I did and implemented much more complicated solutions ;-)

Because I have no time, my first PoC code took me minutes, the second one I hacked on a saturday evening while having a chat with Alex here at my kitchen table.

Yours, VB.

Thank you, but I didn't want to apologize for something ;-)

But I agree, that it is important to be a little bit polite and try to explain the facts and their consequences in a way, people don't have the feeling then, they would be called idiots or treated like this.

People who have other opinions are not idiots, but people I want to hear. People who don't know these facts (yet), are not idiots but people who may be convinced in a discussion.

Only people who deny or ignore the facts are idiots, if the facts are proven. And even then we could discuss the consequences, and different people may have different views of the consequences of the facts.

Maybe Ansgar and Sebastian could be a little bit more polite. But maybe on the other hand I would miss their fresh and direct way ;-)

Yours, VB.

No, what it means is that it only works on computers that were already vulnerable and where the user has not followed microsofts instructions on how to secure the browsers.

All the POC code does is show that the user is already vulnerable, and that they may have improperly configured their PFW as it didn't work on any of the computers I tried it on.

So, passing his POC or failing it, doesn't appear to mean jack.

"Volker Birk" wrote

great!! I downloaded it, but I couldn't use it because : it's a Trojan. named : TR/Click.Small.IP

Tried your other programs :

is the Trojan : TR/Agent.OC.1

is the Trojan : TR/Agent.OC

That's why you don't like active firewalls?

Nobody else virusscanner had a comment?

Those are not trojans but proofs of concept. A trojan horse is by definition software that has hidden functionality supposed to harm the user. The PoCs do exactly what they claim: they bypass personal firewalls. It's absolutely ridiculous of AV vendors to classify a PoC as malware, much less as a trojan horse.

Besides, nobody here argued against AV software as it may *prevent* malware from running, which is a good thing to do. Personal firewalls OTOH try to prevent malware from communicating outbound *while* it is already running. The latter simply doesn't work if the malware makes any evasion attempts.

cu

59cobalt

No, it hasn't had to do with vulnerabilities. There are multiple built in mechanism in the Windows OS for inter process communications and so for remote control applications: Windows Messaging (the only thing, what breakout.c uses), DCOM, ...

here are some more examples: windows

formatting link
Instead of this I'd try to test a DNS-tunneler as phone home software.

Tell it Mr. Birk. He'd write a special version of the PoC for you ;-)

Wolfgang

Which AV Utility told you this?

It is _not_ a Trojan. Unfortunately it is misinterpreted by some Virus scanners as attack code. Why manufacturers of Virus Scanners detect absolutely harmless PoC code as malware is open to your interpretation.

Hint: these manufacturers usually are manufacturers of "Personal Firewalls", too. Honi soit qui mal y pense.

It's not a Trojan, too.

It's not a Trojan, too.

No. You have the source code. Just read it and compile your own version. If you're using Microsoft's tool chain, you'll see, that exactly this binary is generated.

Please ask your provider of your Virus Scanner, why they're doing such misinterpretation. I'm looking forward to this explanation.

Yours, VB.

Throw it away and buy something else. Or at least complain.

Yours, VB.

Volker Birk" wrote

No. It's your software, so ask them yourself. I'm tired asking Antivir to undertake action for false positives. They don't answer my emails with false positive info; they did not answer a well-known freeware software writer having problems with an ongoing false positive Antivir alert.

It's not only your PoC software giving problems. My old virus demo's like cascade, jeruzalem or drip are also marked for permanent deletion. And more and more old serious programs are marked as potential danger.

These are some of the reasons why I no longer use virus scanners on any of my own PCs. Other reasons include interference with video capture/recording and inability to find viruses until it's too late.

It's much better to configure your network/system/procedures so that viruses cannot do any damage, even if an inexperienced user gets one.

Jason

I'm not a user of their software, and my software does not make such problems, but the the Virus Scanner software itself.

If they don't offer valuable service, maybe you could consider using another Virus Scanner (or rethink, if you need one at all).

Yours, VB.

...

AOL^W ACK.

Wolfgang

SO, you say that the PFW vendors don't really protect you, and then when they do what they should, stop your POC sample, you say you don't know why they detect it.

Sounds like you need to make a POC app that really works.

No, it's not rediculous to classify them as malware, since this is a useful heuristic way to recognize a zero day virus. By it's capabilities, rather than some string of text. The fact that it's payload is harmless is beside the point from the AV point of view, the fact that it does stuff that would normally only be done by malware is the important part. In fact building heuristic AV definitions and IPS signatures from PoC's is a responsible and proactive way to provide additional protection against zero-day attacks.

-Russ.

The assumption that the PoCs do stuff only malware would normally do is wrong.

cu

59cobalt

When the PoC is breaking/bypassing your firewall and connecting out, it sounds quite correct to me, to identify it as a potentially malicious bit of code heuristically.

Other PoC's may be fully harmless, of course.

-Russ.

Please have a look at what the code actually does (i.e. read the source), before judging it.

cu

59cobalt

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required