The Coalition against Personal Firewalls

May 25, 2006 141 Replies

"Jason Edwards"

there is no real difference between firehole and the Avira update function. If you start the Antivir update your browser is also started and presents an Antivir advertising page. Firehole is nicer and more friendly because it first ask if it's allowed to make the connection ;-). A lot of software uses this unasked connection construction to promote products. It would be very great if your protection software could trigger and block those programs.

On Mon, 5 Jun 2006 09:42:32 +0100, Jason Edwards spoketh

Yes, *it* should be detected as malware

Compilers doesn't test the function of software, it only checks for validity of statements and syntax.

Lars M. Hansen

formatting link
(replace 'badnews' with 'news' in e-mail address)

Which *it* should be detected as malware by AV tools?

Volker's executable? Firehole? leaktest? Or all of them?

Jason

Jason Edwards wrote: ["Leythos"]

Don't confuse "Leythos" with logics! ;-)

Yours, VB.

On Mon, 5 Jun 2006 11:57:49 +0100, Jason Edwards spoketh

The "it" being discussed is VBs PoC.

Lars M. Hansen

formatting link
(replace 'badnews' with 'news' in e-mail address)

See what I mean, he doesn't have a point that he can reply too, so he starts with the BS again.

It's a simple fact, that PFW's do protect users, not all users, but enough users that it makes it worth the installation to protect those using them properly.

Then perhaps you may help here: what of my PoC is malware? And why is it a Trojan in your definition?

Yours, VB.

Regardless of the "Intenet" of your POC, it does what you claim can bypass a firewall, which means it does something a user doesn't want it to do. The point is not that you are providing a "Good" code to test, the point is that, as you claim yourself, that the code proves that it can bypass the firewall against the users desire.

Anything that exploits a hole in the OS, Apps, Firewalls, is really a form of malware, even if it's used to test the security, it doesn't matter what the real intent is.

You missed the point completely.

Yours, VB.

Do you think that Firehole and Leaktest should also be detected as malware by AV tools?

Jason

It only does something a user doesn't want it to do if it is done without the user's knowledge. If the user _does_ know that they are running Volker's PoC as a test, then the PoC is not doing something that the user doesn't want it to do.

The code only bypasses the firewall against the user's desire if the user does not know it is running. If the user _does_ know it is running then the user clearly has a desire to watch the demonstration, in other words the user _does_ have a desire to see the firewall bypassed.

If it's done without the user's knowledge then yes, it really would be malware, and I would agree that AV tools should detect it. But Volker's PoC does not do anything without the user's knowledge, even if it exploits a hole in the OS or some other security software.

Therefore we must make a distinction between Volker's PoC and real malware which uses the PoC to its own ends without the user's knowledge. Do you agree?

Jason

No, there is no difference. The "Intent" is not what makes the difference.

If the "code" can do something unwanted, then it should be detected and blocked. While "Some" may want it to pass, others may want the specific actions of his code to be detected and blocked - as he claims that PFW solutions don't block it and that's why they are worthless. It would seem to me that since they CAN detect it, that his statements are no longer true and could be suspect all along.

So, if something is going to take advantage of a exploit vector, don't you agree that it should be detected as malware?

Why would you want AV software to detect and block it if it's just a demonstration of a concept but does not itself install unwanted code or damage a computer or attempt to steal data?

This is not unwanted. I want to use it to test my configuration to verify whether it works or not. I want to see if it passes or fails.

So I don't consider the PoC on its own malicious. I do consider malware which attempts to use this PoC to do malicious things to be malicious but that would have a different signature so my AV software should be able to tell the difference even if heurisics alone can't.

Why are you repeating what Volker does or doesn't claim about PFWs again?? I don't care whether a PFW blocks it or whether PFWs are worthless or whether PFWs can detect the PoC. Please try to understand that I am questioning the behaviour of AV software not PFWs. AV software does not even require the file to be run. Please also try to understand that I don't care whether it's AVG or some other scanner.

No, _not_ _by_ _AV_ software_ if it's taking advantage of the exploit vector for no reason other than demonstrating to me that an exploit vector may exist which could be exploited by real malware. It should be a simple matter for the AV software to distinguish the PoC from other code which uses the PoC because other code would match by behavior (heuristics) but not by signature.

If you have the view that AV software alone (not PFWs or anything else) should detect the PoC as malicious (and only the PoC not other code with the same behaviour in it) before the executable is run, then there is no point continuing as we just have different views and that's life.

Goodnight

Jason

I'm not sure you understand, if something acts like malware, even if you think it's a good app, you want protective apps to ignore it automatically?

How the heck are protective apps suppose to know what you want? They don't work that way, the look at what something has a potential to do, how it contacts other parts of the OS or apps, a signature, etc....

Then unblock it.

And you have the right to consider it any way you want, but don't force others to have the same opinion. If the product ACTS like malware, most people would want it detected and blocked.

So it comes down to this - because "You" want it to be permitted, anti- malware vendors should ignore the app that mimics malaware to prove that there are holes in PFW solutions and that AV products can't detect it?

Because you keep missing the point that he claims it proves something that you are asking about - since it's detected it means that it IS detected, which he said they don't do.

Then what the heck do you keep going on about? If you don't care if it's detected, if you don't care if it's run, what do you care about?

So, you want the AV software to ignore something taking advantage of a exploit, but only if the exploit is being used by a friendly application? Do you have any idea just how ridiculous that sounds? Unless you tell the AV software to ignore it, just how do you expect the AV software to know the difference and still block other apps that exploit the hole?

You seem to be missing the boat completely - if the POC works, it works because the application/OS has a flaw/exploit. If the exploit is blocked, and I don't care who/what is taking advantage of it, then the AV/PFW solution is working perfectly. If the POC/malware/other is not blocked from taking advantage of the exploit, then the AV/PFW solution fails to protect you.

It's quite simple, here it is:

If "ANY" application tries to take advantage of an exploit and is detected and blocked, then the AV/PFW solution is doing its job.

Notice I didn't say anything about the "Intenet" of the application attempting to take advantage of the exploit.

On 5 Jun 2006 15:04:11 +0200, Volker Birk spoketh

I didn't say it was a trojan. I don't know what various AV software call your PoC, but that's not relevant.

The point is that your PoC shows a method which can be used for malware to bypass firewalls.

There's another recent PoC code available. It proves a method of infecting StarOffice and OpenOffice documents. Despite the fact that the code does nothing but propagate itself, it is still classified as a virus and treated like one.

Just because your code does nothing but prove the concept doesn't mean someone isn't going to use the same code, or similar code in a piece of software that will do something bad...

It seems like Jasons main argument is that other software isn't detected as malware, so why is this detected? Well, I don't have the answer to that. I don't write the AV software or the signatures, so that's a question for them. However, that's like arguing in traffic court that, despite the fact that you were speeding, you were unfairly singled out because there were other cars speeding too, and they weren't pulled over.

For some reason unfathomable to me, Steve Gibson have been proclaimed "Security Guru", which is probably why his "leaktest" is considered trusted, and therefor not detected as malware. Despite the fact that Volker have contributed his knowledge and experiences in the security field, he doesn't appear to have achieved the same level of trust.

Lars M. Hansen

formatting link
'badnews' with 'news' in e-mail address)

Some AV programs do.

int f() { return 42; }

Now this posting shows a method, which can be used for malware to bypass firewalls - the concept of writing a function.

A virus is code, which propagates itself. From Wikipedia: "In computer security, a computer virus is a self-replicating computer program that spreads by inserting copies of itself into other executable code or documents."

OMN! Please, *PLEAZE* don't compare me to him!

Yours, VB.

If it propagates itself to others who have not agreed to test a PoC and do not know what they are getting then I agree that it should be detected as malware.

Why is it difficult to distinguish similar code from a known piece of code which is nothing more that a PoC and does not do something bad? A signature can tell you immediately that you have Leaktest 2.1, VB 1.1 or something unknown. Volker's PoC on its own cannot be used to do anything bad, not even if you use another program to invoke it. To do anything bad it would have to be modified and would thus have a different signature or different behavior or both.

Bad analogy. Speeding has the potential to cause damage to yourself and others. So I have no problem with speeding being detected. Volker's PoC by itself cannot damage anything.

Whether he's a "Security Guru" or not doesn't change the fact that his code attempts to demonstrate a weakness in PFWs. Leaktest cannot damage anything either.

We'll probably never know why AV vendors included a signature for Volker's PoC. As far as I can tell there is no heuristic detection involved.

Jason

Sure you will, but you won't get it down the path you are taking - you see, if something is a good enough example of how to exploit something, well, it should be detected as such. I don't understand how you can fail to see/rationalize that concept.

Anything that makes use of an exploit should be detected and stopped/blocked as malware. AV software does not understand the "Intenet" of the programmer, it understands the black/white functions of the application, the vectors, and the actions.

I seriously doubt that any AV vendor has taken the time to put a definition into their product to specifically detect VB's code, I would expect, since it used the same method as other exploits, that it's being detected by that, which is what anyone would expect.

Why should a program which tells the browser to connect to

formatting link
be detected as a virus? Why should a program which tells the browser to connect to
formatting link
not be detected as a virus? Making this change to Volker's program will change the signature and then it's not a virus any more. If you do not believe this then please do the following before replying.

  1. Find a virus scanner which detects Volker's code as a virus.
  2. Compile your own code which connects to a different http server. Is the new code detected as a virus? And if so by which AV product?

Thank you for taking the time to perform this experiment and letting us know the results.

Serious doubts are no good to me; I need facts which speak for themselves. So please provide proof of your statement that "since it used the same method as other exploits, that it's being detected by that". I will accept this as a fact when you have proved that it is a fact. To prove it as a fact you need only give me one AV tool (virus scanner) which detects the code I compiled myself as a virus/malware. My code uses exactly the same method unless there's something seriously wrong with the compiler. Also I'll want to know when the scanner first detected Volker's code by the methods it uses instead of by signature alone. It's no good if that's today or some future time.

Thank you for taking the time to find and provide proof that Volker's code is being detected (by AV software) by the method it uses and not just a signature.

Have a nice day.

Jason

How about VB's own words - that the code is a POC that proves holes in personal firewalls. If something that proves holes in PFW is not a exploit, what most would call a threat, then nothing else is either.

I do not understand how you can be so dense - the POC was to prove a exploit, but you say it's not malicious, but you agree that it can prove and exploit, but you don't want something that can take advantage of an exploit to not be considered malicious. If it quacks like a duck it must be a duck.

Already proven, you just don't seem to understand what you're looking at. You need to understand that a POC is code, that's all it is, and if that code takes advantage of a exploit that AV or other software can detect, then you know two things - 1, it was a good POC for the exploit,

2, that your protection software is working properly.

You're really got a comprehension problem - different av products will detect the POC/anything through their own means, which may or may not be the same between av products. I don't control the AV software market, I don't control exploits, I don't control how the av software detects threats. If you want to know why your av solution detected it, ask the vendor, they are the ONLY ones that can tell you. The rest of us just look at the fact that it takes advantage of an EXPLOIT and that anything that takes advantage of an exploit should be detected and stopped - it's really that simple.

I'm not taking time to prove anything, and I don't know how your AV software is detecting VB's code (and I don't really care either). What matters is that a POC for an exploit was developed by someone, that the AV software you are running detected it by some means, that means that the POC was properly detected as a threat - since the intent of the POC was to expose an exploit, and the point of AV software is to detect/stop threats - so, it all sounds like it's working as designed.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required