![]() |
Outpost User Operated Support Forum
Agnitum Outpost Pro Release (OP, OSS, AV): 7.0.3.3392 [24-AUG-2010]
www.agnitum.com |
|
#1
|
|||
|
|||
|
With malware being digitally signed becoming more popular I've been wondering how the current versions 7.x are dealing with them in general. Because I didn't have a chance to upgrade yet hopefully someone came across the answer.
Version 6.7 does prompt for unknown and/or changed executables when Component Control is configured accordingly. That is only true for digitally unsigned executables. For example I have never seen a prompt by Outpost for CCleaner or Recuva of which both are signed. To see what Outpost does with an invalid signature I edited the CCleaner executable with an hex editor and changing one byte that wouldn't affect the ability to run the program. Windows will correctly state that the digital signature is invalid because of that modification yet Outpost does not prompt at all, neither because obviously the file hash has changed or the digital signature became invalid. Outpost does not even store the file hashes for signed modules. Because of that behavior I contacted Agnitum Support asking for clarification and the only answer was if this was reproducible with 7.0. So I couldn't follow up on that matter yet. What Outpost in my opinion should be able to do: -Prompt for all modules regardless of them being digitally signed -Check the validity for digitally signed modules if file hashes are not being tracked -Track file hashes if validity of digital signatures cannot be guaranteed Some reading material, pretty much on every single security orientated blog at the moment: It's signed, therefore it's clean, right? Signed Stuxnet Rootkit Stuxnet and stolen certificates P.S.: This is more of a general issue than something specific to Outpost Firewall but since that's the version I am using I posted in this forum. If however that's the wrong place I apologize. |
|
#2
|
||||
|
||||
|
Re: Digitally signed executables and malware
you might want to untick the box in the improvenet settings at the bottom regarding digitally signed apps....
i would hope agnitum are following this....
__________________
Regards, CAVE CANEM ET SEMPER PARATUS Win7x86, P4E, 3 GB ram, nVidia fx5200, Asrock p4v88 MB, and win7 x64, pentium D, 2GB ram, nvidia 8400gs, acer aspire t650, Firefox 3.6.8pre, Thunderbird 3.1, IE8, 802.11g adapters, Netgear DG834G adsl modem/FW/router, Outpost Security Suite v7.0.2, in-house IT Support Dept. consisting of two retired greyhounds. ![]() Last edited by kronckew; 07-20-2010 at 09:49 PM. |
|
#3
|
||||
|
||||
|
Re: Digitally signed executables and malware
Things started to look ugly: Siemens: German customer hit by industrial worm.
__________________
If it ain't broke... fix it until it is. |
|
#4
|
||||
|
||||
|
Re: Digitally signed executables and malware
luckily so far the only one reported. the race is on for Microsoft &/or Siemens to come up with a patch before the malware baddies get their act together. i've disabled auto rule generation in general for the moment.
__________________
Regards, CAVE CANEM ET SEMPER PARATUS Win7x86, P4E, 3 GB ram, nVidia fx5200, Asrock p4v88 MB, and win7 x64, pentium D, 2GB ram, nvidia 8400gs, acer aspire t650, Firefox 3.6.8pre, Thunderbird 3.1, IE8, 802.11g adapters, Netgear DG834G adsl modem/FW/router, Outpost Security Suite v7.0.2, in-house IT Support Dept. consisting of two retired greyhounds. ![]() |
|
#5
|
||||
|
||||
|
Re: Digitally signed executables and malware
Quote:
__________________
If it ain't broke... fix it until it is. |
|
#6
|
||||
|
||||
|
Re: Digitally signed executables and malware
Well, I followed the patch instructions a few days ago and looked again this am, but I see no difference in my icons appearance, i.e., they did not turn 'blank'. Yet the reg changes did stick... win xp sp3.
On win7 pro, only icons to websites, internet shortcut, became blank. Last edited by minoka; 07-21-2010 at 12:38 AM. |
|
#7
|
||||
|
||||
|
Re: Digitally signed executables and malware
i tried the 'patch' (microsloth list it as a 'work-around' rather than a fix), it turned all my start menu icons to the same blank page icon & it's very difficult to find things in the menu as they all look alike now with visual clues missing you have to read the whole list & ensure you actually select the right one, any menu 'folders' with sub items are also affected. i've unpatched & await the proper fix. i suspect that if you do not have one of the products affected (i do not), it is reasonably safe to stay unpatched, tho i have turned off auto-generating rules.
also found this on the virusbuster site: Quote:
__________________
Regards, CAVE CANEM ET SEMPER PARATUS Win7x86, P4E, 3 GB ram, nVidia fx5200, Asrock p4v88 MB, and win7 x64, pentium D, 2GB ram, nvidia 8400gs, acer aspire t650, Firefox 3.6.8pre, Thunderbird 3.1, IE8, 802.11g adapters, Netgear DG834G adsl modem/FW/router, Outpost Security Suite v7.0.2, in-house IT Support Dept. consisting of two retired greyhounds. ![]() Last edited by kronckew; 07-21-2010 at 05:44 AM. |
|
#8
|
|||
|
|||
|
Re: Digitally signed executables and malware
Those only apply to network and anti-leak rules if I'm not wrong. Anything automatic is disabled on my system (Auto-learn, ImproveNet, rule auto-creation) anyway without affecting my component control settings.
|
|
#9
|
||||
|
||||
|
Re: Digitally signed executables and malware
agnitum have today released a new build 3377 to protect against the vulnerability stuxnet exploits in .lnk files. my icons are back
__________________
Regards, CAVE CANEM ET SEMPER PARATUS Win7x86, P4E, 3 GB ram, nVidia fx5200, Asrock p4v88 MB, and win7 x64, pentium D, 2GB ram, nvidia 8400gs, acer aspire t650, Firefox 3.6.8pre, Thunderbird 3.1, IE8, 802.11g adapters, Netgear DG834G adsl modem/FW/router, Outpost Security Suite v7.0.2, in-house IT Support Dept. consisting of two retired greyhounds. ![]() |
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|