Coat Leaktest
  > CATEGORIES
  LEAK TESTING
  KILL TESTING
  ADVICES
  DOCUMENTS
  REWARDS
  > IN THE WILD
  > LINKS
  > FAQ
  > TOOLS

     SCAN YOUR COMPUTER

     TEST YOUR BROWSER



Leaktest information
Website : http://www.matousec.com/
Author : Matousec - Transparent security
Dates : -
Categories : other
Download : Coat.zip (View EULA)
MD5 8356bb438ac32fa3671ca633114150fa
SHA-160 2dc918c3c8619a2d17b0e20e49153472d5ecde2b
Operating System : 2000/XP ?


Leaktest description
From Matousec.com : The Coat leak-test rewrites its own memory and tries to establish an Internet connection. It rewrites its image base, image name, command line, Windows title etc. and it also changes the information of the main module in the module list. All these data reside in the address space of its process. All the data are changed to match the image of the default browser. Then, it tries to establish the Internet connection. Firewalls that are not able to handle this trick suffer from a serious design bug because they trust ring 3 data of malicious processes. They do not have their internal list of running programs and obtain this information when it is needed. This gives malicious processes enough time to modify these data before they execute privileged actions. Such firewalls (as well as many other programs - e.g. Process Explorer from Sysinternals) then see the malicious process as something else - e.g. the default browser - and allow the execution of privileged actions without any questions.


Download Coat Leaktest
(View EULA)

Home      News      Contact      Online form      Mailing list