Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
January 02, 2010, 08:03:16 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
346788
Posts
38336
Topics
87096
Members
Latest Member:
robmcq
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Help - CIS
Defense+ Help
Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
« previous
next »
Pages:
[
1
]
2
Author
Topic: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat (Read 1706 times)
BoosTy
Newbie
Offline
Posts: 5
Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
on:
September 19, 2009, 01:23:39 PM »
I did some testing and I was able to execute .bat files in cmd it blocks .exe but it wont block .bat files like it should please fix this bug its a big open door people can just upload a .bat file execute it and wipe out comodo so please patch this and give me credit for finding it lol !
Logged
HeffeD
Comodo's Hero
Offline
Posts: 1529
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #1 on:
September 19, 2009, 03:33:45 PM »
Create a .bat file that will wipe out CIS, then let us know.
Logged
Can
you
beat my gladiator?
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4397
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #2 on:
September 19, 2009, 06:06:50 PM »
Quote from: HeffeD on September 19, 2009, 03:33:45 PM
Create a .bat file that will wipe out CIS, then let us know.
Comodo protects its files as can be seen under Defense + --> Common Tasks --> My protected files.
In what mode are you testing the starting of the .bat file?
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
BoosTy
Newbie
Offline
Posts: 5
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #3 on:
September 19, 2009, 06:25:32 PM »
I ran it in paranoid mode and in safe mode heres what happens
I created test.bat file with del c:\123.txt
i put it in the c:\ directory
then I open up cmd and type in c:\test.bat
it executes with out any warning at all and the text file was deleted so what i am saying is, if someone gets on the machine, they can just execute .bat files all day long if there able to upload them and get into command, they can clean house or at least do damage , however when i try to exectue a .exe file in command comodo does its job and pops up asking me if its ok , and, also comodo does its job when i try to double click on a .bat file BUT IT WONT STOP IT IF EXECUTED IN COMMAND why not
Logged
SS26
Comodo's Hero
Offline
Posts: 1505
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #4 on:
September 19, 2009, 06:34:47 PM »
You mean that Defense+ of Comodo should treat .bat as programs (.exe)? For example, like KIS (see
this post
and
this post with screenshots
)?
Logged
HeffeD
Comodo's Hero
Offline
Posts: 1529
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #5 on:
September 19, 2009, 06:50:42 PM »
If someone runs a .bat on your system that tries to do anything malicious, CIS will warn you.
.bat files themselves are not dangerous. If you want though, you could add them to your blocked files.
Logged
Can
you
beat my gladiator?
BoosTy
Newbie
Offline
Posts: 5
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #6 on:
September 19, 2009, 06:59:03 PM »
Yes it should treat .bat the same as .exe otherwise its useless and I wont use it anymore because, this is how bot nets and root kits it makes there job easy all they have to do is upload a .bat if they get far enough and then they can just execute it inside telnet using command and your making there job easy they can do a lot with a .bat file see whats running delete things kill processes maybe even kill comodo or turn off a anti virus , so this has to be changed this is a big deal , if u guys make it so that it asks hey do u want command to run this .bat file I would love that it would increase protection big time please update this
Logged
HeffeD
Comodo's Hero
Offline
Posts: 1529
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #7 on:
September 19, 2009, 07:10:37 PM »
You can block them if you like....
Defense+ -> My Blocked Files -> Add -> File Groups -> Executables
You will now see .bat files on your blocked list.
Logged
Can
you
beat my gladiator?
BoosTy
Newbie
Offline
Posts: 5
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #8 on:
September 19, 2009, 07:14:50 PM »
lol well ya that will block all of them tho and what if i want some to be able to run
i just dont see why this isnt built into the program everything else about it is so good and then one door is left open
Logged
HeffeD
Comodo's Hero
Offline
Posts: 1529
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #9 on:
September 19, 2009, 07:32:05 PM »
It's not left open...
If the .bat tries to do anything malicious, CIS will stop it.
Logged
Can
you
beat my gladiator?
BoosTy
Newbie
Offline
Posts: 5
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #10 on:
September 19, 2009, 09:39:19 PM »
well the thing is the bat file i made and tested with was able to delete a file on the system is malicious, also the bat file could be used to gain extra info giving an attacker more info for the next step , is there a reason for letting this run i dont wanna keep posting on it i guess i feel like i'm getting no where I might have to use a different firewall other then comodo but i just love everything else about it would it be possible to include this as a option in a update ? I think it would be cool to at least give the option
Logged
SS26
Comodo's Hero
Offline
Posts: 1505
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #11 on:
September 20, 2009, 03:39:16 AM »
BoosTy
To achieve what you want with Defense+ of Comodo in Safe/Clean PC mode you can try following: set Image Execution controller to "normal" under Defense+/Advanced/Image Execution settings.
Result: if virus will attempt to execute malicious batch you will get Defense+ warning similar to "virus.exe tries to execute cmd.exe". If blocked
virus won't be able to call malicious batch
. However if you launch that batch by clicking on it in Windows Explorer, game is over. It is because explorer.exe is trusted and cmd.exe is trusted - activity will be learnt by Defense+. Great caution needed if you launch .bat and .cmd from Windows Explorer.
If you want to complete control over batch execution, try following using Paranoid mode of Defense+:
Quote from: SS26 on August 29, 2009, 03:21:35 AM
1st way is to treat cmd.exe as unsafe executable manually: do not let D+ remember anything for cmd.exe ever... maybe except calling your safe programs;
2nd way is to treat calls for cmd.exe from explorer.exe and rundll32.exe as unsafe, hence do not let D+ remember these calls.
of course, Image execution control must be turned on.
Logged
SS26
Comodo's Hero
Offline
Posts: 1505
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #12 on:
September 20, 2009, 03:51:04 AM »
Summary how i control any batch on my system:
Defense+ set to paranoid mode, Image Execution control is turned on.
explorer.exe is allowed to call cmd.exe.
cmd.exe has everything set to "ask" with exceptions to call bash.exe and other safe apps.
When batch is attempted to run by unknown program (virus) i get Defense+ warning.
When i launch batch from Windows explorer i get various alerts like "cmd.exe tries to do this and that". If i know this batch and sure it is what i want to run i choose to treat cmd.exe as trusted app without "remember my answer". If i don't know this batch or see suspicious behaviour i choose to treat cmd.exe as isolated app without "remember my answer".
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4397
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #13 on:
September 20, 2009, 05:31:50 PM »
Quote from: BoosTy on September 19, 2009, 06:25:32 PM
I ran it in paranoid mode and in safe mode heres what happens
I created test.bat file with del c:\123.txt
i put it in the c:\ directory
then I open up cmd and type in c:\test.bat
it executes with out any warning at all and the text file was deleted so what i am saying is, if someone gets on the machine, they can just execute .bat files all day long if there able to upload them and get into command, they can clean house or at least do damage , however when i try to exectue a .exe file in command comodo does its job and pops up asking me if its ok , and, also comodo does its job when i try to double click on a .bat file BUT IT WONT STOP IT IF EXECUTED IN COMMAND why not
I tried your scenario and when explorer.exe automatically starts cmd.exe you won't get an alert. However the c:\ folder is not a protected folder so you won't be alerted. When you store 123.txt in, say for example, c:\windows\system\ you will get alerted.
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
mxnerd
Newbie
Offline
Posts: 1
Re: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
«
Reply #14 on:
November 12, 2009, 03:07:29 PM »
I have an executable that needs a parameters to run. So I created a DOS batch file that appends the necessary parameter at the end of the executable.
I try to put the batch file an the executable in the "My Own Safe Files"list, but only the exe file is added. The batch file was always kicked out.
What can I do?
In training mode.
===============
OK. Found it was blocked by Computer Security Policy. It works now.
«
Last Edit: November 12, 2009, 03:59:10 PM by mxnerd
»
Logged
Tags:
.bat file execute
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.046 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com