Welcome, Guest. Please login or register.
December 11, 2009, 02:56:35 PM

Login with username, password and session length

341732 Posts
37763 Topics
85747 Members

Latest Member: HUfantom

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Defense+ Help
| | | | |-+  Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Found Problem in COMODO it blocks .exe files when ran from cmd but not .bat  (Read 1315 times)
BoosTy
Newbie
*
Offline Offline

Posts: 5


« on: September 19, 2009, 01:23:39 PM »

I did some testing and I was able to execute .bat files in cmd it blocks .exe but it wont block .bat files like it should please fix this bug its a big open door people can just upload a .bat file execute it and wipe out comodo so please patch this and give me credit for finding it lol !
Logged
HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1480


« Reply #1 on: September 19, 2009, 03:33:45 PM »

Create a .bat file that will wipe out CIS, then let us know.  Wink
Logged

EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4160



« Reply #2 on: September 19, 2009, 06:06:50 PM »

Create a .bat file that will wipe out CIS, then let us know.  Wink
Comodo protects its files as can be seen under Defense + --> Common Tasks --> My protected files.

In what mode are you testing the starting of the .bat file?
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
BoosTy
Newbie
*
Offline Offline

Posts: 5


« Reply #3 on: September 19, 2009, 06:25:32 PM »

I ran it in paranoid mode and in safe mode heres what happens

I created test.bat file with       del c:\123.txt

i put it in the c:\ directory

then I open up cmd and type in c:\test.bat

it executes with out any warning at all and the text file was deleted so what i am saying is, if someone gets on the machine, they can just execute .bat files all day long if there able to upload them and get into command, they can clean house or at least do damage , however when i try to exectue a .exe file in command comodo does its job and pops up asking me if its ok , and, also comodo does its job when i try to double click on a .bat file BUT IT WONT STOP IT IF EXECUTED IN COMMAND why not Huh
Logged
SS26
Comodo's Hero
*****
Offline Offline

Posts: 1454


« Reply #4 on: September 19, 2009, 06:34:47 PM »

You mean that Defense+ of Comodo should treat .bat as programs (.exe)? For example, like KIS (see this post and this post with screenshots)?
Logged
HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1480


« Reply #5 on: September 19, 2009, 06:50:42 PM »

If someone runs a .bat on your system that tries to do anything malicious, CIS will warn you.

.bat files themselves are not dangerous. If you want though, you could add them to your blocked files.
Logged

BoosTy
Newbie
*
Offline Offline

Posts: 5


« Reply #6 on: September 19, 2009, 06:59:03 PM »

Yes it should treat .bat the same as .exe otherwise its useless and I wont use it anymore because, this is how bot nets and root kits it makes there job easy all they have to do is upload a .bat if they get far enough and then they can just execute it inside telnet using command and your making there job easy they can do a lot with a .bat file see whats running delete things kill processes maybe even kill comodo or turn off a anti virus , so this has to be changed this is a big deal , if u guys make it so that it asks hey do u want command to run this .bat file I would love that it would increase protection big time please update this
Logged
HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1480


« Reply #7 on: September 19, 2009, 07:10:37 PM »

You can block them if you like....  Roll Eyes

Defense+ -> My Blocked Files -> Add -> File Groups -> Executables

You will now see .bat files on your blocked list.
Logged

BoosTy
Newbie
*
Offline Offline

Posts: 5


« Reply #8 on: September 19, 2009, 07:14:50 PM »

lol well ya that will block all of them tho and what if i want some to be able to run Huh i just dont see why this isnt built into the program everything else about it is so good and then one door is left open
Logged
HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1480


« Reply #9 on: September 19, 2009, 07:32:05 PM »

It's not left open...

If the .bat tries to do anything malicious, CIS will stop it.
Logged

BoosTy
Newbie
*
Offline Offline

Posts: 5


« Reply #10 on: September 19, 2009, 09:39:19 PM »

well the thing is the bat file i made and tested with was able to delete a file on the system  is malicious, also the bat file could be used to gain extra info giving an attacker more info for the next step , is there a reason for letting this run i dont wanna keep posting on it i guess i feel like i'm getting no where I might have to use a different firewall other then comodo but i just love everything else about it would it be possible to include this as a option in a update  ? I think it would be cool to at least give the option
Logged
SS26
Comodo's Hero
*****
Offline Offline

Posts: 1454


« Reply #11 on: September 20, 2009, 03:39:16 AM »

BoosTy

To achieve what you want with Defense+ of Comodo in Safe/Clean PC mode you can try following: set Image Execution controller to "normal" under Defense+/Advanced/Image Execution settings.
Result: if virus will attempt to execute malicious batch you will get Defense+ warning similar to "virus.exe tries to execute cmd.exe". If blocked virus won't be able to call malicious batch. However if you launch that batch by clicking on it in Windows Explorer, game is over. It is because explorer.exe is trusted and cmd.exe is trusted - activity will be learnt by Defense+. Great caution needed if you launch .bat and .cmd from Windows Explorer.

If you want to complete control over batch execution, try following using Paranoid mode of Defense+:
1st way is to treat cmd.exe as unsafe executable manually: do not let D+ remember anything for cmd.exe ever... maybe except calling your safe programs;

2nd way is to treat calls for cmd.exe from explorer.exe and rundll32.exe as unsafe, hence do not let D+ remember these calls.

of course, Image execution control must be turned on.


 
Logged
SS26
Comodo's Hero
*****
Offline Offline

Posts: 1454


« Reply #12 on: September 20, 2009, 03:51:04 AM »

Summary how i control any batch on my system:
 
Defense+ set to paranoid mode, Image Execution control is turned on.
explorer.exe is allowed to call cmd.exe.
cmd.exe has everything set to "ask" with exceptions to call bash.exe and other safe apps.

When batch is attempted to run by unknown program (virus) i get Defense+ warning.
When i launch batch from Windows explorer i get various alerts like "cmd.exe tries to do this and that". If i know this batch and sure it is what i want to run i choose to treat cmd.exe as trusted app without "remember my answer". If i don't know this batch or see suspicious behaviour i choose to treat cmd.exe as isolated app without "remember my answer".
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4160



« Reply #13 on: September 20, 2009, 05:31:50 PM »

I ran it in paranoid mode and in safe mode heres what happens

I created test.bat file with       del c:\123.txt

i put it in the c:\ directory

then I open up cmd and type in c:\test.bat

it executes with out any warning at all and the text file was deleted so what i am saying is, if someone gets on the machine, they can just execute .bat files all day long if there able to upload them and get into command, they can clean house or at least do damage , however when i try to exectue a .exe file in command comodo does its job and pops up asking me if its ok , and, also comodo does its job when i try to double click on a .bat file BUT IT WONT STOP IT IF EXECUTED IN COMMAND why not Huh
I tried your scenario and when explorer.exe automatically starts cmd.exe you won't get an alert. However the c:\ folder is not a protected folder so you won't be alerted. When you store 123.txt in, say for example, c:\windows\system\ you will get alerted.
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
mxnerd
Newbie
*
Offline Offline

Posts: 1


« Reply #14 on: November 12, 2009, 03:07:29 PM »

I have an executable that needs a parameters to run.  So I created a DOS batch file that appends the necessary parameter at the end of the executable.

I try to put the batch file an the executable in the "My Own Safe Files"list, but only the exe file is added.  The batch file was always kicked out.

What can I do?

In training mode.

===============

OK.  Found it was blocked by Computer Security Policy.  It works now.
« Last Edit: November 12, 2009, 03:59:10 PM by mxnerd » Logged
Tags: .bat file execute 
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.046 seconds with 20 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com