Welcome, Guest. Please login or register.
December 27, 2009, 12:48:22 AM

Login with username, password and session length

345440 Posts
38149 Topics
86624 Members

Latest Member: gerrance

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Feedback/Comments/Announcements/News - CIS
| | | |-+  COMODO Leak Test Suite Release with 34 Tests! [CLOSED]
« previous next »
Pages: 1 ... 7 8 [9] Go Down Print
Author Topic: COMODO Leak Test Suite Release with 34 Tests! [CLOSED]  (Read 31871 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 8373



WWW
« Reply #120 on: November 15, 2008, 02:02:38 PM »

Can we pls report our results to this post

it will make sure users will have access to all the information about leak test results in one post rather than searching thru many threads..
thank you for your help

Melih
Logged

Leolas
Computer Security Testing Group
Comodo Family Member
*****
Offline Offline

Posts: 94



« Reply #121 on: November 16, 2008, 01:03:48 PM »

No. Most of these tests are previous leak tests. We have combined them into one suite. However we did include some new tests that we have NOT invented but malware writers were using. KnownDLLs tes for example. KnownDLLs test was used by some malware to inject code into applications and it is used heavily by advanced malware.

For QA, I have checked it personally with their current version. No OA is NOT passing all of them. There was a bug in CLT which was causing false results to be produced. This includes CIS too.

You might test with new version and inform your vendor to protect their customers asap....

egemen


I didn't say that CLT isn't a good test, or that is useless.
What I mean is that if I were firewall developer, I wouldn't make a test that my fw doesn't pass.
BTW, they've already been informed, and with CLT in run safer, OA passes all the tests. Anyway, I haven't written here to compare Comodo to OA, and I was jocking when I said that OA did better! It really scored 470 (I also linked the picture), but I know it was a bug.  Wink
Logged
lizard777
Comodo Member
**
Offline Offline

Posts: 46


« Reply #122 on: November 16, 2008, 03:10:24 PM »

Hi Everyone,

We have just released a COMODO Leak Tests Suite, which contains 34 leak tests in one suite.  It can be accessed from http://www.testmypcsecurity.com/securitytests/firewall_test_suite.html.

In this suite, you will find some old leak tests as well as a couple of new leak tests. Some of the new leak tests are created from the fedbcak from COMODO AV Labs and used actively by malware in the wild.

Feel free to test your PCs security. While testing CIS, you need to set CIS to COMODO Proactive Security inorder to get maximum results.

Egemen

I downloaded this version saved it to my desk top and scaned with with avira antivir and it said it was malware here is the report.

Avira AntiVir Personal
Report file date: Sunday, November 16, 2008  14:51

Scanning for 1035635 virus strains and unwanted programs.

Licensed to:      Avira AntiVir PersonalEdition Classic
Serial number:    0000149996-ADJIE-0001
Platform:         Windows Vista
Windows version:  (plain)  [6.0.6000]
Boot mode:        Normally booted
Username:         name
Computer name:    name

Version information:
BUILD.DAT     : 8.2.0.336      16933 Bytes  10/30/2008 11:40:00
AVSCAN.EXE    : 8.1.4.7       315649 Bytes   7/18/2008 21:59:38
AVSCAN.DLL    : 8.1.4.0        40705 Bytes   7/18/2008 21:59:38
LUKE.DLL      : 8.1.4.5       164097 Bytes   7/18/2008 21:59:40
LUKERES.DLL   : 8.1.4.0        12033 Bytes   7/18/2008 21:59:40
ANTIVIR0.VDF  : 7.1.0.0     15603712 Bytes  10/27/2008 23:35:43
ANTIVIR1.VDF  : 7.1.0.56      411136 Bytes   11/9/2008 19:13:26
ANTIVIR2.VDF  : 7.1.0.57        2048 Bytes   11/9/2008 19:13:27
ANTIVIR3.VDF  : 7.1.0.88      210944 Bytes  11/14/2008 21:38:22
Engineversion : 8.2.0.31 
AEVDF.DLL     : 8.1.0.6       102772 Bytes  10/15/2008 18:59:00
AESCRIPT.DLL  : 8.1.1.15      332156 Bytes  11/11/2008 22:01:43
AESCN.DLL     : 8.1.1.5       123251 Bytes   11/8/2008 00:25:10
AERDL.DLL     : 8.1.1.3       438645 Bytes   11/6/2008 00:33:40
AEPACK.DLL    : 8.1.3.4       393591 Bytes  11/11/2008 22:01:42
AEOFFICE.DLL  : 8.1.0.30      196986 Bytes   11/8/2008 00:25:09
AEHEUR.DLL    : 8.1.0.71     1487222 Bytes   11/8/2008 00:25:08
AEHELP.DLL    : 8.1.1.3       119157 Bytes   11/8/2008 00:25:05
AEGEN.DLL     : 8.1.1.0       319859 Bytes   11/8/2008 00:25:04
AEEMU.DLL     : 8.1.0.9       393588 Bytes  10/15/2008 18:58:52
AECORE.DLL    : 8.1.4.1       172405 Bytes   11/8/2008 00:25:03
AEBB.DLL      : 8.1.0.3        53618 Bytes  10/15/2008 18:58:50
AVWINLL.DLL   : 1.0.0.12       15105 Bytes   7/18/2008 21:59:38
AVPREF.DLL    : 8.0.2.0        38657 Bytes   7/18/2008 21:59:38
AVREP.DLL     : 8.0.0.2        98344 Bytes    8/2/2008 10:31:23
AVREG.DLL     : 8.0.0.1        33537 Bytes   7/18/2008 21:59:38
AVARKT.DLL    : 1.0.0.23      307457 Bytes   4/14/2008 21:52:18
AVEVTLOG.DLL  : 8.0.0.16      119041 Bytes   7/18/2008 21:59:38
SQLITE3.DLL   : 3.3.17.1      339968 Bytes   4/14/2008 21:52:19
SMTPLIB.DLL   : 1.2.0.23       28929 Bytes   7/18/2008 21:59:41
NETNT.DLL     : 8.0.0.1         7937 Bytes   4/14/2008 21:52:19
RCIMAGE.DLL   : 8.0.0.51     2371841 Bytes   7/18/2008 21:58:03
RCTEXT.DLL    : 8.0.52.0       86273 Bytes   7/18/2008 21:58:23

Configuration settings for the scan:
Jobname..........................: ShlExt
Configuration file...............: C:\Users\name~1\AppData\Local\Temp\5878db12.avp
Logging..........................: medium
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: off
Scan registry....................: off
Search for rootkits..............: off
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: off
Smart extensions.................: on
Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
Macro heuristic..................: on
File heuristic...................: high
Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

Start of the scan: Sunday, November 16, 2008  14:51

Starting the file scan:

Begin scan in 'C:\Users\name\Desktop\CLT.zip'
C:\Users\name\Desktop\
C:\Users\name\Desktop\CLT.zip
   
  • Archive type: ZIP
    --> plugins/BITS.dll
      [DETECTION] Contains recognition pattern of the SPR/KeyLogger.MN program
    --> plugins/Coat.dll
      [DETECTION] Contains HEUR/Malware suspicious code
    [NOTE]      The file was deleted!


End of the scan: Sunday, November 16, 2008  14:52
Used time: 00:47 Minute(s)

The scan has been done completely.

      0 Scanning directories
     40 Files were scanned
      1 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      1 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      0 Files cannot be scanned
     38 Files not concerned
      1 Archives were scanned
      0 Warnings
      1 Notes

Logged
Star Shadow
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 286


« Reply #123 on: November 16, 2008, 03:46:06 PM »

I downloaded this version saved it to my desk top and scaned with with avira antivir and it said it was malware here is the report.
[...snip...]
I can't call this a false positive because this is a test. CLT mimics the behavior of malware, so any good anti-virus program will flag this as a virus or malware. However, this is not really real malware. You can call this a vaccine, which is the virus, but dead, so your body builds up antibodies to fight the real infection and the vaccine doesn't cause the real infection. So, this is like dead malware only used to test the antibodies of a hips/firewall/antivirus program. So, this is safe, you can re-download it and tell avira not to delete anything. Tongue

Okay?
Logged

I'm getting Married!!!
lizard777
Comodo Member
**
Offline Offline

Posts: 46


« Reply #124 on: November 16, 2008, 06:19:29 PM »

I can't call this a false positive because this is a test. CLT mimics the behavior of malware, so any good anti-virus program will flag this as a virus or malware. However, this is not really real malware. You can call this a vaccine, which is the virus, but dead, so your body builds up antibodies to fight the real infection and the vaccine doesn't cause the real infection. So, this is like dead malware only used to test the antibodies of a hips/firewall/antivirus program. So, this is safe, you can re-download it and tell avira not to delete anything. Tongue

Okay?

Thanks. so avira did delete both of those things right not just one? i will run it again later.
Logged
ailef
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 699



« Reply #125 on: November 16, 2008, 06:55:14 PM »

i tested avira antivir premium on xp pro SP3 and it scored 110/340.
if someone can test antivir premium suite...
for info vista 64-bit SP1 ultimate without any security tool scored 180/340...
Logged

xps M1330[at]T9500 - Windows 7 ultimate 64bit - comodo 3.13 build 574 - KAV 2010 build 736
nalacknick
Comodo Family Member
***
Offline Offline

Posts: 87


« Reply #126 on: November 17, 2008, 02:28:20 PM »

I tried the test with the pro active setting and got 340/340......that's great........but the default setting of a fresh install is Internet security and when I tried this option I only got 300/340. Do I have anything to worry about if left on (default) Internet security?. I am not an expert user and so I prefer this setting because there seems to be less pop-ups than proactive setting.
Thanks
Nick
Logged
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2151



« Reply #127 on: November 17, 2008, 02:56:38 PM »

I tried the test with the pro active setting and got 340/340......that's great........but the default setting of a fresh install is Internet security and when I tried this option I only got 300/340. Do I have anything to worry about if left on (default) Internet security?. I am not an expert user and so I prefer this setting because there seems to be less pop-ups than proactive setting.
Thanks
Nick

No you do not need to worry about. Because we have antivirus to mitigate the infection risk. Also Internet Security configuration is hardened to keep all of the infection points. For example, registry, important files etc are protected.

So defaults are good enough.
Logged
AeoniAn
Comodo's Hero
*****
Offline Offline

Posts: 243


Protected & Armoured. COMODO is here!


« Reply #128 on: November 17, 2008, 11:54:42 PM »

(sorry guys for the short break, but my 2 cents to the topic is:)

340/340 = all passed.

 Cheers
Logged

CIS v574 full: Proactive, FW Custom, D+ Paranoid, IE normal, AV statf, heur med.
Sempron 3000+, MB MSI-7145, 1GB RAM
XP-SP3-Pro-BR x32 + W7-64 + Ubuntu LTS x64
ADM rights, Cable-PPPoA
PeerBlock v1.0+r
A-SquaredAM + MBAM + SAS (w/o any real-time)
Zero, Nada, No-one single infecction >49 months
shadha
Comodo Loves me
****
Offline Offline

Posts: 108


« Reply #129 on: November 18, 2008, 02:11:42 AM »

Hi Guys,
I just tried the suite of tests and it only failed 1 test, "Hijacking: Startup programs    Vulnerable". Does anybody have any idea why and how I can fix this. I got a score of 310/320 and I want it to be 320. Apart from this small glitch all is well and once again gentlemen you have excelled. Keep up the good work. While I am writing when will there be a tag in the email body saying that the email has been scanned. AVG Avast NOD32 do it and I think it is a great feature. It gives me the confidence and my customers the confidence that the email has been scanned. I have asked this question before and I did get the answer that everything is scanned but I would like this notification in the body of the email and not as an attachement.
All the best Guys
shadha Clapping (B)
Logged
ganda claus
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5603


ho ho ho


« Reply #130 on: November 18, 2008, 03:42:51 AM »

hi there shadha Wave
make sure you tick all of the tickable option  Grin
Defense+/advanced/defense+ settings/monitor settings

no, CIS doesn't have email scanner. not yet. but it doesn't really matter cos CIS realtime protection will still catch the malware on email attachment (or everywhere on your comp) once it's executed.
Logged
nalacknick
Comodo Family Member
***
Offline Offline

Posts: 87


« Reply #131 on: November 18, 2008, 04:50:01 AM »

No you do not need to worry about. Because we have antivirus to mitigate the infection risk. Also Internet Security configuration is hardened to keep all of the infection points. For example, registry, important files etc are protected.

So defaults are good enough.

Thx for the info/re assurance egemen.............I knew Comodo wouldn't let me down  Smiler Cheers
Logged
3xist
Guest
« Reply #132 on: November 21, 2008, 08:22:11 PM »

There is a new thread here with the updated version: http://forums.comodo.com/leak_testingattacksvulnerability_research/comodo_leak_test_suite_updated_version-t30110.0.html

Thread Closed. :-)

Josh
Logged
Tags:
Pages: 1 ... 7 8 [9] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.079 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com