Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 19, 2013, 03:04:53 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
668819
Posts
71128
Topics
145741
Members
Latest Member:
bsjt
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
General Security Questions and Comments
Please feel free to ask any questions to learn all about Computer Security.
« previous
next »
Pages:
[
1
]
2
3
...
16
Author
Topic: Please feel free to ask any questions to learn all about Computer Security. (Read 155812 times)
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Please feel free to ask any questions to learn all about Computer Security.
«
on:
December 30, 2006, 10:13:47 PM »
Here you will have access to the world's best security experts to help you learn all about Computer security!
feel free to ask!
Melih
«
Last Edit: December 30, 2006, 10:16:03 PM by Melih
»
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
AOwL
Comodo SuperHero
Comodo's Hero
Offline
Posts: 2349
Comodo Firewall Pro - Be safe, use protection...
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #1 on:
January 26, 2007, 11:10:58 PM »
Ok, now about security.
Does V 3 of CFP protect us against the exploit of mshta.exe?
Why doesn't more malware use it, since it seems to be efficient?
Is HIPS the only way to do that?
In greenborder.com they use a GreenBorder-Security-Test.hta file that you download and run.
It uses mshta.exe (just like some new malware) to create a folder on your desktop with "stolen" documents and so on... It also creates a mshta.exe.mui on your desktop.
It creates a scriptfile that do a "eggdrop"...?
It's called GreenBorderEgDrop.js that do something and saves to "GreenBorderPsSee.exe".
Both files are found in C:\Documents and Settings\YourName\Local settings\Temp
There is something about a MZKERNEL32.DLL...
I found mshta.exe in three folders.
windows\ie7
windows\system32
windows\system32\dllcache
I found some info that it use lsass.exe so that the process talks to LSASS and it reads the data from the
registry, this path is not visible from the Admin context. Permissions needs to be changed to read
it. (stealing passwords?)
These are my observations without knowledge in programming or using special tools.
It would be nice if someone at Comodo explain this test/scenario in a normal language.
The main question is, should I keep mshta.exe renamed?
Do you know if it's needed in other files than .hta?
I only found one .hta file on my PC besides those testfiles. It was for WMP.
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #2 on:
January 27, 2007, 09:08:33 AM »
Quote from: AOwL on January 26, 2007, 11:10:58 PM
Ok, now about security.
Does V 3 of CFP protect us against the exploit of mshta.exe?
Why doesn't more malware use it, since it seems to be efficient?
Is HIPS the only way to do that?
In greenborder.com they use a GreenBorder-Security-Test.hta file that you download and run.
It uses mshta.exe (just like some new malware) to create a folder on your desktop with "stolen" documents and so on... It also creates a mshta.exe.mui on your desktop.
It creates a scriptfile that do a "eggdrop"...?
It's called GreenBorderEgDrop.js that do something and saves to "GreenBorderPsSee.exe".
Both files are found in C:\Documents and Settings\YourName\Local settings\Temp
There is something about a MZKERNEL32.DLL...
I found mshta.exe in three folders.
windows\ie7
windows\system32
windows\system32\dllcache
I found some info that it use lsass.exe so that the process talks to LSASS and it reads the data from the
registry, this path is not visible from the Admin context. Permissions needs to be changed to read
it. (stealing passwords?)
These are my observations without knowledge in programming or using special tools.
It would be nice if someone at Comodo explain this test/scenario in a normal language.
The main question is, should I keep mshta.exe renamed?
Do you know if it's needed in other files than .hta?
I only found one .hta file on my PC besides those testfiles. It was for WMP.
Indeed we will protect against that too with v3!
CFP v3 will be the First line of defense against malware!
CFP v3 will create a quantum shift in the security market from AV being your first line of defense to CFP v3 being your first line of defense against Malware! The time for allowing everything and only catch whats bad (if you know what is bad that is) (eg: AV products today..) is passed its sell by date! we need a proper protection.. we need CFP v3!!
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
AOwL
Comodo SuperHero
Comodo's Hero
Offline
Posts: 2349
Comodo Firewall Pro - Be safe, use protection...
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #3 on:
January 27, 2007, 09:20:14 AM »
That sounds great!
That mshta.exe exploit still worries me though...
CFP 3 isn't out yet...
If you need the source files and the created script and program files from that test, just let me know.
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #4 on:
January 28, 2007, 09:36:56 AM »
Quote from: AOwL on January 27, 2007, 09:20:14 AM
That sounds great!
That mshta.exe exploit still worries me though...
CFP 3 isn't out yet...
If you need the source files and the created script and program files from that test, just let me know.
sure go ahead and send it across pls.
thanks
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
bedo
Newbie
Offline
Posts: 1
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #5 on:
January 31, 2007, 06:01:34 PM »
Hi, I'm a new user.
Is there anyway I can secure individual documents from getting leaked.
For example, my cv. It's all good and well that my pc and identity is hidden from malicious web users but if someone gets access to my personal files, well, that is scary.
Can this be done with Comodo or do I need another type of programme?
Bedo
Logged
BOO BERRY
Newbie
Offline
Posts: 1
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #6 on:
February 09, 2007, 04:02:07 AM »
HI! I WENT TO E-MULE TO DOWNLOAD SONGS, AND I CHANGED MY MIND AND UNINSTALLED IT.....BUT NOW I AM GETTTING LITERALLY HUNDREDS OF BLOCKED INTERNET ACCESS ATTACKS, BLOCKED BY MY ZONE ALARM FIREWALL. JUST INSTALLED THE COMODO. I AM NOT AT ALL COMPUTER SAVVY, COULD YOU GIVE ME SOME ADVICE ON HOW TO STOP THESE ATTACKS.......THANK-YOU
Logged
N.T.T.W.
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #7 on:
February 09, 2007, 04:48:42 AM »
Quote from: BOO BERRY on February 09, 2007, 04:02:07 AM
HI! I WENT TO E-MULE TO DOWNLOAD SONGS, AND I CHANGED MY MIND AND UNINSTALLED IT.....BUT NOW I AM GETTTING LITERALLY HUNDREDS OF BLOCKED INTERNET ACCESS ATTACKS, BLOCKED BY MY ZONE ALARM FIREWALL. JUST INSTALLED THE COMODO. I AM NOT AT ALL COMPUTER SAVVY, COULD YOU GIVE ME SOME ADVICE ON HOW TO STOP THESE ATTACKS.......THANK-YOU
Sounds like you picked up some nasties while downloading Emule.
Firstly I would use a cleaner such as the free CCleaner and delete all temporary files, cookies etc.
Then I would download Spybot Search and Destroy, update it, use the immunize feature and then run a full scan. Use spybot to remove any malware entries it finds. You can also use Spybot to view and remove any browser helper objects or active x components that are undesirable.
Next, make sure your antivirus is up to date and run a full scan - this should hopefully find any traces of malware on your pc.
Ad-Aware SE personal is also free and sometimes finds things your antivirus or spybot miss.
If this does not solve your problem then post again and I am sure someone will offer further advice.
Links:
p://www.ccleaner.com/
http://www.spybot.info/
http://www.lavasoftusa.com/
I would certainly recommend the latest Comodo Firewall Pro and CAVS beta.
Logged
Post proelia praemia.
Die dulci fruere.
longhauldump
Newbie
Offline
Posts: 1
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #8 on:
February 24, 2007, 04:40:20 PM »
Melih,
I am a second user..supposed to be administration on win32 application..win 32 says comodo firewall is not a valid win32 application and won't let me down load..what should I do?
Logged
tazzbuds
Guest
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #9 on:
February 27, 2007, 02:43:34 AM »
Quote from: bedo on January 31, 2007, 06:01:34 PM
Hi, I'm a new user.
Is there anyway I can secure individual documents from getting leaked.
For example, my cv. It's all good and well that my pc and identity is hidden from malicious web users but if someone gets access to my personal files, well, that is scary.
Can this be done with Comodo or do I need another type of programme?
Bedo
hello yes comodo site u will see a software program its shows a dload that secures your notes but beware if u dont save it all u will lose it so yes go to comodo site and read up u will find it on your right side or on anuther page contact me [ at ] harry_markee [ at ] yahoo.com
«
Last Edit: February 27, 2007, 06:36:20 AM by panic
»
Logged
NoPayne
Newbie
Offline
Posts: 18
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #10 on:
February 28, 2007, 10:44:49 AM »
Quote from: Melih on December 30, 2006, 10:13:47 PM
Here you will have access to the world's best security experts to help you learn all about Computer security! feel free to ask!
Why is it you have time to answer questions about computer security, but you don't have time to answer support requests with helpful information that will make the Comodo firewall install and work properly on my computer?
I submitted support requests over a month ago about the screwed up Comodo 2.4 installer that have gone unanswered. I have requested assistance in the forums that have also been ignored.
I can find answers all over the internet to my computer security questions. But, Comodo is the authority on Comodo products, and I would expect to get reliable answers here that will help me get Comodo to install and work properly. Why not put a little more effort into supporting the guinea pigs who test your beta releases???
Logged
NoPayne
Newbie
Offline
Posts: 18
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #11 on:
February 28, 2007, 11:00:36 AM »
Quote from: Melih on January 27, 2007, 09:08:33 AM
CFP v3 will be the First line of defense against malware!
CFP v3 will create a quantum shift in the security market from AV being your first line of defense to CFP v3 being your first line of defense against Malware! The time for allowing everything and only catch whats bad (if you know what is bad that is) (eg: AV products today..) is passed its sell by date! we need a proper protection.. we need CFP v3!!
Oh, great. So, instead of having a nice little firewall that does what a firewall is supposed to do, you're going to turn Comodo Firewall into another over-bloated suite that attempts to be all things to all people, like ZoneAlarm or Norton. "Do everything" suites are EXACTLY what I was trying to avoid when I came to Comodo.
And, then, or course, you will have "dumb down" the interface so every novice idiot can read the cartoon icons and not have learn anything useful or think about what they're doing. Good grief!!!
Logged
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #12 on:
February 28, 2007, 12:26:47 PM »
Quote from: NoPayne on February 28, 2007, 10:44:49 AM
Why is it you have time to answer questions about computer security, but you don't have time to answer support requests with helpful information that will make the Comodo firewall install and work properly on my computer?
I submitted support requests over a month ago about the screwed up Comodo 2.4 installer that have gone unanswered. I have requested assistance in the forums that have also been ignored.
I can find answers all over the internet to my computer security questions. But, Comodo is the authority on Comodo products, and I would expect to get reliable answers here that will help me get Comodo to install and work properly. Why not put a little more effort into supporting the guinea pigs who test your beta releases???
NoPayne...
it certainly is not our wish or desire not to answer our users. I am sorry if we haven't. You can use the forums to ask these questions if you wish. If not, pls forward me your support ticket no and let me see where the system has failed in answering you.
thanks
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Melih
CEO - Comodo
Administrator
Comodo's Hero
Offline
Posts: 12944
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #13 on:
February 28, 2007, 12:27:23 PM »
Quote from: NoPayne on February 28, 2007, 11:00:36 AM
Oh, great. So, instead of having a nice little firewall that does what a firewall is supposed to do, you're going to turn Comodo Firewall into another over-bloated suite that attempts to be all things to all people, like ZoneAlarm or Norton. "Do everything" suites are EXACTLY what I was trying to avoid when I came to Comodo.
And, then, or course, you will have "dumb down" the interface so every novice idiot can read the cartoon icons and not have learn anything useful or think about what they're doing. Good grief!!!
What you are describing is not our intention at all
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
NoPayne
Newbie
Offline
Posts: 18
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #14 on:
February 28, 2007, 02:02:31 PM »
I'm releived. javascript:void(0);
Bounce
I'm sure whatever changes are in store will be innovative. I hope they will be efficient and not too imposing.
NP
Logged
Tags:
Pages:
[
1
]
2
3
...
16
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.054 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com