Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 29, 2009, 10:43:41 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
346002
Posts
38216
Topics
86797
Members
Latest Member:
tommi2415
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
General Security Questions and Comments (not product related)
Please feel free to ask any questions to learn all about Computer Security.
« previous
next »
Pages:
[
1
]
2
3
...
8
Author
Topic: Please feel free to ask any questions to learn all about Computer Security. (Read 49650 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8374
Please feel free to ask any questions to learn all about Computer Security.
«
on:
December 30, 2006, 10:13:47 PM »
Here you will have access to the world's best security experts to help you learn all about Computer security!
feel free to ask!
Melih
«
Last Edit: December 30, 2006, 10:16:03 PM by Melih
»
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
AOwL
Comodo SuperHero
Global Moderator
Comodo's Hero
Offline
Posts: 2349
Comodo Firewall Pro - Be safe, use protection...
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #1 on:
January 26, 2007, 11:10:58 PM »
Ok, now about security.
Does V 3 of CFP protect us against the exploit of mshta.exe?
Why doesn't more malware use it, since it seems to be efficient?
Is HIPS the only way to do that?
In greenborder.com they use a GreenBorder-Security-Test.hta file that you download and run.
It uses mshta.exe (just like some new malware) to create a folder on your desktop with "stolen" documents and so on... It also creates a mshta.exe.mui on your desktop.
It creates a scriptfile that do a "eggdrop"...?
It's called GreenBorderEgDrop.js that do something and saves to "GreenBorderPsSee.exe".
Both files are found in C:\Documents and Settings\YourName\Local settings\Temp
There is something about a MZKERNEL32.DLL...
I found mshta.exe in three folders.
windows\ie7
windows\system32
windows\system32\dllcache
I found some info that it use lsass.exe so that the process talks to LSASS and it reads the data from the
registry, this path is not visible from the Admin context. Permissions needs to be changed to read
it. (stealing passwords?)
These are my observations without knowledge in programming or using special tools.
It would be nice if someone at Comodo explain this test/scenario in a normal language.
The main question is, should I keep mshta.exe renamed?
Do you know if it's needed in other files than .hta?
I only found one .hta file on my PC besides those testfiles. It was for WMP.
Logged
WinXP SP2 HE - IE7 - FF 2 - TB - CFP 2.4 - NOD32 - BoClean -ST - AMD64x2 - 3Gb Ram - 1.5Tb HD
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8374
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #2 on:
January 27, 2007, 09:08:33 AM »
Quote from: AOwL on January 26, 2007, 11:10:58 PM
Ok, now about security.
Does V 3 of CFP protect us against the exploit of mshta.exe?
Why doesn't more malware use it, since it seems to be efficient?
Is HIPS the only way to do that?
In greenborder.com they use a GreenBorder-Security-Test.hta file that you download and run.
It uses mshta.exe (just like some new malware) to create a folder on your desktop with "stolen" documents and so on... It also creates a mshta.exe.mui on your desktop.
It creates a scriptfile that do a "eggdrop"...?
It's called GreenBorderEgDrop.js that do something and saves to "GreenBorderPsSee.exe".
Both files are found in C:\Documents and Settings\YourName\Local settings\Temp
There is something about a MZKERNEL32.DLL...
I found mshta.exe in three folders.
windows\ie7
windows\system32
windows\system32\dllcache
I found some info that it use lsass.exe so that the process talks to LSASS and it reads the data from the
registry, this path is not visible from the Admin context. Permissions needs to be changed to read
it. (stealing passwords?)
These are my observations without knowledge in programming or using special tools.
It would be nice if someone at Comodo explain this test/scenario in a normal language.
The main question is, should I keep mshta.exe renamed?
Do you know if it's needed in other files than .hta?
I only found one .hta file on my PC besides those testfiles. It was for WMP.
Indeed we will protect against that too with v3!
CFP v3 will be the First line of defense against malware!
CFP v3 will create a quantum shift in the security market from AV being your first line of defense to CFP v3 being your first line of defense against Malware! The time for allowing everything and only catch whats bad (if you know what is bad that is) (eg: AV products today..) is passed its sell by date! we need a proper protection.. we need CFP v3!!
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
AOwL
Comodo SuperHero
Global Moderator
Comodo's Hero
Offline
Posts: 2349
Comodo Firewall Pro - Be safe, use protection...
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #3 on:
January 27, 2007, 09:20:14 AM »
That sounds great!
That mshta.exe exploit still worries me though...
CFP 3 isn't out yet...
If you need the source files and the created script and program files from that test, just let me know.
Logged
WinXP SP2 HE - IE7 - FF 2 - TB - CFP 2.4 - NOD32 - BoClean -ST - AMD64x2 - 3Gb Ram - 1.5Tb HD
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8374
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #4 on:
January 28, 2007, 09:36:56 AM »
Quote from: AOwL on January 27, 2007, 09:20:14 AM
That sounds great!
That mshta.exe exploit still worries me though...
CFP 3 isn't out yet...
If you need the source files and the created script and program files from that test, just let me know.
sure go ahead and send it across pls.
thanks
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
bedo
Newbie
Offline
Posts: 1
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #5 on:
January 31, 2007, 06:01:34 PM »
Hi, I'm a new user.
Is there anyway I can secure individual documents from getting leaked.
For example, my cv. It's all good and well that my pc and identity is hidden from malicious web users but if someone gets access to my personal files, well, that is scary.
Can this be done with Comodo or do I need another type of programme?
Bedo
Logged
BOO BERRY
Newbie
Offline
Posts: 1
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #6 on:
February 09, 2007, 04:02:07 AM »
HI! I WENT TO E-MULE TO DOWNLOAD SONGS, AND I CHANGED MY MIND AND UNINSTALLED IT.....BUT NOW I AM GETTTING LITERALLY HUNDREDS OF BLOCKED INTERNET ACCESS ATTACKS, BLOCKED BY MY ZONE ALARM FIREWALL. JUST INSTALLED THE COMODO. I AM NOT AT ALL COMPUTER SAVVY, COULD YOU GIVE ME SOME ADVICE ON HOW TO STOP THESE ATTACKS.......THANK-YOU
Logged
N.T.T.W.
Global Moderator
Comodo's Hero
Offline
Posts: 1124
A minute of your time can help many.
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #7 on:
February 09, 2007, 04:48:42 AM »
Quote from: BOO BERRY on February 09, 2007, 04:02:07 AM
HI! I WENT TO E-MULE TO DOWNLOAD SONGS, AND I CHANGED MY MIND AND UNINSTALLED IT.....BUT NOW I AM GETTTING LITERALLY HUNDREDS OF BLOCKED INTERNET ACCESS ATTACKS, BLOCKED BY MY ZONE ALARM FIREWALL. JUST INSTALLED THE COMODO. I AM NOT AT ALL COMPUTER SAVVY, COULD YOU GIVE ME SOME ADVICE ON HOW TO STOP THESE ATTACKS.......THANK-YOU
Sounds like you picked up some nasties while downloading Emule.
Firstly I would use a cleaner such as the free CCleaner and delete all temporary files, cookies etc.
Then I would download Spybot Search and Destroy, update it, use the immunize feature and then run a full scan. Use spybot to remove any malware entries it finds. You can also use Spybot to view and remove any browser helper objects or active x components that are undesirable.
Next, make sure your antivirus is up to date and run a full scan - this should hopefully find any traces of malware on your pc.
Ad-Aware SE personal is also free and sometimes finds things your antivirus or spybot miss.
If this does not solve your problem then post again and I am sure someone will offer further advice.
Links:
p://www.ccleaner.com/
http://www.spybot.info/
http://www.lavasoftusa.com/
I would certainly recommend the latest Comodo Firewall Pro and CAVS beta.
Logged
Post proelia praemia.
Die dulci fruere.
longhauldump
Newbie
Offline
Posts: 1
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #8 on:
February 24, 2007, 04:40:20 PM »
Melih,
I am a second user..supposed to be administration on win32 application..win 32 says comodo firewall is not a valid win32 application and won't let me down load..what should I do?
Logged
tazzbuds
Guest
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #9 on:
February 27, 2007, 02:43:34 AM »
Quote from: bedo on January 31, 2007, 06:01:34 PM
Hi, I'm a new user.
Is there anyway I can secure individual documents from getting leaked.
For example, my cv. It's all good and well that my pc and identity is hidden from malicious web users but if someone gets access to my personal files, well, that is scary.
Can this be done with Comodo or do I need another type of programme?
Bedo
hello yes comodo site u will see a software program its shows a dload that secures your notes but beware if u dont save it all u will lose it so yes go to comodo site and read up u will find it on your right side or on anuther page contact me [ at ] harry_markee [ at ] yahoo.com
«
Last Edit: February 27, 2007, 06:36:20 AM by panic
»
Logged
NoPayne
Newbie
Offline
Posts: 18
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #10 on:
February 28, 2007, 10:44:49 AM »
Quote from: Melih on December 30, 2006, 10:13:47 PM
Here you will have access to the world's best security experts to help you learn all about Computer security! feel free to ask!
Why is it you have time to answer questions about computer security, but you don't have time to answer support requests with helpful information that will make the Comodo firewall install and work properly on my computer?
I submitted support requests over a month ago about the screwed up Comodo 2.4 installer that have gone unanswered. I have requested assistance in the forums that have also been ignored.
I can find answers all over the internet to my computer security questions. But, Comodo is the authority on Comodo products, and I would expect to get reliable answers here that will help me get Comodo to install and work properly. Why not put a little more effort into supporting the guinea pigs who test your beta releases???
Logged
NoPayne
Newbie
Offline
Posts: 18
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #11 on:
February 28, 2007, 11:00:36 AM »
Quote from: Melih on January 27, 2007, 09:08:33 AM
CFP v3 will be the First line of defense against malware!
CFP v3 will create a quantum shift in the security market from AV being your first line of defense to CFP v3 being your first line of defense against Malware! The time for allowing everything and only catch whats bad (if you know what is bad that is) (eg: AV products today..) is passed its sell by date! we need a proper protection.. we need CFP v3!!
Oh, great. So, instead of having a nice little firewall that does what a firewall is supposed to do, you're going to turn Comodo Firewall into another over-bloated suite that attempts to be all things to all people, like ZoneAlarm or Norton. "Do everything" suites are EXACTLY what I was trying to avoid when I came to Comodo.
And, then, or course, you will have "dumb down" the interface so every novice idiot can read the cartoon icons and not have learn anything useful or think about what they're doing. Good grief!!!
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8374
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #12 on:
February 28, 2007, 12:26:47 PM »
Quote from: NoPayne on February 28, 2007, 10:44:49 AM
Why is it you have time to answer questions about computer security, but you don't have time to answer support requests with helpful information that will make the Comodo firewall install and work properly on my computer?
I submitted support requests over a month ago about the screwed up Comodo 2.4 installer that have gone unanswered. I have requested assistance in the forums that have also been ignored.
I can find answers all over the internet to my computer security questions. But, Comodo is the authority on Comodo products, and I would expect to get reliable answers here that will help me get Comodo to install and work properly. Why not put a little more effort into supporting the guinea pigs who test your beta releases???
NoPayne...
it certainly is not our wish or desire not to answer our users. I am sorry if we haven't. You can use the forums to ask these questions if you wish. If not, pls forward me your support ticket no and let me see where the system has failed in answering you.
thanks
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8374
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #13 on:
February 28, 2007, 12:27:23 PM »
Quote from: NoPayne on February 28, 2007, 11:00:36 AM
Oh, great. So, instead of having a nice little firewall that does what a firewall is supposed to do, you're going to turn Comodo Firewall into another over-bloated suite that attempts to be all things to all people, like ZoneAlarm or Norton. "Do everything" suites are EXACTLY what I was trying to avoid when I came to Comodo.
And, then, or course, you will have "dumb down" the interface so every novice idiot can read the cartoon icons and not have learn anything useful or think about what they're doing. Good grief!!!
What you are describing is not our intention at all
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
NoPayne
Newbie
Offline
Posts: 18
Re: Please feel free to ask any questions to learn all about Computer Security.
«
Reply #14 on:
February 28, 2007, 02:02:31 PM »
I'm releived. javascript:void(0);
Bounce
I'm sure whatever changes are in store will be innovative. I hope they will be efficient and not too imposing.
NP
Logged
Tags:
Pages:
[
1
]
2
3
...
8
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.1 seconds with 16 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com