Welcome, Guest. Please login or register.
Did you miss your activation email?
May 19, 2013, 10:29:08 AM

Login with username, password and session length

663016 Posts
70580 Topics
145156 Members

Latest Member: wa4rqd

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Leak Testing/Attacks/Vulnerability Research
| | |-+  130/340
« previous next »
Pages: [1] 2 3 Go Down Print
Author Topic: 130/340  (Read 11116 times)
Valentin N
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 2834


Usability Study Group


WWW
« on: November 25, 2010, 06:05:33 AM »

Hey All Smiley

I guess I have wrong settings which made me get 130 of 340. Any help would be appreciated.

OS:Win7 pro 32bit
Security: CIS 5 with proactive security settings on

Antivirus
AV settings: Realtime protection is on ON Access, scan memory on start is on, auto updates are on, Don't scan files that are bigger than 50Mb with heuristics on hight. Manual scanning has heuristics on high, scan archive files and don't scan files that are more than 200MB.

Firewall
The firewall is on Safe mode, Alart settings is on High and on Advance settings all options are marked besides Monitor NDIS protocols other than TCP/IP. In Stealth Ports Wizard i have selected "Block all incoming connections and make my ports stealth for everyone

Defense+
Defense+ is on safe mode. In General Settings everything is as it is from the factory. In Execution Control Settings the Imagee Execution Control Level is enabled, Treat unrecognized files as Restricted and all of other options are marked. Everything is as it is from the factory but I have unmarked Automatically trust files from trusted installers. Everything is marked in Monitoring Settings.

Here is the list

LIST
Date   11:27:47 - 2010-11-25
OS   Windows Vista SP0 build 7600 (strange that is says Win Vista)
1. RootkitInstallation: MissingDriverLoad   Vulnerable
2. RootkitInstallation: LoadAndCallImage   Vulnerable
3. RootkitInstallation: DriverSupersede   Protected
4. RootkitInstallation: ChangeDrvPath   Vulnerable
5. Invasion: Runner   Protected
6. Invasion: RawDisk   Vulnerable
7. Invasion: PhysicalMemory   Protected
8. Invasion: FileDrop   Vulnerable
9. Invasion: DebugControl   Protected
10. Injection: SetWinEventHook   Vulnerable
11. Injection: SetWindowsHookEx   Vulnerable
12. Injection: SetThreadContext   Vulnerable
13. Injection: Services   Vulnerable
14. Injection: ProcessInject   Protected
15. Injection: KnownDlls   Vulnerable
16. Injection: DupHandles   Protected
17. Injection: CreateRemoteThread   Protected
18. Injection: APC dll injection   Vulnerable
19. Injection: AdvancedProcessTermination   Vulnerable
20. InfoSend: ICMP Test   Protected
21. InfoSend: DNS Test   Vulnerable
22. Impersonation: OLE automation   Protected
23. Impersonation: ExplorerAsParent   Protected
24. Impersonation: DDE   Vulnerable
25. Impersonation: Coat   Vulnerable
26. Impersonation: BITS   Vulnerable
27. Hijacking: WinlogonNotify   Protected
28. Hijacking: Userinit   Vulnerable
29. Hijacking: UIHost   Protected
30. Hijacking: SupersedeServiceDll   Vulnerable
31. Hijacking: StartupPrograms   Vulnerable
32. Hijacking: ChangeDebuggerPath   Vulnerable
33. Hijacking: AppinitDlls   Vulnerable
34. Hijacking: ActiveDesktop   Protected
Score   130/340

Thanks in advance

Regards,
            Valentin
Logged

Skype: comodohelper (Personal)

CEVPN: Valentin N

CIS 5.9

Keep CTM alive by voting

L.A.R. Grizzly
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1510


Akron, Ohio, USA


WWW
« Reply #1 on: November 25, 2010, 09:52:49 AM »

Hey All Smiley

I guess I have wrong settings which made me get 130 of 340. Any help would be appreciated.

OS:Win7 pro 32bit
Security: CIS 5 with proactive security settings on

https://forums.comodo.com/leak-testingattacksvulnerability-research/comodo-leak-test-suite-updated-version-t30110.0.html;msg443168#msg443168
Logged

Win7 Pro SP1 32 Bit - WinXP Pro SP3 32 Bit
CIS 6.1.276867.2813
Firefox and Thunderbird
Toolbar Icon Themes for Firefox and Thunderbird
Valentin N
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 2834


Usability Study Group


WWW
« Reply #2 on: November 25, 2010, 11:53:12 AM »

Thanks for the link L.A.R.

I have followed the instructs that you  link to be but that won't help.

Regards,
            Valentin
Logged

Skype: comodohelper (Personal)

CEVPN: Valentin N

CIS 5.9

Keep CTM alive by voting

clockwork
Comodo's Hero
*****
Offline Offline

Posts: 1922


Oxygen requires Chuck Norris to live


« Reply #3 on: November 25, 2010, 12:00:18 PM »

is the test running in the comodo sandbox?

do you allow on questions from defense+ after the test is started? your answers are part of the test. you can answer no, or dont answer at all.

Logged

"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
L.A.R. Grizzly
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1510


Akron, Ohio, USA


WWW
« Reply #4 on: November 25, 2010, 12:25:12 PM »

Thanks for the link L.A.R.

I have followed the instructs that you  link to be but that won't help.

Regards,
            Valentin

It wasn't referred as instruction, it was referred because Leak Tests wasn't designed to work with a sandbox. You will get erroneous results. The Leak Test program needs to be updated to work properly with the new CIS.
Logged

Win7 Pro SP1 32 Bit - WinXP Pro SP3 32 Bit
CIS 6.1.276867.2813
Firefox and Thunderbird
Toolbar Icon Themes for Firefox and Thunderbird
Valentin N
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 2834


Usability Study Group


WWW
« Reply #5 on: November 25, 2010, 12:39:22 PM »

okey I will wait for the updated version; i know I a clean system (so I think Grin) since I make regularly scans with different scanners and I control if something seems abnormal.

Regards,
            Valentin
Logged

Skype: comodohelper (Personal)

CEVPN: Valentin N

CIS 5.9

Keep CTM alive by voting

L.A.R. Grizzly
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1510


Akron, Ohio, USA


WWW
« Reply #6 on: November 25, 2010, 01:27:34 PM »

okey I will wait for the updated version; i know I a clean system (so I think Grin) since I make regularly scans with different scanners and I control if something seems abnormal.

Regards,
            Valentin

Rest assured, you are perfectly protected. I have CIS as my only security program and I feel no need to worry! With DACS coming in future versions, CIS will be even more powerful.
Logged

Win7 Pro SP1 32 Bit - WinXP Pro SP3 32 Bit
CIS 6.1.276867.2813
Firefox and Thunderbird
Toolbar Icon Themes for Firefox and Thunderbird
Valentin N
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 2834


Usability Study Group


WWW
« Reply #7 on: November 25, 2010, 01:45:25 PM »

I feel secure and I have the highest settings someone can have.
Logged

Skype: comodohelper (Personal)

CEVPN: Valentin N

CIS 5.9

Keep CTM alive by voting

BoredNow
Comodo's Hero
*****
Offline Offline

Posts: 344



« Reply #8 on: November 25, 2010, 01:55:04 PM »

I also got bad results the first time I ran this test as well, but if you search the forum for...

....  Getting Accurate Leak Test Results  ....

and follow the instructions, you will get accurate results.

The first 5 sections are very important.
Basically, you need to make sure any rules that were made while you ran the test the first time need to be removed, and you need to delete the Internet Explorer (IE) browsing history cache.
And then reboot.  Wink




Logged

HP pavilion media center 2006
Windows 7 64bit - Standard Acct.
EMET 3
CIS-5.10
Sandboxie 3.76
L.A.R. Grizzly
Star Group
Comodo's Hero
*****
Offline Offline

Posts: 1510


Akron, Ohio, USA


WWW
« Reply #9 on: November 25, 2010, 02:32:58 PM »

I also got bad results the first time I ran this test as well, but if you search the forum for...

....  Getting Accurate Leak Test Results  ....

and follow the instructions, you will get accurate results.

The first 5 sections are very important.
Basically, you need to make sure any rules that were made while you ran the test the first time need to be removed, and you need to delete the Internet Explorer (IE) browsing history cache.
And then reboot.  Wink

Sounds like quite a hassle just to get a program to say everything's OK.
Logged

Win7 Pro SP1 32 Bit - WinXP Pro SP3 32 Bit
CIS 6.1.276867.2813
Firefox and Thunderbird
Toolbar Icon Themes for Firefox and Thunderbird
clockwork
Comodo's Hero
*****
Offline Offline

Posts: 1922


Oxygen requires Chuck Norris to live


« Reply #10 on: November 25, 2010, 02:57:27 PM »

what should be changed in the test to work with the comodo sandbox? do you just want that the "testresult" looks good, or do you want to test your program? hey, all products would get 100% results if it was usual to modify tests to get good results Cheesy

the test shows that the sandbox allows things to be done automatically which you dont want to be done.
yes, a reboot will remove some of the happened threats.... but the threats worked until that (keyloggers for example).

when a TEST has to be changed to get good results.... LOL?

the test shows that there is a design problem with an "automatic allowing sandbox". in other words: automatic sandboxing is meaning much more, that the threats are allowed to run automatically, even without any question from defense+.
Logged

"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
JoWa
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2932



« Reply #11 on: November 25, 2010, 03:46:58 PM »

Virtualisation allows files to be dropped and changes to be made in the registry, but in a special “virtual” folder and registry. CLT doesn't understand that they are virtual, and says Vulnerable. That's why CLT should be updated. Wink

But if you run CLT and click on Sandbox in the unlimited access alert, virtualisation is not applied, and you can get 340/340, with default settings! Smiley
Logged

Ubuntu 13.04, 64-bit | Chrome 27β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
Valentin N
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 2834


Usability Study Group


WWW
« Reply #12 on: November 25, 2010, 03:53:43 PM »

I just wanted to see but since the program is more or less quite old i will wait and I know that my system is clean.

Regards,
            Valentin
Logged

Skype: comodohelper (Personal)

CEVPN: Valentin N

CIS 5.9

Keep CTM alive by voting

BoredNow
Comodo's Hero
*****
Offline Offline

Posts: 344



« Reply #13 on: November 26, 2010, 12:16:49 AM »

The point is, the test was designed to test the HIPS side of CIS -- not the sandbox.

And once you run the test, CIS makes rules for the leak test which have to be cleaned up, otherwise it will let the same leaks through the next time you run it.

Following the clean-up procedure is no big deal. I am a computer noob and I did it in about 5 minutes.
 Afro
Logged

HP pavilion media center 2006
Windows 7 64bit - Standard Acct.
EMET 3
CIS-5.10
Sandboxie 3.76
salaficall
Comodo Loves me
****
Offline Offline

Posts: 192



WWW
« Reply #14 on: November 26, 2010, 08:47:46 AM »

Virtualisation allows files to be dropped and changes to be made in the registry, but in a special “virtual” folder and registry. CLT doesn't understand that they are virtual, and says Vulnerable. That's why CLT should be updated. Wink

But if you run CLT and click on Sandbox in the unlimited access alert, virtualisation is not applied, and you can get 340/340, with default settings! Smiley

this is not true

Automatic sandboxing does not virtualise software Files and registry keys created by the software are NOT stored in a separate place on your hard disk. (Instead, to protect system integrity, the sandboxed program is prevented from writing to protected folders, pre-existing files, and registry keys ).

https://forums.comodo.com/defense-sandbox-help-cis/introduction-to-the-5x-sandbox-under-construction-t61169.0.html;msg430226#msg430226


anyway , even if I disabled the file system and the registry virtualisation completely , still one can never get full score with the sanbox option on !!!

I only get full score if I disabled the sandbox option ...

since we all now agree that Automatic sandboxing does not virtualise software Files and registry keys created by the software , and it only prevents the sanboxed program from writing to protected folders, pre-existing files, and registry keys

so why CLT results when ran with S/B disabled are not equal to CLT ran with S/B enabled???!!!

since the automatic sandboxing is only more restrictions , i assume the CLT results are supposed to be better not worse !!!! like the case we have here !!

CIS 5 is a very powerful software but I guess the sandbox is bugged ! 
Logged

An ounce of prevention is better than a pound of cure

That's why I like Comodo !
Tags:
Pages: [1] 2 3 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.059 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com