Welcome, Guest. Please login or register.
Did you miss your activation email?
May 26, 2013, 01:19:45 AM

Login with username, password and session length

664096 Posts
70638 Topics
145272 Members

Latest Member: iqhancpu458

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Leak Testing/Attacks/Vulnerability Research
| | |-+  CIS fails CLT :(
« previous next »
Pages: [1] Go Down Print
Author Topic: CIS fails CLT :(  (Read 3489 times)
cocopara
Comodo Family Member
***
Offline Offline

Posts: 51


« on: December 31, 2010, 07:37:54 PM »

Operating System - WIndows 7 (whatever latest Service pack)
Version of CIS: the latest version of the 5.0 edition
Real time scanner: I use MBAM Smiley and CIS
CIS settings - Same as the CLT guide in addition to having put the image execution control to untrusted / restricted
CLT score - 270

Note: I got bad results earlier aswell but this is a fresh install of 5.0 (prior to the 4.0 I had)

Results:

Date   01:36:04 - 01.01.2011

OS   Windows Vista SP0 build 7600

1. RootkitInstallation: MissingDriverLoad   Protected
2. RootkitInstallation: LoadAndCallImage   Protected
3. RootkitInstallation: DriverSupersede   Protected
4. RootkitInstallation: ChangeDrvPath   Vulnerable
5. Invasion: Runner   Protected
6. Invasion: RawDisk   Vulnerable
7. Invasion: PhysicalMemory   Protected
8. Invasion: FileDrop   Vulnerable
9. Invasion: DebugControl   Protected
10. Injection: SetWinEventHook   Vulnerable
11. Injection: SetWindowsHookEx   Vulnerable
12. Injection: SetThreadContext   Protected
13. Injection: Services   Vulnerable
14. Injection: ProcessInject   Protected
15. Injection: KnownDlls   Vulnerable
16. Injection: DupHandles   Protected
17. Injection: CreateRemoteThread   Protected
18. Injection: APC dll injection   Protected
19. Injection: AdvancedProcessTermination   Protected
20. InfoSend: ICMP Test   Protected
21. InfoSend: DNS Test   Vulnerable
22. Impersonation: OLE automation   Protected
23. Impersonation: ExplorerAsParent   Vulnerable
24. Impersonation: DDE   Vulnerable
25. Impersonation: Coat   Vulnerable
26. Impersonation: BITS   Protected
27. Hijacking: WinlogonNotify   Protected
28. Hijacking: Userinit   Vulnerable
29. Hijacking: UIHost   Protected
30. Hijacking: SupersedeServiceDll   Vulnerable
31. Hijacking: StartupPrograms   Vulnerable
32. Hijacking: ChangeDebuggerPath   Protected
33. Hijacking: AppinitDlls   Vulnerable
34. Hijacking: ActiveDesktop   Protected
Score   190/340

BTW: I DO HAVE WINDOWS 7 NOT VISTA...
« Last Edit: December 31, 2010, 07:57:18 PM by cocopara » Logged
Michael Withstand
Comodo's Hero
*****
Offline Offline

Posts: 424



« Reply #1 on: December 31, 2010, 08:37:33 PM »

Disable sandbox, set to proactive, make sure all the required settings is checked(see sticky). Delete all internet browser cache and history. Restart then test again.
Logged

First they tried to kill u, then they flagged false mental illness then they persecute u, then they cheated everything u do, then they blame u for fighting back.

My blog: http://exposingsingapore.wordpress.com
cocopara
Comodo Family Member
***
Offline Offline

Posts: 51


« Reply #2 on: December 31, 2010, 08:45:02 PM »

Disable sandbox, set to proactive, make sure all the required settings is checked(see sticky). Delete all internet browser cache and history. Restart then test again.

I have done this test so many times.

All of the above is done EXCEPT the browser cache.

How big of an impact can the browser cache be?.
Logged
Michael Withstand
Comodo's Hero
*****
Offline Offline

Posts: 424



« Reply #3 on: December 31, 2010, 08:53:06 PM »

I have done this test so many times.

All of the above is done EXCEPT the browser cache.

How big of an impact can the browser cache be?.

I think it may affect impersonation: Coat result.

When I started using CIS in XP then I used to get very low leak test score.

I just assumed that my PC was compromised which is hardly surprising since I hadn't been using any firewall for years then.

An OS reinstall fixed the problem just fine!  Smiley
Logged

First they tried to kill u, then they flagged false mental illness then they persecute u, then they cheated everything u do, then they blame u for fighting back.

My blog: http://exposingsingapore.wordpress.com
cocopara
Comodo Family Member
***
Offline Offline

Posts: 51


« Reply #4 on: December 31, 2010, 08:58:27 PM »

I think it may affect impersonation: Coat result.

When I started using CIS in XP then I used to get very low leak test score.

I just assumed that my PC was compromised which is hardly surprising since I hadn't been using any firewall for years then.

An OS reinstall fixed the problem just fine!  Smiley

Does this test tell the truth then. WIth my configs will I actually be as secure as anyone else though the test scores are different?. I have done everything Smiley except browser cache. Even though if I did that and received 320 I would actually be just as secure as otherwise or NO?
Logged
BoredNow
Comodo's Hero
*****
Offline Offline

Posts: 344



« Reply #5 on: January 18, 2011, 03:23:35 PM »

I have done this test so many times.

All of the above is done EXCEPT the browser cache.

How big of an impact can the browser cache be?.

From the guide...
3. Delete the Internet Explorer (IE) browsing history cache.  Run IE, click on the "tools" menu, then select "internet options". Click on the "general tab" and then click on the "delete" button under browsing history. You can also delete the browsing history using cleaning programs such as CCleaner or Cleanup! The reason why you need to clean the IE history:  If CLT was previously run and previously failed "Impersonation: Coat", IE will open the target webpage from the IE cache, and not through the leak, leading to a false failure of "Impersonation: Coat". Erasing the browsing history ensures that IE cannot load the webpage from the cache and forces IE to load the webpage through the leak.
Logged

HP pavilion media center 2006
Windows 7 64bit - Standard Acct.
EMET 3
CIS-5.10
Sandboxie 3.76
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.046 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com