Welcome, Guest. Please login or register.
Did you miss your activation email?
May 20, 2013, 03:55:42 PM

Login with username, password and session length

663281 Posts
70512 Topics
153381 Members

Latest Member: catygopcqex

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Leak Testing/Attacks/Vulnerability Research
| | |-+  CIS 4: Low scores in Comodo Leaktests
« previous next »
Pages: [1] Go Down Print
Author Topic: CIS 4: Low scores in Comodo Leaktests  (Read 4674 times)
Marcelius
Newbie
*
Offline Offline

Posts: 3


« on: March 14, 2010, 10:49:17 AM »

Hello! I just installed CIS 4 and I'm getting very poor scores in the Comodo Leaktests tool. I've installed only the firewall but I'm also using Defense+ and the Sandbox.

When I run clt.exe I get a Defense+ popup asking for permission to run the file with elevated privileges, if I chose Block the test doesn't open so I guess that's not the point. But if I grant elevated privileges then I get a very poor score of 50/340.





Any help will be appreciated. I have both the firewall and Defense+ in Safe Mode and I'm running Windows XP SP3.
Logged
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1362


Reality is subordinate to perception.


WWW
« Reply #1 on: March 14, 2010, 02:14:27 PM »

When I run clt.exe I get a Defense+ popup asking for permission to run the file with elevated privileges, if I chose Block the test doesn't open so I guess that's not the point. But if I grant elevated privileges then I get a very poor score of 50/340.
Guess not allowing D+ elevation alert for untrusted executables could be considered a point  Lips Sealed

Overall you could use different ways to run/test CLT

eg:
  • Testing automated sandboxing (virtualization disabled) by invoking Clt.exe from the command prompt (or a .bat file).
  • Testing sandboxing with virtualization by right-clicking clt.exe file and choosing "Run in Comodo Sandbox"
  • Testing Full D+ by disabling sandbox (right click on CIS tray icon\Sandbox security level\disabled)  and running clt.exe

PS: I attached an archive containing a .bat file. Once clt.bat is extracted and placed in the same folder of clt.exe it could be used to run clt like described at point 1

* clt.zip (0.12 KB - downloaded 6 times.)
« Last Edit: March 14, 2010, 02:33:34 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Marcelius
Newbie
*
Offline Offline

Posts: 3


« Reply #2 on: March 14, 2010, 03:18:45 PM »

Guess not allowing D+ elevation alert for untrusted executables could be considered a point  Lips Sealed
Hahaha I know Cheesy, but I just wanted to run the test anyway, I wouldn't do that with a really unknown file.

But something strange happened now running the leaktest in the three ways you suggested: this time I did not receive the alert asking for elevated privileges. Any possible explanation for this behavior? Of course I got much better scores this way.

Here is my summary:

  • I got a nice improvement with this method: 310/340. But it seems that my system is still vulnerable to Invasion: PhysicalMemory, Impersonation: DDE and Impersonation: Coat.
  • Using "Run in Comodo Sandbox" gave me a 230/340. Being vulnerable in Invasion: PhysicalMemory, , Invasion: FileDrop, Impersonation: DDE, Impersonation: Coat, Hijacking: WinlogonNotify, Hijacking: Userinit, Hijacking: UIHost, Hijacking: SupersedeServiceDll, Hijacking: Startup Programs, Hijacking: ChangeDebuggerPath and ijacking: ActiveDesktop.
  • I did not expect this Tongue: 330/340 with the Sandbox disabled. Only vulnerable to Impersonation: Coat.

Should I disable the sandbox permanently? Where should I look to fix the Impersonation: Coat vulnerability?

Thanks a lot for your answer and the .bat file.
« Last Edit: March 14, 2010, 03:22:06 PM by Marcelius » Logged
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1362


Reality is subordinate to perception.


WWW
« Reply #3 on: March 14, 2010, 04:38:59 PM »

But something strange happened now running the leaktest in the three ways you suggested: this time I did not receive the alert asking for elevated privileges. Any possible explanation for this behavior?

Elevation alerts won't be displayed when sandbox is disabled (point 3).
Elevation alert did not appear on point 1 and 2 because those ways forced clt.exe to run sandboxed.

Point 1 reproduce a general scenario where an unrecognized/untrusted file (cmd.exe\clt.bat) run another executable (clt.exe). In such case the latter executable (clt.exe) will be automatically sandboxed without virtualization (automatic sandoxing would happen even if the latter was an application on Comodo's list of safe files )

Point 2 force sandboxing using context menu. In such case file/registry virtualization is enabled as well. (Thus some tests did incorrectly appear as vulnerable )

Point 3 use D+ and should be able to pass all CLT tests  but I too had Coat occasionally fail on V4 without apparent reason.  Rebooting windows and testing CLT with sandbox disabled increase the chance yo pass Coat as well but finger crossed this glitch will be solved in time.



About PhysicalMemory: perhaps you got onto another glitch. (2nd run cause failed Leaktests in sandbox if the 1s run was elevated) You could take that test again after a reboot.

About DDE: Not sure if sandbox is meant to block it.You could try to reboot and test it again.



You can find additional information about the sandbox in Introduction to the Sandbox and more in How the Comodo Sandbox works.

ATM I'm running CIS with sandbox enabled but I still undecided. Undecided

« Last Edit: March 14, 2010, 05:07:48 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Marcelius
Newbie
*
Offline Offline

Posts: 3


« Reply #4 on: March 14, 2010, 07:08:13 PM »

Thanks a lot for your detailed explanation and the links, Endymion. You have been of tremendous help Thumb Up .
Logged
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 1362


Reality is subordinate to perception.


WWW
« Reply #5 on: March 15, 2010, 06:53:28 AM »

You're welcome.  Smiley
Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.781 seconds with 21 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com