Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 22, 2010, 08:32:03 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373664
Posts
41473
Topics
94222
Members
Latest Member:
abbbz
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Leak Testing/Attacks/Vulnerability Research
Killed cfp.exe demonstration video by mj0011
« previous
next »
Pages:
1
[
2
]
3
4
Author
Topic: Killed cfp.exe demonstration video by mj0011 (Read 7245 times)
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #15 on:
November 03, 2009, 09:08:48 PM »
Not that I think anyone here thinks so, but if anyone in here is thinking this video "must" be real.. Take a look at this as well:
Melih is at the white house.. And they has the CFP logo there now.. as you can see with your own eyes..
And what is this:
http://www.youtube.com/watch?v=Sr4n7nnu7q8
T. REX are alive again, in a park near you!
The point is, believing someone who refuses to provide some kind of evidence is just stupid.. =) This guy could so easily provide his PoC but chose not to..
Logged
3DNow
Newbie
Offline
Posts: 18
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #16 on:
November 03, 2009, 09:10:00 PM »
haha you can doubt this video,and i will never give u the PoC and your useless protection are still been bypassd.for i have nothing bad.when someday u see the real attack by malware author,u will see how they turn water to glod
Logged
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #17 on:
November 03, 2009, 09:33:18 PM »
Quote from: 3DNow on November 03, 2009, 09:10:00 PM
haha you can doubt this video,and i will never give u the PoC and your useless protection are still been bypassd.for i have nothing bad.when someday u see the real attack by malware author,u will see how they turn water to glod
Why would you do that.. If you spread it to the public then then we will end up getting hold of your PoC probably sooner or later..
And if you plan on infecting a lot of users you will need to use some sort of product flaw probably as well.. And CIS is quite capable at preventing many infections that way.. and your malware can't just be aimed at killing CIS.. What are you planning? Making a huge botnet? stealing passwords?
And what about the users that uses other products....?? Oh and I guess you are going to make your file so badass that it survives a format (not unusuall for people to do when infected..)..
Anyhow if you are the creator of this video (I don't think you are, but well) have you tested this PoC is against something else than CIS? (to be honest I hasn't watched the video..)
Anyhow, CIS is the product that passes all HIPS/firewall tests on matousec.. (unlike the others) and the product probably intercept more stuff than most suites out there.. So Iam sure you could poke a hole in some other suites as well.. Thats usually what happens when something new "pops up".. But yeah, sure its possible that you could have found a flaw.. No offense but without a PoC your just a troll..
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 2006
The only thing i ask for are eggs.
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #18 on:
November 03, 2009, 09:38:23 PM »
Send it to me over a PM.. I will send it to Comodo, if you dont want it public.
Logged
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #19 on:
November 03, 2009, 09:40:36 PM »
Quote from: OmeletGuy on November 03, 2009, 09:38:23 PM
Send it to me over a PM.. I will send it to Comodo, if you dont want it public.
The guy is going to take over the Internet with this flaw, he is the Bill gates of hackers.. Just wait, he has no intention to share it..
Logged
ssj100
Comodo's Hero
Offline
Posts: 284
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #20 on:
November 04, 2009, 06:48:10 AM »
I believe there probably is a POC that can bypass CIS (perhaps more than one). Apparently there are at least 3 POCs (from the same guy?) that can bypass Malware Defender's protection - I think the creator of Malware Defender ("Xiaolin") has been spending the last few days trying to patch these vulnerabilities:
Here, he fixes the first POC bypass:
http://www.wilderssecurity.com/showpost.php?p=1566408&postcount=27
And here, the second:
http://www.wilderssecurity.com/showpost.php?p=1566522&postcount=31
And in this post, he admits he is trying to fix the third POC bypass and has resigned to the fact that Malware Defender will need to be re-designed:
http://www.wilderssecurity.com/showpost.php?p=1568038&postcount=56
I don't know about you guys, but this sounds like pretty big stuff. Malware Defender is arguably the best classical HIPS out there.
Logged
Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 372
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #21 on:
November 04, 2009, 07:08:34 AM »
Quote from: 3DNow on November 03, 2009, 09:10:00 PM
haha you can doubt this video,and i will never give u the PoC and your useless protection are still been bypassd.
You only killed the cfp.exe process. What about the cmdagent.exe? And even if you killed both you still didn't bypass protection because all unknown requests are blocked.
It's just untransparent trolling what you are doing. If you don't want to appear like a criminal loser with some psychich problems you should share the POC...
Logged
dkmc
Newbie
Offline
Posts: 14
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #22 on:
November 04, 2009, 12:00:36 PM »
Monkey boy, [* cut *]
Quote from: evil_religion on November 04, 2009, 07:08:34 AM
It's just untransparent trolling what you are doing. If you don't want to appear like a criminal loser with some psychich problems you should share the POC...
If you do not want to appear like vulgar loudmouthed creature then....think yourself.
«
Last Edit: November 06, 2009, 09:10:42 AM by dkmc
»
Logged
Be polite. Be professional. But, have a plan to kill everyone you meet.
[
from
USMC Rules for Gunfighting ]
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #23 on:
November 04, 2009, 12:48:46 PM »
[Post removed..]
«
Last Edit: November 06, 2009, 02:51:30 PM by Monkey_Boy=)
»
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 2006
The only thing i ask for are eggs.
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #24 on:
November 04, 2009, 12:52:54 PM »
Monkey_Boy & dkmc stop fighting with each other please.
Logged
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #25 on:
November 04, 2009, 01:40:02 PM »
[Post removed..]
«
Last Edit: November 06, 2009, 02:51:52 PM by Monkey_Boy=)
»
Logged
Dennis2
Global Moderator
Comodo's Hero
Offline
Posts: 2507
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #26 on:
November 04, 2009, 02:05:26 PM »
Please read the
Forum Policy
before anyone posts in this topic again.
Thank you
Dennis
Forum Policy
§8. Unacceptable behaviours
Logged
Moderator:
Aims to keep the forum a friendly place. Any concerns? Please PM me and/or review the
NEW forum policy
.
System:
Windows 7 (UAC)x32, CIS 4,Sandboxie 3.44
Vista Home P. (UAC)x32 SP2, CIS 3.14, W.D.
dkmc
Newbie
Offline
Posts: 14
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #27 on:
November 04, 2009, 02:27:42 PM »
Quote from: Monkey_Boy=) on November 04, 2009, 01:40:02 PM
If he thinks Iam wrong somewhere then I would appreciate if he explain where and about what so I know..
I doubt that your serious about that.
Anyway: Re-read thread slowly and thoroughly and pay attention to your comments. Simple as that.
Logged
Be polite. Be professional. But, have a plan to kill everyone you meet.
[
from
USMC Rules for Gunfighting ]
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #28 on:
November 04, 2009, 03:00:05 PM »
Quote from: dkmc on November 04, 2009, 02:27:42 PM
I doubt that your serious about that.
Anyway: Re-read thread slowly and thoroughly and pay attention to your comments. Simple as that.
Explain yourself or just cut it.. My comments are about how easy it is to fake a crash, and that this video has very little credibility, I know for a fact that I can "crash" CIS using the task manager if I tamper a bit with it..
I did watch the video now however.. Isn't it a bit "questionable" how even prior to this guy doing his attack CIS is not showing the usual "all okay" under system status..?
Logged
ssj100
Comodo's Hero
Offline
Posts: 284
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #29 on:
November 04, 2009, 03:36:02 PM »
Quote from: dkmc on November 04, 2009, 02:27:42 PM
I doubt that your serious about that.
Anyway: Re-read thread slowly and thoroughly and pay attention to your comments. Simple as that.
I don't see what the big deal is. I'm sure there are several ways of bypassing classical HIPS, whether it be Defense+ or Malware Defender, if the malicious file is allowed to be executed on the REAL system. This is why it's so important to implement another layer of protection - virtualisation. I use Sandboxie myself.
Regardless, it's unlikely CIS users will ever get infected if they handle Defense+ properly. Sure, there are theoretical bypasses, but how likely are real people going to face them in real life?
Logged
Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
Tags:
Pages:
1
[
2
]
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 12.358 seconds with 20 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com