Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 23, 2013, 02:44:34 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663664
Posts
70572
Topics
145228
Members
Latest Member:
LuellaSil
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Leak Testing/Attacks/Vulnerability Research
weakness of the gpCode
« previous
next »
Pages:
1
...
4
5
[
6
]
7
8
...
10
Author
Topic: weakness of the gpCode (Read 77067 times)
harsha_mic
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 154
Re: CFW fails in GPCode ransom test
«
Reply #75 on:
April 27, 2011, 07:36:56 AM »
This is very sad to know. Now, we have malwares (stuxnet,gpcode, i don'i know how many others are there) where Comodo D+ (the strongest part of Comodo which is not based on signatures) cannot contain it.
Logged
W7 64 bit | Comodo Fw v5.8 | Eset NOD32 AV v5 | Hitman (ondemand)
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13182
Volunteer Moderator
Re: CFW fails in GPCode ransom test
«
Reply #76 on:
April 27, 2011, 07:49:36 AM »
This has been discussed here also;
weakness of the gpCode
I also have proposed a few, q&d fixes that advanced users can apply.
This issue should be fixed in a regular update of CIS if you ask me.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
harsha_mic
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 154
Re: CFW fails in GPCode ransom test
«
Reply #77 on:
April 27, 2011, 08:23:38 AM »
Thanks for the link. But new in this test, it actually fails even when Sandbox set to untrusted.
I am surprised that not a single peep from dev team in that long lenghty thread.
Logged
W7 64 bit | Comodo Fw v5.8 | Eset NOD32 AV v5 | Hitman (ondemand)
aigle
Comodo's Hero
Offline
Posts: 673
Re: CFW fails in GPCode ransom test
«
Reply #78 on:
April 27, 2011, 09:43:13 AM »
Honestly I have made two threads on Wilders to give a stimulus to Comodo developers.
First is about Stuxnet, 2nd is about gpcode. My main purpose was to draw the attention of comdod guys as I know if some thing like this is posted on wilders, it,s shared here and vice versa.
There is still a third thread on the way very soon that will show another Comodo defence plus failure, Sadly the developers are quiet and deny to fix these while OA people did it so smartly and rapidly.
It reminds me of Conficker that was fixed immediately by OA but Comodo took many months before they could fix it( comodo was intercepting it but the pop up alert was not so clear like OA at that time) and that was even after so many forums posts and my PMs to the developers. It was finally OK in v 5.
Let,s hope for the best.
«
Last Edit: April 27, 2011, 03:04:44 PM by aigle
»
Logged
harsha_mic
Computer Security Testing Group
Comodo Loves me
Offline
Posts: 154
Re: CFW fails in GPCode ransom test
«
Reply #79 on:
April 27, 2011, 10:03:08 AM »
first of all a sincere thanks in trying to point out the D+ cons and your effort in letting Comodo know it.
probably its time to look towards OA again.
I'm always confused to which product i should use when it comes to Comodo and OA. I really like both the products. It was clearer when there was no x64 support from OA. But now ... Competition is always good for us (we, the end consumers).
«
Last Edit: April 27, 2011, 01:18:13 PM by harsha_mic
»
Logged
W7 64 bit | Comodo Fw v5.8 | Eset NOD32 AV v5 | Hitman (ondemand)
aigle
Comodo's Hero
Offline
Posts: 673
Comodo Defence Plus bypassed by malware
«
Reply #80 on:
April 27, 2011, 03:01:53 PM »
I have made three thraed on Wilders forums showing how Comodo Defence Plus is bypassed by three different malware.
Last thread is about blackday.exe trojan that can bypass Defence Plus and can make a mess of system.
Blackday trojan versus HIPS
(at Widers Security Forums)
I wonder when these issues will be fixed. BTW OnlineArmor stops all these malware dead.
Other two threads at Wilders are here.
Gpcode trojan versus HIPS
Stuxnet .(lnk exploit malware) versus HIPS
Other threads in comodo forums are here.
Would Comodo have stopped the Stuxnet worm?
weakness of the gpCode
CFW fails in GPCode ransom test
Edit by EricJH: I edited the bare url's to url's with topic names in it for clarification and quick overview
«
Last Edit: April 27, 2011, 07:12:49 PM by EricJH
»
Logged
morphiusz
Star Group
Comodo's Hero
Offline
Posts: 2196
Comodo's śmieć :)
Re: Comodo Defence Plus bypassed by malware
«
Reply #81 on:
April 27, 2011, 03:23:03 PM »
It's so sad that CIS failed those tests so badly
And devs don't do anything...
Can we have a response here?
I will bump this topic from time to time
Logged
aigle
Comodo's Hero
Offline
Posts: 673
Re: Comodo Defence Plus bypassed by malware
«
Reply #82 on:
April 27, 2011, 05:34:24 PM »
Thanks.
Very nice signature.
BTW is comodo forum dead? I don,t see many responses here as I used to be in the past.
If comodo fans don,t become angry, I will like to ask if CIS is still in active development or is soon going to be dead just like so many other comodo products in the past? It,s just a sinsiter feeling that I am getting. Hope it,s not the case. Comodo might be in trouble due to recent issues related to stolen certificates.
«
Last Edit: April 27, 2011, 05:36:40 PM by aigle
»
Logged
Peter5
Comodo's Hero
Offline
Posts: 257
Re: Comodo Defence Plus bypassed by malware
«
Reply #83 on:
April 27, 2011, 06:27:09 PM »
Great work aigle. We need more people doing this kind of tests.
Can you test the Manual Sandbox (Virtualizattion) to see if it makes any difference?
Thanks
Logged
aigle
Comodo's Hero
Offline
Posts: 673
Re: Comodo Defence Plus bypassed by malware
«
Reply #84 on:
April 27, 2011, 06:59:37 PM »
Will try later. I think it will pass.
Logged
Peter5
Comodo's Hero
Offline
Posts: 257
Re: Comodo Defence Plus bypassed by malware
«
Reply #85 on:
April 27, 2011, 07:10:25 PM »
Quote from: aigle on April 27, 2011, 06:59:37 PM
Will try later. I think it will pass.
Thanks
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6568
Re: Comodo Defence Plus bypassed by malware
«
Reply #86 on:
April 27, 2011, 07:18:30 PM »
Quote from: aigle on April 27, 2011, 05:34:24 PM
I will like to ask if CIS is still in active development or is soon going to be dead just like so many other comodo products in the past?
Well, since the mods have the version 5.4 pre-release, I'd say it's still in active development...
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16707
Re: Comodo Defence Plus bypassed by malware
«
Reply #87 on:
April 27, 2011, 07:33:27 PM »
Quote from: aigle on April 27, 2011, 05:34:24 PM
Thanks.
Very nice signature.
BTW is comodo forum dead? I don,t see many responses here as I used to be in the past.
If comodo fans don,t become angry, I will like to ask if CIS is still in active development or is soon going to be dead just like so many other comodo products in the past? It,s just a sinsiter feeling that I am getting. Hope it,s not the case. Comodo might be in trouble due to recent issues related to stolen certificates.
The mods are testing v5.4 (a bug fix release; nothing spectacular). Version 6 is in the making. Valkyrie has been given to the public for testing, the same for Site Inspector. Then there was Comodo Unite beta released, another update for Programs Manager.... then there is something cooking with Comodo Round the Clock... Melih is very enthusiastic about the possibilities of Valkyrie for the cloud file analysis....
CIS is Comodo's flagship. You seriously think that would become abandonware? I want what you were smoking..... can you hook me up with your man?
I think Comodo is pretty active.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
wasgij6
Global Moderator
Comodo's Hero
Offline
Posts: 3061
Re: Comodo Defence Plus bypassed by malware
«
Reply #88 on:
April 27, 2011, 09:29:10 PM »
well i really hope they do something about this
seeing this kinda quote kinda worries me
Quote from: morphiusz on April 26, 2011, 11:48:35 PM
I was talkng with egemen and he said that there is no need to improve D+ against Gpcode
So, there are officialy malware which can bypass Comodo, and Comodo actually doesn't want to deal with this. Sad.
Wath's about Melih's statement, that they would fix CIS when it had some vulnerabilities?
Logged
| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
egemen
Comodo Staff
Comodo's Hero
Offline
Posts: 3269
Re: CFW fails in GPCode ransom test
«
Reply #89 on:
April 27, 2011, 10:27:54 PM »
Hi Guys,
Let me comment on this one more time. First of all, if configured, CIS can very well protect against this and any other threats proactively.
First lets see what this gpcode does: It gets to the users computer drive by download and searches for the files in users harddisk. It then encrypts all picture and text files i.e. damages some non-OS-essential files.
Is this a threat to the user ? YES!
Is this a real threat to be prevented ? YES!
Does CIS prevent against this now? YES!
Then how does COMODO protect against this
BY DEFAULT
. By default, antivirus detection is enough to detect gpcode and any of its variants. Lets not make false comments by saying CIS does not protect its users against gpcode. CIS DOES prevent against the REAL threat wih its antivirus right now.
Now lets talk about preventing this proactively.
Is there a way to configure CIS to prevent this proactively? YES.
Method 1: Add you sensitive files/folders to CIS protected files list and you are done. For example, you can add My Documents, My Pictures folders or *.doc, *.txt, *.jpg etc. to your protected files list and it can be protected.
Method 2: Always run your WEB browsers in COMODO Sandbox by adding them to Sandbox pemanently. And while doing this, make sure File system and registry virtualization are both enabled. If you do this and accidently get gpcode or something like gpcode or actually any virus from WEB, they will be running in a virtual file system and hence they can not acess your files or folders.
You can also directly run GPCODE with right-click menu in CIS sandbpx and you will see it cant do anything.
Ofcourse CIS is capable of preventing it proactively as of now. However, these settings are not configured by default.
So why is COMODO not making an immediate HACK to prevent this proactively. Some other products are preventing it already.
We do not need to make a HACK but offer you a proper solution which is proven to prevent this and any similar threat while not affecting your daily work with your computer.
The proper solution is the active file system virtualization of *SOME* automatically sandboxed applications by default. Yes, we are right now working on this kind of a ideal automatic sandbox which is going to be in CIS 6 and will work similar to method 2.
It is NOT a HACK but a properly engineered solution that *avreage joe* wont have problems when CIS is installed.
It takes 10 minutes to write a HACK which simply checks each applications right to enumerate files and folders and thats it. You are there. And what would be the cost? Joe's photo editor will create a popup asking him if he wants some application to list files. Or Marry, while his new MP3 player builds a playlist, it might conflict.
Logged
Tags:
Pages:
1
...
4
5
[
6
]
7
8
...
10
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.062 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com