Welcome, Guest. Please login or register.
October 12, 2008, 04:23:18 AM

Login with username, password and session length

199531 Posts
22909 Topics
54984 Members

Latest Member: mihalyljozsef

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  A new leak test application from COMODO !
« previous next »
Pages: 1 ... 3 4 [5] 6 7 Go Down Print
Author Topic: A new leak test application from COMODO !  (Read 32976 times)
daveiw
Newbie
*
Offline Offline

Posts: 2



« Reply #60 on: December 28, 2007, 03:25:44 PM »

This is the firewall log for the test by the way:

Quote
20:21:17   CPILSUITE.EXE   Blocked   Application is attempting to inject its component into another process.   Process: CPILSuite.exe, Injected: F:\DOWNLOADS\CPILSUITE\CPIL2.DLL
20:21:15   CPIL.EXE   Blocked   Application is attempting to modify other application memory.   Process: CPIL.EXE, Target process: C:\WINDOWS\EXPLORER.EXE
20:05:37   CPIL.EXE   Blocked   Application is attempting to modify other application memory.   Process: CPIL.EXE, Target process: C:\WINDOWS\EXPLORER.EXE
20:05:13   CPIL.EXE   Blocked   Application is attempting to modify other application memory.   Process: CPIL.EXE, Target process: C:\WINDOWS\EXPLORER.EXE
20:04:22   CPILSUITE.EXE   Blocked   Application is attempting to inject its component into another process.   Process: CPILSuite.exe, Injected: F:\DOWNLOADS\CPILSUITE\CPIL2.DLL
20:04:14   CPIL.EXE   Blocked   Application is attempting to modify other application memory.   Process: CPIL.EXE, Target process: C:\WINDOWS\EXPLORER.EXE
Logged

Windows XP Home SP2:
Nod32
AVG Anti Spyware (formerly Ewido)
and Outpost Pro 4 user.
Boofo
Comodo Member
**
Offline Offline

Posts: 33


« Reply #61 on: January 09, 2008, 02:10:43 AM »

I have tried this test and at first nothing got through. Then I allowed it to get through once. I rebooted and it still gets through no matter what I do. I even uninstalled and reinstalled the firewall but Test 1 always gets through now. How to I get it back to not allowing Test 1 to get through?
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3165


bubble!


« Reply #62 on: January 09, 2008, 06:14:22 AM »

I have tried this test and at first nothing got through. Then I allowed it to get through once. I rebooted and it still gets through no matter what I do. I even uninstalled and reinstalled the firewall but Test 1 always gets through now. How to I get it back to not allowing Test 1 to get through?
this is my "expert" opinion  Nerd  Grin :
1) you ticked "remember" when you allowed the app
2) you still had the CPIL leak test app on your comp when you reinstall CFP3 using Clean PC mode, so
    CPIL leak test was white listed on your PC.

enough fake "expert" opinion, let's wait for the real expert to come here  Grin


Ganda
Logged

Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* **** Angry
Boofo
Comodo Member
**
Offline Offline

Posts: 33


« Reply #63 on: January 09, 2008, 06:59:31 AM »

Ok, so how do I un-whitelist it then? Wink
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3165


bubble!


« Reply #64 on: January 09, 2008, 07:12:37 AM »

WOW, so it works huh   Cheesy
ehhm,here we go
go to CFP3/defense+/advanced/computer security policy
you'll see list of remembered rules there. Remove or edit the rule for the leaktest app.
oh, you might wanna check %windir%\explorer.exe ==> use a custom policy/access right/
on run an executable, click modify and find the leak test app there
« Last Edit: January 09, 2008, 07:18:48 AM by ganda » Logged

Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* **** Angry
Boofo
Comodo Member
**
Offline Offline

Posts: 33


« Reply #65 on: January 09, 2008, 07:30:26 AM »

WOW, so it works huh   Cheesy
ehhm,here we go
go to CFP3/defense+/advanced/computer security policy
you'll see list of remembered rules there. Remove or edit the rule for the leaktest app.
oh, you might wanna check %windir%\explorer.exe ==> use a custom policy/access right/
on run an executable, click modify and find the leak test app there

I deleted the rules for that before and it still gets by test 1. The second part of your instructions I didn't quite understand. That only takes me to the window explorer program. I'm using Windows XP.
« Last Edit: January 09, 2008, 07:33:11 AM by Boofo » Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3165


bubble!


« Reply #66 on: January 09, 2008, 08:27:08 AM »

I deleted the rules for that before and it still gets by test 1. The second part of your instructions I didn't quite understand. That only takes me to the window explorer program. I'm using Windows XP.
i use Xp SP2 too. i think we really need the expert help right now Grin
ok, this is my step 2, sorry for being unclear, me & english.
CFP3/Defense+/advanced/computer security policy
*find %windir%\explorer.exe ,double click on it,
*tick use a custom policy, and click access right
*on the "access rights" window==>run an axecutable==> click modify,
you'll see another list of allowed/blocked apps there


Ganda

« Last Edit: January 09, 2008, 08:29:03 AM by ganda » Logged

Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* **** Angry
Boofo
Comodo Member
**
Offline Offline

Posts: 33


« Reply #67 on: January 09, 2008, 03:31:58 PM »

Ahh, ok, I found what you were talking about. Thank you for the very detailed explanation. Wink

The app wasn't listed in there.

Somehow it involves the hooks but I don't see where to edit those.

I thank you for all the help, sir. We'll get this figured out if we keep plugging away at it. Wink
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3165


bubble!


« Reply #68 on: January 09, 2008, 08:47:42 PM »

Ahh, ok, I found what you were talking about. Thank you for the very detailed explanation. Wink

The app wasn't listed in there.

Somehow it involves the hooks but I don't see where to edit those.

I thank you for all the help, sir. We'll get this figured out if we keep plugging away at it. Wink
huh Huh hook? what hook?
based on my stupid experience of mistakenly allowing/blocking apps  Grin , after i do these steps :
*find %windir%\explorer.exe ,double click on it,
*tick use a custom policy, and click access right
*on the "access rights" window==>run an axecutable==> click modify
there are lots of apps listed there, and i just remove the mistakenly allowed/blocked app.

Logged

Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* **** Angry
Boofo
Comodo Member
**
Offline Offline

Posts: 33


« Reply #69 on: January 09, 2008, 09:14:10 PM »

The app is not listed in that section so there is nothing to remove.

When you run CPLSuite it adds some hooks. That is how it bypasses the firewall.
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3165


bubble!


« Reply #70 on: January 09, 2008, 09:20:30 PM »

The app is not listed in that section so there is nothing to remove.
hmm  Huh so you don't have specific rule for CPIL leaktest and still don't pass test 1.

When you run CPLSuite it adds some hooks. That is how it bypasses the firewall.

oh ya, i remember that, it's defense+ warning that blocked the attempt.

 Undecided let see if someone can help you out. have you tried another leaktest apps? didn't pass the leaktest app by mistakenly click "allow" doesn't mean your firewall's leaking  Grin


edit :
hey, i've just tried the CPIL leaktest, i allow & remember test 1 (access physical memory directly attempt), remove the rule, but i still didn't pass test 1 after that.
let's ask for help together  Grin
i'll try to reboot my comp and see if i still fail after rebooting
« Last Edit: January 09, 2008, 09:26:04 PM by ganda » Logged

Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* **** Angry
ganda
Forum Ninja
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3165


bubble!


« Reply #71 on: January 09, 2008, 09:35:08 PM »

hi Boofo  Wave
just rebooted my comp, CFP3 successfully block test 1.  Huh
it's a weird problem you have there. Huh
Logged

Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* **** Angry
Boofo
Comodo Member
**
Offline Offline

Posts: 33


« Reply #72 on: January 09, 2008, 09:54:25 PM »

hi Boofo  Wave
just rebooted my comp, CFP3 successfully block test 1.  Huh
it's a weird problem you have there. Huh


I even tried uninstalling and reinstalling the firewalll and it still gets through. Sad

I emailed Melih, but he wasn't sure why it is doing that.
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3165


bubble!


« Reply #73 on: January 09, 2008, 10:04:02 PM »

sorry to hear that  Sad
but i gues you shouldn't worry too much, it's just leak test app that you've mistakenly allowed, not a real leakage  Grin . perhaps you wanna try another leaktest app like GRCleaktest and see if your CFP3 can pass them.
let see if some mods here can help you.  Thinking
Logged

Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* **** Angry
Boofo
Comodo Member
**
Offline Offline

Posts: 33


« Reply #74 on: January 09, 2008, 10:20:04 PM »

sorry to hear that  Sad
but i gues you shouldn't worry too much, it's just leak test app that you've mistakenly allowed, not a real leakage  Grin . perhaps you wanna try another leaktest app like GRCleaktest and see if your CFP3 can pass them.
let see if some mods here can help you.  Thinking

I guess it's just the principle of it all. This is the best firewall ever and I can't even stop a little leaktest.
Logged
Tags:
Pages: 1 ... 3 4 [5] 6 7 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.359 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com