Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 12, 2008, 04:23:18 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199531
Posts
22909
Topics
54984
Members
Latest Member:
mihalyljozsef
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Leak Testing/Attacks/Vulnerability Research
A new leak test application from COMODO !
« previous
next »
Pages:
1
...
3
4
[
5
]
6
7
Author
Topic: A new leak test application from COMODO ! (Read 32976 times)
daveiw
Newbie
Offline
Posts: 2
Re: A new leak test application from COMODO !
«
Reply #60 on:
December 28, 2007, 03:25:44 PM »
This is the firewall log for the test by the way:
Quote
20:21:17 CPILSUITE.EXE Blocked Application is attempting to inject its component into another process. Process: CPILSuite.exe, Injected: F:\DOWNLOADS\CPILSUITE\CPIL2.DLL
20:21:15 CPIL.EXE Blocked Application is attempting to modify other application memory. Process: CPIL.EXE, Target process: C:\WINDOWS\EXPLORER.EXE
20:05:37 CPIL.EXE Blocked Application is attempting to modify other application memory. Process: CPIL.EXE, Target process: C:\WINDOWS\EXPLORER.EXE
20:05:13 CPIL.EXE Blocked Application is attempting to modify other application memory. Process: CPIL.EXE, Target process: C:\WINDOWS\EXPLORER.EXE
20:04:22 CPILSUITE.EXE Blocked Application is attempting to inject its component into another process. Process: CPILSuite.exe, Injected: F:\DOWNLOADS\CPILSUITE\CPIL2.DLL
20:04:14 CPIL.EXE Blocked Application is attempting to modify other application memory. Process: CPIL.EXE, Target process: C:\WINDOWS\EXPLORER.EXE
Logged
Windows XP Home SP2:
Nod32
AVG Anti Spyware (formerly Ewido)
and Outpost Pro 4 user.
Boofo
Comodo Member
Offline
Posts: 33
Re: A new leak test application from COMODO !
«
Reply #61 on:
January 09, 2008, 02:10:43 AM »
I have tried this test and at first nothing got through. Then I allowed it to get through once. I rebooted and it still gets through no matter what I do. I even uninstalled and reinstalled the firewall but Test 1 always gets through now. How to I get it back to not allowing Test 1 to get through?
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
Offline
Posts: 3165
bubble!
Re: A new leak test application from COMODO !
«
Reply #62 on:
January 09, 2008, 06:14:22 AM »
Quote from: Boofo on January 09, 2008, 02:10:43 AM
I have tried this test and at first nothing got through. Then I allowed it to get through once. I rebooted and it still gets through no matter what I do. I even uninstalled and reinstalled the firewall but Test 1 always gets through now. How to I get it back to not allowing Test 1 to get through?
this is my "expert" opinion
:
1) you ticked "remember" when you allowed the app
2) you still had the CPIL leak test app on your comp when you reinstall CFP3 using Clean PC mode, so
CPIL leak test was white listed on your PC.
enough fake "expert" opinion, let's wait for the real expert to come here
Ganda
Logged
Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* ****
Boofo
Comodo Member
Offline
Posts: 33
Re: A new leak test application from COMODO !
«
Reply #63 on:
January 09, 2008, 06:59:31 AM »
Ok, so how do I un-whitelist it then?
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
Offline
Posts: 3165
bubble!
Re: A new leak test application from COMODO !
«
Reply #64 on:
January 09, 2008, 07:12:37 AM »
WOW, so it works huh
ehhm,here we go
go to
CFP3/defense+/advanced/computer security policy
you'll see list of remembered rules there. Remove or edit the rule for the leaktest app.
oh, you might wanna check
%windir%\explorer.exe ==> use a custom policy/access right/
on
run an executable
, click
modify
and find the leak test app there
«
Last Edit: January 09, 2008, 07:18:48 AM by ganda
»
Logged
Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* ****
Boofo
Comodo Member
Offline
Posts: 33
Re: A new leak test application from COMODO !
«
Reply #65 on:
January 09, 2008, 07:30:26 AM »
Quote from: ganda on January 09, 2008, 07:12:37 AM
WOW, so it works huh
ehhm,here we go
go to
CFP3/defense+/advanced/computer security policy
you'll see list of remembered rules there. Remove or edit the rule for the leaktest app.
oh, you might wanna check
%windir%\explorer.exe ==> use a custom policy/access right/
on
run an executable
, click
modify
and find the leak test app there
I deleted the rules for that before and it still gets by test 1. The second part of your instructions I didn't quite understand. That only takes me to the window explorer program. I'm using Windows XP.
«
Last Edit: January 09, 2008, 07:33:11 AM by Boofo
»
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
Offline
Posts: 3165
bubble!
Re: A new leak test application from COMODO !
«
Reply #66 on:
January 09, 2008, 08:27:08 AM »
Quote from: Boofo on January 09, 2008, 07:30:26 AM
I deleted the rules for that before and it still gets by test 1. The second part of your instructions I didn't quite understand. That only takes me to the window explorer program. I'm using Windows XP.
i use Xp SP2 too. i think we really need the expert help right now
ok, this is my step 2, sorry for being unclear, me & english.
CFP3/Defense+/advanced/computer security policy
*find
%windir%\explorer.exe
,double click on it,
*tick
use a custom policy
, and click
access right
*on the "access rights" window==>
run an axecutable
==> click
modify
,
you'll see another list of allowed/blocked apps there
Ganda
«
Last Edit: January 09, 2008, 08:29:03 AM by ganda
»
Logged
Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* ****
Boofo
Comodo Member
Offline
Posts: 33
Re: A new leak test application from COMODO !
«
Reply #67 on:
January 09, 2008, 03:31:58 PM »
Ahh, ok, I found what you were talking about. Thank you for the very detailed explanation.
The app wasn't listed in there.
Somehow it involves the hooks but I don't see where to edit those.
I thank you for all the help, sir. We'll get this figured out if we keep plugging away at it.
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
Offline
Posts: 3165
bubble!
Re: A new leak test application from COMODO !
«
Reply #68 on:
January 09, 2008, 08:47:42 PM »
Quote from: Boofo on January 09, 2008, 03:31:58 PM
Ahh, ok, I found what you were talking about. Thank you for the very detailed explanation.
The app wasn't listed in there.
Somehow it involves the hooks but I don't see where to edit those.
I thank you for all the help, sir. We'll get this figured out if we keep plugging away at it.
huh
hook? what hook?
based on my stupid experience of mistakenly allowing/blocking apps
, after i do these steps :
*find %windir%\explorer.exe ,double click on it,
*tick use a custom policy, and click access right
*on the "access rights" window==>run an axecutable==> click modify
there are lots of apps listed there, and i just
remove
the mistakenly allowed/blocked app.
Logged
Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* ****
Boofo
Comodo Member
Offline
Posts: 33
Re: A new leak test application from COMODO !
«
Reply #69 on:
January 09, 2008, 09:14:10 PM »
The app is not listed in that section so there is nothing to remove.
When you run CPLSuite it adds some hooks. That is how it bypasses the firewall.
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
Offline
Posts: 3165
bubble!
Re: A new leak test application from COMODO !
«
Reply #70 on:
January 09, 2008, 09:20:30 PM »
Quote from: Boofo on January 09, 2008, 09:14:10 PM
The app is not listed in that section so there is nothing to remove.
hmm
so you don't have specific rule for CPIL leaktest and still don't pass test 1.
Quote from: Boofo on January 09, 2008, 09:14:10 PM
When you run CPLSuite it adds some hooks. That is how it bypasses the firewall.
oh ya, i remember that, it's defense+ warning that blocked the attempt.
let see if someone can help you out. have you tried another leaktest apps? didn't pass the leaktest app by mistakenly click "allow" doesn't mean your firewall's leaking
edit :
hey, i've just tried the CPIL leaktest, i allow & remember test 1 (access physical memory directly attempt), remove the rule, but i still didn't pass test 1 after that.
let's ask for help together
i'll try to reboot my comp and see if i still fail after rebooting
«
Last Edit: January 09, 2008, 09:26:04 PM by ganda
»
Logged
Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* ****
ganda
Forum Ninja
Global Moderator
Comodo's Hero
Offline
Posts: 3165
bubble!
Re: A new leak test application from COMODO !
«
Reply #71 on:
January 09, 2008, 09:35:08 PM »
hi Boofo
just rebooted my comp, CFP3 successfully block test 1.
it's a weird problem you have there.
Logged
Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* ****
Boofo
Comodo Member
Offline
Posts: 33
Re: A new leak test application from COMODO !
«
Reply #72 on:
January 09, 2008, 09:54:25 PM »
Quote from: ganda on January 09, 2008, 09:35:08 PM
hi Boofo
just rebooted my comp, CFP3 successfully block test 1.
it's a weird problem you have there.
I even tried uninstalling and reinstalling the firewalll and it still gets through.
I emailed Melih, but he wasn't sure why it is doing that.
Logged
ganda
Forum Ninja
Global Moderator
Comodo's Hero
Offline
Posts: 3165
bubble!
Re: A new leak test application from COMODO !
«
Reply #73 on:
January 09, 2008, 10:04:02 PM »
sorry to hear that
but i gues you shouldn't worry too much, it's just leak test app that you've mistakenly allowed, not a real leakage
. perhaps you wanna try another leaktest app like GRCleaktest and see if your CFP3 can pass them.
let see if some mods here can help you.
Logged
Current Goals;
* get a new piggy doll
* become a superhero
* raise my level to 45
* learn lightning base magic
* ****
Boofo
Comodo Member
Offline
Posts: 33
Re: A new leak test application from COMODO !
«
Reply #74 on:
January 09, 2008, 10:20:04 PM »
Quote from: ganda on January 09, 2008, 10:04:02 PM
sorry to hear that
but i gues you shouldn't worry too much, it's just leak test app that you've mistakenly allowed, not a real leakage
. perhaps you wanna try another leaktest app like GRCleaktest and see if your CFP3 can pass them.
let see if some mods here can help you.
I guess it's just the principle of it all. This is the best firewall ever and I can't even stop a little leaktest.
Logged
Tags:
Pages:
1
...
3
4
[
5
]
6
7
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.359 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com