Welcome, Guest. Please login or register.
October 11, 2008, 05:22:26 AM

Login with username, password and session length

199171 Posts
22886 Topics
54928 Members

Latest Member: ptr1959w

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  An Independent Firewall Leak Testing
« previous next »
Pages: [1] Go Down Print
Author Topic: An Independent Firewall Leak Testing  (Read 3288 times)
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 1737



« on: November 28, 2006, 08:30:45 PM »

Hi All,

Guys at the following site published a comprehensive firewall leak test.
http://www.matousec.com/projects/windows-personal-firewall-analysis/leak-tests-results.php

Unlike other testers, these guy(s?) are systems programmer(s) and are very familiar with modern malware techniques.

Thats why cheaters failed ! Wink

Current version i.e. CPF 2.3.6.81, had a race condition bug which caused it to fail the leak test "Coat" but beta versions are immune from this bug.

Egemen
Logged
AOwL
Comodo SuperHero
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2349


Comodo Firewall Pro - Be safe, use protection...


WWW
« Reply #1 on: November 28, 2006, 09:05:44 PM »

Read it and weep Cry :Smiley Grin
Logged

WinXP SP2 HE - IE7 - FF 2 - TB - CFP 2.4 - NOD32 - BoClean -ST - AMD64x2 - 3Gb Ram - 1.5Tb HD
TheTOM_SK
Comodo Loves me
****
Offline Offline

Posts: 121



« Reply #2 on: November 29, 2006, 05:12:15 AM »

Congrats and keep up good work and do not start cheating, you do not have to unlike others.
Logged
Graham1
Comodo's Hero
*****
Offline Offline

Posts: 618



« Reply #3 on: November 29, 2006, 01:27:05 PM »

Thats why cheaters failed ! Wink

I can't believe the Outpost guys tried to cheat Shocked. Did they think they wouldn't get caught :Smiley. I bet alot of Outpost user's will deflect because of this and guess where they will be coming...

Smiley

Edit: I wonder why ZoneAlarm Free wasn't included in the tests or does it have similar protection as the paid version?
« Last Edit: November 29, 2006, 01:29:54 PM by Graham1 » Logged
AOwL
Comodo SuperHero
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2349


Comodo Firewall Pro - Be safe, use protection...


WWW
« Reply #4 on: November 29, 2006, 01:37:56 PM »

Zone Alarm free doesn't come close to the paid (Pro) one...
Logged

WinXP SP2 HE - IE7 - FF 2 - TB - CFP 2.4 - NOD32 - BoClean -ST - AMD64x2 - 3Gb Ram - 1.5Tb HD
pandlouk
I love Comodo
Comodo's Hero
*****
Offline Offline

Posts: 2240


Panagiotis


« Reply #5 on: November 29, 2006, 02:23:17 PM »

 Comodo Rocks Love Bounce
Logged
jasper2408
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 651


« Reply #6 on: November 29, 2006, 04:22:36 PM »

Congrats go to the Comodo crew for a job well done.    Clapping

jasper
Logged

CFP 3.0.22.327beta  CMF   Avast Pro  SAS Pro Sandboxie Win XP PRO SP2 (x32)
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 1737



« Reply #7 on: November 29, 2006, 05:12:51 PM »

I can't believe the Outpost guys tried to cheat Shocked. Did they think they wouldn't get caught :Smiley. I bet alot of Outpost user's will deflect because of this and guess where they will be coming...

Smiley

Edit: I wonder why ZoneAlarm Free wasn't included in the tests or does it have similar protection as the paid version?

Here "cheating" means "inadequate defense".  So its defense is good enough to pass the leak tests. But when it comes to the real world, such a defense is hardly enough.

So please note that "Cheating" does not mean "deception" in this context.

Egemen
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6017



« Reply #8 on: November 30, 2006, 11:06:10 AM »

Hi All,

Guys at the following site published a comprehensive firewall leak test.
http://www.matousec.com/projects/windows-personal-firewall-analysis/leak-tests-results.php

Egemen

Egemen, Melih,

Do we know what Matousec means by "Highest Security" in regards to CPF?  I realize the "Default" is probably from an automatic install; CPF's regular settings.  What is their "Highest"?

TNX,

LM
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 1737



« Reply #9 on: November 30, 2006, 11:50:01 AM »

Egemen, Melih,

Do we know what Matousec means by "Highest Security" in regards to CPF?  I realize the "Default" is probably from an automatic install; CPF's regular settings.  What is their "Highest"?

TNX,

LM

It should mean "Do not show alerts for the applications certified by COMODO" option disabled. With this option enabled CPF fails wallbreaker(1,3,4) tests. 

Other than that out of the box for anti-leak resistance should be as good. And for that test, we intentionally skipped further checks because it would generate unnecessarily large number of alerts. So when HIPS enabled CPF is released, it will ask before the process is executed as others do.

Currently, it does not pose a really serious risk because it is highly visible to the user(Otherwise CPF would catch).

You can leave your settings as out of the box.

Egemen
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6017



« Reply #10 on: November 30, 2006, 12:16:33 PM »

Thanks for the info, Egemen!

LM
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
solo
Comodo Loves me
****
Offline Offline

Posts: 153


« Reply #11 on: December 05, 2006, 11:38:23 AM »

Here "cheating" means "inadequate defense".  So its defense is good enough to pass the leak tests. But when it comes to the real world, such a defense is hardly enough.

So please note that "Cheating" does not mean "deception" in this context.

Egemen

In a way, cheating in this context does mean deception:  deception of the end user.  Outpost Pro wants the end user to feel fully ptotected by putting in measures that will get around the leak test.  But in reality, the measures in place will not truly protect the end user from "real world" malware.

I would call that deception.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.429 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com