Welcome, Guest. Please login or register.
March 17, 2010, 01:04:54 AM

Login with username, password and session length

371986 Posts
41195 Topics
93814 Members

Latest Member: sanford58

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Leak Testing/Attacks/Vulnerability Research
| | |-+  Comodo Firewall Pro isn`t passing leak tests [Resolved]
« previous next »
Pages: 1 2 3 [4] 5 Go Down Print
Author Topic: Comodo Firewall Pro isn`t passing leak tests [Resolved]  (Read 11118 times)
Toggie
Guest
« Reply #45 on: May 17, 2007, 12:11:30 AM »

The whole idea of the CPIL test is to simulate DLL Injection. Essentially, CPIL injects a DLL into EXPLORER.EXE which is the parent application for INTERNET EXPLORER. EXPLORER.EXE then TRYs to make use of IEs Internet Connection. CFP identifies the DLL injection and duly notifies you, hence the alert. You are supposed to BLOCK the alert, thus stopping the hijack.
Logged
mrx666
Comodo Member
**
Offline Offline

Posts: 42


« Reply #46 on: May 17, 2007, 12:13:31 AM »

WHAT!!?? Then why am I not seeing any alerts?? I`m telling you, nothing is going up when I do the tests! I`m tired, but not THAT tired! I did mention the last test, where I clicked on test one and the red square turned to a blue shield for a second, then went back to a red square. Would that have anything to do with it?
Logged
mrx666
Comodo Member
**
Offline Offline

Posts: 42


« Reply #47 on: May 17, 2007, 12:17:27 AM »

This is my alerts page:

Logged
Toggie
Guest
« Reply #48 on: May 17, 2007, 12:21:52 AM »

I`m seeing alerts for this type of activity, I`m not seeing alerts for the leak tests.

I'm sorry did I misunderstand your comment? If you are seeing an alert for this

Date/Time :2007-05-16 20:30:41
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (iexplore.exe)
Application: C:\Program Files\Internet Explorer\iexplore.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: UDP Out
Destination: x.x.x.x::dns(53)
Details: C:\WINDOWS\explorer.exe has tried to use C:\Program Files\Internet Explorer\iexplore.exe through OLE Automation, which can be used to hijack other applications.

You are seeing an alert for the leak test.
Logged
mrx666
Comodo Member
**
Offline Offline

Posts: 42


« Reply #49 on: May 17, 2007, 12:27:49 AM »

No, you didn`t misunderstand. I think I mis-spoke.
Ok, one more time, I`m going to clear my cache, reboot, and take the test again. Then I`ll check the activity log and see what it says. Back in 5.
Logged
mrx666
Comodo Member
**
Offline Offline

Posts: 42


« Reply #50 on: May 17, 2007, 12:55:36 AM »

Ok, here`s my activity log. I took the test around 10:40. CFP failed the test with no alerts. The square turned into a shield and back into a square.
Logged
Toggie
Guest
« Reply #51 on: May 17, 2007, 01:12:41 AM »

Well, I'm mystified right now. As far as I can see CFP is doing exactly what it should, at least as far as the logs are concerned. As to why you are not receiving any pop-ups from CFP, I just don't know. I have to wonder if the installation is corrupt in some way.

Here is one of the alerts I get when I run test 1
Logged
Toggie
Guest
« Reply #52 on: May 17, 2007, 01:18:16 AM »

Actually, I've just noticed something. your log entries are different from mine. When I run test 1, I get this:

Date/Time :2007-05-17 17:05:40
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (IEXPLORE.EXE)
Application: C:\Program Files\Internet Explorer\IEXPLORE.EXE
Parent: C:\WINDOWS\explorer.exe
Protocol: UDP Out
Destination: x.x.x.x::dns(53)
Details: C:\Documents and Settings\*\My Documents\Software\CPILSuite\cpil.exe modified the memory of the Parent application C:\WINDOWS\explorer.exe in memory.

You logs don't contain any references to CPIL, I wonder why?
Logged
mrx666
Comodo Member
**
Offline Offline

Posts: 42


« Reply #53 on: May 17, 2007, 01:31:28 AM »

Because, for some reason, everything is being delayed. See if there`s anything funny here
Logged
mrx666
Comodo Member
**
Offline Offline

Posts: 42


« Reply #54 on: May 17, 2007, 01:44:22 AM »

Well, I'm mystified right now. As far as I can see CFP is doing exactly what it should, at least as far as the logs are concerned. As to why you are not receiving any pop-ups from CFP, I just don't know. I have to wonder if the installation is corrupt in some way.

Here is one of the alerts I get when I run test 1

I`ve got that alert twice in the last 15 minutes. I clicked on deny, and my pages came up just like in your screen shot. But the thing was, I wasn`t doing a test!
« Last Edit: May 17, 2007, 01:48:39 AM by mrx666 » Logged
Toggie
Guest
« Reply #55 on: May 17, 2007, 01:49:37 AM »

I'm not sure how you're even managing to connect, everything is being denied. Personally, I would be inclined to re-install cfp, taking care to make sure all traces of the former installation have been successfully removed, both from the Hard disk and the registry.

On a similar note, did you have a different firewall installed before CFP, if so, which?
Logged
mrx666
Comodo Member
**
Offline Offline

Posts: 42


« Reply #56 on: May 17, 2007, 01:59:10 AM »

People`s PC had a firewall in their security pack.
As for the download, should I save it to disk, or run it straight from the download? Also, no matter which way I do it, I can`t have ANY anti-virus or malware running? Doesn`t that leave my computer open to viruses and trojans?
« Last Edit: May 17, 2007, 02:00:54 AM by mrx666 » Logged
mrx666
Comodo Member
**
Offline Offline

Posts: 42


« Reply #57 on: May 17, 2007, 02:02:51 AM »

Another thing, what`s the best way to remove it from the registry?
Logged
Toggie
Guest
« Reply #58 on: May 17, 2007, 02:09:56 AM »

For the duration of the installation I think you'll be safe. Disconnect from the net for a few minutes if your worried. It really is better not to have any additional applications running when you run the install.

Personally, I download and then run the setup.

once you have run the un-installer, open regedit (start/run/regedit) and search for any entries related to Comodo and delete them. Reboot, then reinstall.
Logged
mrx666
Comodo Member
**
Offline Offline

Posts: 42


« Reply #59 on: May 17, 2007, 02:17:16 AM »

Ok, that`s what I`ll do later today. Hopefully, I won`t have to come back with the same problem(you guys will probably ban me if I do! LOL!!) Right now, I`m off to bed. Thank you very much for helping me. Thank you to the other moderators, too. Have a very good night/morning.
Logged
Tags:
Pages: 1 2 3 [4] 5 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.053 seconds with 16 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com