Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 17, 2010, 01:04:54 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
371986
Posts
41195
Topics
93814
Members
Latest Member:
sanford58
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Leak Testing/Attacks/Vulnerability Research
Comodo Firewall Pro isn`t passing leak tests [Resolved]
« previous
next »
Pages:
1
2
3
[
4
]
5
Author
Topic: Comodo Firewall Pro isn`t passing leak tests [Resolved] (Read 11118 times)
Toggie
Guest
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #45 on:
May 17, 2007, 12:11:30 AM »
The whole idea of the CPIL test is to simulate DLL Injection. Essentially, CPIL injects a DLL into EXPLORER.EXE which is the parent application for INTERNET EXPLORER. EXPLORER.EXE then TRYs to make use of IEs Internet Connection. CFP identifies the DLL injection and duly notifies you, hence the alert. You are supposed to BLOCK the alert, thus stopping the hijack.
Logged
mrx666
Comodo Member
Offline
Posts: 42
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #46 on:
May 17, 2007, 12:13:31 AM »
WHAT!!?? Then why am I not seeing any alerts?? I`m telling you, nothing is going up when I do the tests! I`m tired, but not THAT tired! I did mention the last test, where I clicked on test one and the red square turned to a blue shield for a second, then went back to a red square. Would that have anything to do with it?
Logged
mrx666
Comodo Member
Offline
Posts: 42
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #47 on:
May 17, 2007, 12:17:27 AM »
This is my alerts page:
Logged
Toggie
Guest
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #48 on:
May 17, 2007, 12:21:52 AM »
Quote from: mrx666 on May 17, 2007, 12:04:12 AM
I`m seeing alerts for this type of activity,
I`m not seeing alerts for the leak tests.
I'm sorry did I misunderstand your comment? If you are seeing an alert for this
Date/Time :2007-05-16 20:30:41
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (iexplore.exe)
Application: C:\Program Files\Internet Explorer\iexplore.exe
Parent: C:\WINDOWS\explorer.exe
Protocol: UDP Out
Destination: x.x.x.x::dns(53)
Details: C:\WINDOWS\explorer.exe has tried to use C:\Program Files\Internet Explorer\iexplore.exe through OLE Automation, which can be used to hijack other applications.
You are seeing an alert for the leak test.
Logged
mrx666
Comodo Member
Offline
Posts: 42
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #49 on:
May 17, 2007, 12:27:49 AM »
No, you didn`t misunderstand. I think I mis-spoke.
Ok, one more time, I`m going to clear my cache, reboot, and take the test again. Then I`ll check the activity log and see what it says. Back in 5.
Logged
mrx666
Comodo Member
Offline
Posts: 42
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #50 on:
May 17, 2007, 12:55:36 AM »
Ok, here`s my activity log. I took the test around 10:40. CFP failed the test with no alerts. The square turned into a shield and back into a square.
Logged
Toggie
Guest
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #51 on:
May 17, 2007, 01:12:41 AM »
Well, I'm mystified right now. As far as I can see CFP is doing exactly what it should, at least as far as the logs are concerned. As to why you are not receiving any pop-ups from CFP, I just don't know. I have to wonder if the installation is corrupt in some way.
Here is one of the alerts I get when I run test 1
Logged
Toggie
Guest
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #52 on:
May 17, 2007, 01:18:16 AM »
Actually, I've just noticed something. your log entries are different from mine. When I run test 1, I get this:
Date/Time :2007-05-17 17:05:40
Severity :High
Reporter :Application Behavior Analysis
Description: Suspicious Behaviour (IEXPLORE.EXE)
Application: C:\Program Files\Internet Explorer\IEXPLORE.EXE
Parent: C:\WINDOWS\explorer.exe
Protocol: UDP Out
Destination: x.x.x.x::dns(53)
Details: C:\Documents and Settings\*\My Documents\Software\CPILSuite\cpil.exe modified the memory of the Parent application C:\WINDOWS\explorer.exe in memory.
You logs don't contain any references to CPIL, I wonder why?
Logged
mrx666
Comodo Member
Offline
Posts: 42
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #53 on:
May 17, 2007, 01:31:28 AM »
Because, for some reason, everything is being delayed. See if there`s anything funny here
Logged
mrx666
Comodo Member
Offline
Posts: 42
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #54 on:
May 17, 2007, 01:44:22 AM »
Quote from: Toggie on May 17, 2007, 01:12:41 AM
Well, I'm mystified right now. As far as I can see CFP is doing exactly what it should, at least as far as the logs are concerned. As to why you are not receiving any pop-ups from CFP, I just don't know. I have to wonder if the installation is corrupt in some way.
Here is one of the alerts I get when I run test 1
I`ve got that alert twice in the last 15 minutes. I clicked on deny, and my pages came up just like in your screen shot. But the thing was, I wasn`t doing a test!
«
Last Edit: May 17, 2007, 01:48:39 AM by mrx666
»
Logged
Toggie
Guest
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #55 on:
May 17, 2007, 01:49:37 AM »
I'm not sure how you're even managing to connect, everything is being denied. Personally, I would be inclined to re-install cfp, taking care to make sure all traces of the former installation have been successfully removed, both from the Hard disk and the registry.
On a similar note, did you have a different firewall installed before CFP, if so, which?
Logged
mrx666
Comodo Member
Offline
Posts: 42
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #56 on:
May 17, 2007, 01:59:10 AM »
People`s PC had a firewall in their security pack.
As for the download, should I save it to disk, or run it straight from the download? Also, no matter which way I do it, I can`t have ANY anti-virus or malware running? Doesn`t that leave my computer open to viruses and trojans?
«
Last Edit: May 17, 2007, 02:00:54 AM by mrx666
»
Logged
mrx666
Comodo Member
Offline
Posts: 42
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #57 on:
May 17, 2007, 02:02:51 AM »
Another thing, what`s the best way to remove it from the registry?
Logged
Toggie
Guest
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #58 on:
May 17, 2007, 02:09:56 AM »
For the duration of the installation I think you'll be safe. Disconnect from the net for a few minutes if your worried. It really is better not to have any additional applications running when you run the install.
Personally, I download and then run the setup.
once you have run the un-installer, open regedit (start/run/regedit) and search for any entries related to Comodo and delete them. Reboot, then reinstall.
Logged
mrx666
Comodo Member
Offline
Posts: 42
Re: Comodo Firewall Pro isn`t passing leak tests
«
Reply #59 on:
May 17, 2007, 02:17:16 AM »
Ok, that`s what I`ll do later today. Hopefully, I won`t have to come back with the same problem(you guys will probably ban me if I do! LOL!!) Right now, I`m off to bed. Thank you very much for helping me. Thank you to the other moderators, too. Have a very good night/morning.
Logged
Tags:
Pages:
1
2
3
[
4
]
5
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.053 seconds with 16 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com