Welcome, Guest. Please login or register.
July 25, 2008, 07:06:52 PM

Login with username, password and session length

177082 Posts
20939 Topics
50765 Members

Latest Member: georgewevell

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Comodo release 5 new security tests
« previous next »
Pages: 1 2 [3] 4 Go Down Print
Author Topic: Comodo release 5 new security tests  (Read 7485 times)
Comofo
Guest
« Reply #30 on: May 05, 2008, 02:22:40 AM »

If you get a chance, could you release a test for the test?  Tongue


 Viva Comodo
Logged
skboss
Newbie
*
Offline Offline

Posts: 6


« Reply #31 on: May 19, 2008, 06:21:50 PM »

Hi, Guys please help me out here. when I did the test It says that ----"BITS Hijack"  is vulnerable. How do I fix this problem? I am using a Norton 360 V.2 and Comodo Firewall Pro. Besides that when I did the firewall check on Symantec Internet Security checkup; it found that my Port 80 is open. please help me out. I think this is why I am getting the vulnerability error message. How can I block Port 80 or what else Can I do to make my computer secure? please help me out here.
Logged
Commodus
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 1380


Emperor Commodus


« Reply #32 on: May 19, 2008, 07:03:03 PM »

It's not very wise to run Norton 360 which has it's own firewall and Comodo v3. Norton Antivirus and Comodo firewall would be good combination (well the Comodo part for sure  Grin)
Disabling 360's firewall may help, but then Norton will scream and shout that you are not protected and piss you off  Cheesy
So I don't know. It's your call  Smiley
Logged

I don’t know what the key to success is, but the key to failure is trying to please everyone ...

nLited Windows XP Professional SP3 32 bit
Comodo Firewall Pro Version 3.0.25.378
Comodo Memory Firewall Version 2.0.4.20
Comodo Vulnerability Analyzer Version 1.0.1.18 BETA
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3628


I'm not grumpy, just misunderstood.


« Reply #33 on: May 19, 2008, 07:05:52 PM »

Hi skboss, welcome to the forums

BITS stands for Background Intelligent Transfer Service, it's a Windows Service. As the name implies, it's generally involved in file transfers & is used as part of the Windows Update (WU) process. In fact, without BITS WU wouldn't work. I believe the currently vulnerability surrounds the use of the COM API.. but, CFP 3 should have detected that. However, if you are indeed running Norton 360 alongside CFP3, then this might be why it didn't. Running 2 firewalls can, apparently, cause such conflicts which result in this.

Port 80 (HTTP) open? That is unusual, unless you're running a web server (are you?). But, again.. I suppose this could because you're running 2 firewalls.. but, I've not heard of that before specifically. Have you tried GRC's Shields Up?

Logged

XP Pro+SP3 & CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very briefly.
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3628


I'm not grumpy, just misunderstood.


« Reply #34 on: May 19, 2008, 07:14:33 PM »

One thing you could do to mitigate the BITS vulnerability is to limit SVCHOST.EXE (within CFP, not sure about 360) to only access Microsoft Update servers. I suspect this would be fairly effective at stopping the BITS hijack.. (uncertain.. anybody?).. my SVCHOST has been limited like that for years, although I also have BITS disabled (I get Windows Updates by another method).
Logged

XP Pro+SP3 & CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very briefly.
skboss
Newbie
*
Offline Offline

Posts: 6


« Reply #35 on: May 19, 2008, 07:20:47 PM »

Hi, Guys please help me out here.  I did a test with Comodo Firewall Leak Test. It says that ----"BITS Hijack"  is vulnerable. How do I fix this problem?  Sad I am using a Norton 360 V.2 and Comodo Firewall Pro. Besides that  I also did the firewall check on Symantec Internet Security checkup; it found that my Port 80 is open.  Sad I think this is why I am getting the vulnerability message. But the problem is that  I don't know how to block it. Please help me out. I think this is why I am getting the vulnerability message. How can I block Port 80 or what else Can I do to make my computer secure? I also included the firewall test report to understand you guys better and to help me out. I am using Windows Vista service Pack 1. Please help me out here.
Logged
skboss
Newbie
*
Offline Offline

Posts: 6


« Reply #36 on: May 20, 2008, 05:42:12 PM »

Hi, Kali Thank you for your response and to let you know that I am not running a web server. But still my port 80 is open, There is absolutely no way that I can close it. I tried disabling Norton Firewall and just to use Comodo Firewall but still the same result--Port 80 is open. please help me out here.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3628


I'm not grumpy, just misunderstood.


« Reply #37 on: May 20, 2008, 06:01:25 PM »

Hi skboss

Firstly disabling a firewall (ie. Norton 360) when a second firewall is present will probably not be sufficient. This is because firewalls tend to conflict at a driver level & disabling a firewall doesn't necessarily stop their drivers.

Port 80 (HTTP): Open CFP, go to the Firewall section & select "View Active Connections". You should look at the Source (not Destination) & see if there is active connection for TCP Port 80. If there is, what is the associated program? Failing that, what is telling you that TCP Port 80 is open? Symantec's web test? If so, I recommend that you go to GRC's ShieldsUP & confirm that via GRC's test.
Logged

XP Pro+SP3 & CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very briefly.
surveyor_9
Newbie
*
Offline Offline

Posts: 2


« Reply #38 on: May 26, 2008, 08:44:17 PM »

Hi there - I was happily running CFP v3 until I downloaded and tried the clt test which I failed on all accounts.
My network defense is set at custom; my proactive defense is set at paranoid and I do not have the clt.exe allowed in my security policy. I would appreciate any help on fixing this plse. Cheers
Logged
3xist
Guest
« Reply #39 on: May 27, 2008, 05:05:16 AM »

Hi there - I was happily running CFP v3 until I downloaded and tried the clt test which I failed on all accounts.
My network defense is set at custom; my proactive defense is set at paranoid and I do not have the clt.exe allowed in my security policy. I would appreciate any help on fixing this plse. Cheers

Hi surveyor_9 & Welcome to the forums!!

It's not a concern. This test suite is just a little difficult for some users to use (how they should answer certain alerts, etc). You are protected, Don't worry!  Wink

Josh
Logged
surveyor_9
Newbie
*
Offline Offline

Posts: 2


« Reply #40 on: May 27, 2008, 05:31:58 AM »

Hi Josh - thanks for the welcome. I am sure that I am protected but if I can tweak the system then I would be interested in passing the security tests. Is this possible? Cheers Surveyor_9
Logged
J2897
Comodo Member
**
Offline Offline

Posts: 46


Limited User Account Enforcer


WWW
« Reply #41 on: June 05, 2008, 05:47:49 AM »

I haven't tried the test. I'm just reading, wondering why no one has gave step by step instructions on how to pass the test...

I was going to use it on my friends/families PC's and use it to try and convinece them to try Comodo.
Logged

don67
Comodo Member
**
Offline Offline

Posts: 37


« Reply #42 on: June 11, 2008, 01:47:05 PM »

I run the CLT again with the latest version and this is the result.... Thumb Down




« Last Edit: June 11, 2008, 02:54:39 PM by don67 » Logged
Blas
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 352


« Reply #43 on: June 11, 2008, 07:03:19 PM »

Don,

Was CLT already on your computer before installing the firewall?
Logged
don67
Comodo Member
**
Offline Offline

Posts: 37


« Reply #44 on: June 14, 2008, 03:08:53 AM »

Yes CLT is on my computer before i install the firewall in my partition Thinking
Logged
Tags:
Pages: 1 2 [3] 4 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.114 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com