Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
September 05, 2008, 12:40:57 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
188661
Posts
22008
Topics
52794
Members
Latest Member:
chmielu
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Leak Testing/Attacks/Vulnerability Research
Comodo release 5 new security tests
« previous
next »
Pages:
1
2
[
3
]
4
Author
Topic: Comodo release 5 new security tests (Read 9774 times)
Comofo
Guest
Re: Comodo release 5 new security tests
«
Reply #30 on:
May 05, 2008, 02:22:40 AM »
If you get a chance, could you release a test for the test?
Logged
skboss
Newbie
Offline
Posts: 6
Re: Comodo release 5 new security tests
«
Reply #31 on:
May 19, 2008, 06:21:50 PM »
Hi, Guys please help me out here. when I did the test It says that ----"BITS Hijack" is vulnerable. How do I fix this problem? I am using a Norton 360 V.2 and Comodo Firewall Pro. Besides that when I did the firewall check on Symantec Internet Security checkup; it found that my Port 80 is open. please help me out. I think this is why I am getting the vulnerability error message. How can I block Port 80 or what else Can I do to make my computer secure? please help me out here.
Logged
Commodus
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 1693
Emperor Commodus is back
Re: Comodo release 5 new security tests
«
Reply #32 on:
May 19, 2008, 07:03:03 PM »
It's not very wise to run Norton 360 which has it's own firewall and Comodo v3. Norton Antivirus and Comodo firewall would be good combination (well the Comodo part for sure
)
Disabling 360's firewall may help, but then Norton will scream and shout that you are not protected and piss you off
So I don't know. It's your call
Logged
Kyle's fault
They say, "Evil prevails when good men fail to act." What they ought to say is, "Evil prevails."
FOR VIS :-)
Comodo Firewall Pro 3.0.25.378
Comodo Memory Firewall 2.0.4.20
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 3645
I'm not grumpy, just misunderstood.
Re: Comodo release 5 new security tests
«
Reply #33 on:
May 19, 2008, 07:05:52 PM »
Hi skboss, welcome to the forums
BITS stands for Background Intelligent Transfer Service, it's a Windows Service. As the name implies, it's generally involved in file transfers & is used as part of the Windows Update (WU) process. In fact, without BITS WU wouldn't work. I believe the currently vulnerability surrounds the use of the COM API.. but, CFP 3 should have detected that. However, if you are indeed running Norton 360 alongside CFP3, then this might be why it didn't. Running 2 firewalls can, apparently, cause such conflicts which result in this.
Port 80 (HTTP) open? That is unusual, unless you're running a web server (are you?). But, again.. I suppose this could because you're running 2 firewalls.. but, I've not heard of that before specifically. Have you tried GRC's Shields Up?
Logged
XP Pro+SP3 and Vista Bus+SP1 with CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very, very briefly.
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 3645
I'm not grumpy, just misunderstood.
Re: Comodo release 5 new security tests
«
Reply #34 on:
May 19, 2008, 07:14:33 PM »
One thing you could do to mitigate the BITS vulnerability is to limit SVCHOST.EXE (within CFP, not sure about 360) to only access Microsoft Update servers. I suspect this would be fairly effective at stopping the BITS hijack.. (uncertain.. anybody?).. my SVCHOST has been limited like that for years, although I also have BITS disabled (I get Windows Updates by another method).
Logged
XP Pro+SP3 and Vista Bus+SP1 with CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very, very briefly.
skboss
Newbie
Offline
Posts: 6
How to become secure to "BITS HIJACK" and How to block or SECURE port 80?
«
Reply #35 on:
May 19, 2008, 07:20:47 PM »
Hi, Guys please help me out here. I did a test with Comodo Firewall Leak Test. It says that ----"BITS Hijack" is vulnerable. How do I fix this problem?
I am using a Norton 360 V.2 and Comodo Firewall Pro. Besides that I also did the firewall check on Symantec Internet Security checkup; it found that my Port 80 is open.
I think this is why I am getting the vulnerability message. But the problem is that I don't know how to block it. Please help me out. I think this is why I am getting the vulnerability message. How can I block Port 80 or what else Can I do to make my computer secure? I also included the firewall test report to understand you guys better and to help me out. I am using Windows Vista service Pack 1. Please help me out here.
Logged
skboss
Newbie
Offline
Posts: 6
Re: Comodo release 5 new security tests
«
Reply #36 on:
May 20, 2008, 05:42:12 PM »
Hi, Kali Thank you for your response and to let you know that I am not running a web server. But still my port 80 is open, There is absolutely no way that I can close it. I tried disabling Norton Firewall and just to use Comodo Firewall but still the same result--Port 80 is open. please help me out here.
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 3645
I'm not grumpy, just misunderstood.
Re: Comodo release 5 new security tests
«
Reply #37 on:
May 20, 2008, 06:01:25 PM »
Hi skboss
Firstly disabling a firewall (ie. Norton 360) when a second firewall is present will probably not be sufficient. This is because firewalls tend to conflict at a driver level & disabling a firewall doesn't necessarily stop their drivers.
Port 80 (HTTP): Open CFP, go to the Firewall section & select "View Active Connections". You should look at the Source (not Destination) & see if there is active connection for TCP Port 80. If there is, what is the associated program? Failing that, what is telling you that TCP Port 80 is open? Symantec's web test? If so, I recommend that you go to
GRC's ShieldsUP
& confirm that via GRC's test.
Logged
XP Pro+SP3 and Vista Bus+SP1 with CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very, very briefly.
surveyor_9
Newbie
Offline
Posts: 2
Re: Comodo release 5 new security tests
«
Reply #38 on:
May 26, 2008, 08:44:17 PM »
Hi there - I was happily running CFP v3 until I downloaded and tried the clt test which I failed on all accounts.
My network defense is set at custom; my proactive defense is set at paranoid and I do not have the clt.exe allowed in my security policy. I would appreciate any help on fixing this plse. Cheers
Logged
3xist
Guest
Re: Comodo release 5 new security tests
«
Reply #39 on:
May 27, 2008, 05:05:16 AM »
Quote from: surveyor_9 on May 26, 2008, 08:44:17 PM
Hi there - I was happily running CFP v3 until I downloaded and tried the clt test which I failed on all accounts.
My network defense is set at custom; my proactive defense is set at paranoid and I do not have the clt.exe allowed in my security policy. I would appreciate any help on fixing this plse. Cheers
Hi surveyor_9 & Welcome to the forums!!
It's not a concern. This test suite is just a little difficult for some users to use (how they should answer certain alerts, etc). You are protected, Don't worry!
Josh
Logged
surveyor_9
Newbie
Offline
Posts: 2
Re: Comodo release 5 new security tests
«
Reply #40 on:
May 27, 2008, 05:31:58 AM »
Hi Josh - thanks for the welcome. I am sure that I am protected but if I can tweak the system then I would be interested in passing the security tests. Is this possible? Cheers Surveyor_9
Logged
J2897
Comodo Loves me
Offline
Posts: 111
Limited User Account Enforcer
Re: Comodo release 5 new security tests
«
Reply #41 on:
June 05, 2008, 05:47:49 AM »
I haven't tried the test. I'm just reading, wondering why no one has gave step by step instructions on how to pass the test...
I was going to use it on my friends/families PC's and use it to try and convinece them to try Comodo.
Logged
Video Tutorial
don67
Comodo Member
Offline
Posts: 41
Re: Comodo release 5 new security tests
«
Reply #42 on:
June 11, 2008, 01:47:05 PM »
I run the CLT again with the latest version and this is the result....
«
Last Edit: June 11, 2008, 02:54:39 PM by don67
»
Logged
Blas
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 361
Re: Comodo release 5 new security tests
«
Reply #43 on:
June 11, 2008, 07:03:19 PM »
Don,
Was CLT already on your computer before installing the firewall?
Logged
don67
Comodo Member
Offline
Posts: 41
Re: Comodo release 5 new security tests
«
Reply #44 on:
June 14, 2008, 03:08:53 AM »
Yes CLT is on my computer before i install the firewall in my partition
Logged
Tags:
Pages:
1
2
[
3
]
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 23.99 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com