Welcome, Guest. Please login or register.
July 25, 2008, 01:57:10 PM

Login with username, password and session length

177028 Posts
20928 Topics
50751 Members

Latest Member: evlassassin

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Comodo release 5 new security tests
« previous next »
Pages: 1 [2] 3 4 Go Down Print
Author Topic: Comodo release 5 new security tests  (Read 7468 times)
SplittingDistant
Newbie
*
Offline Offline

Posts: 4


« Reply #15 on: April 20, 2008, 07:44:50 AM »

My setup (CFP & CAVS - which I thought were configured correctly) managed:

"Vulnerable" on Rootkit Installation 1
"Protected" on Rootkit 2
"Error" for both .dll injections
"Vulnerable" to the BITS hijack.

Are we going to see any advice  from Comodo regarding ways to configure their products to protect against these threats?

Comodo, you've told me about the monster in the wardrobe, but not how to keep him locked in there. If you don't help me I'm going to have nightmares and probably wet the bed. I'm sure you don't want that to happen.

 
« Last Edit: April 20, 2008, 07:55:58 AM by SplittingDistant » Logged
Coolio10
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 461


« Reply #16 on: April 20, 2008, 08:35:31 AM »

They must of released it without testing against cfp. Many firewalls are passing but a lot of them come up with error which is basically saying your firewall passed. And many are also coming up vulnerable to BITS. I highly doubt comodo would release tests their own firewall couldn't pass so these tests seem to be screwed up.
Logged

(\__/)
(='.'=)
('')_('')

Giveaway of the Day" style="border: none
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3628


I'm not grumpy, just misunderstood.


« Reply #17 on: April 20, 2008, 09:49:02 AM »

BITS: The BITS vulnerability has been know about for some time. Unfortunately, BITS is a required component of Windows Updates (WU). Because of this vulnerability I, and probably many others, have disabled WU from automatically running on their systems and, for me, this included BITS itself. I used to manually turn BITS on (usually set to Manual) when I wanted to run WU, but since AutoPatcher rose from the ashes recently (with APUP) I don't use BITS any more.

I'm boring everybody with these.. BITS.. since I wonder if this why some people are passing the BITS test, whilst others are not.
Logged

XP Pro+SP3 & CFP 3.0.25.378 & AntiVir PE 8.1 & Firefox 3.0.1
__
Will computers ever be as smart as humans? Probably.. very briefly.
Copy, right?
Newbie
*
Offline Offline

Posts: 8



« Reply #18 on: April 20, 2008, 05:13:03 PM »

Oh, NOW I get it, ...I think... where was I? Is this utility testing the firewall or the defence+? Because I was granting it access to execute, because I thought it was trying to "phone home", and that I was supposed to configure my firewall to stop it.

But I am not supposed to let it execute, is that right?

I'm so very confused...
Logged
david banner
Comodo Family Member
***
Offline Offline

Posts: 61


« Reply #19 on: April 27, 2008, 03:57:54 PM »

I was protected on the first, error for next 3 and  vulnerable to BITS Hijack. But it is not clear at all how to respond. Should all firewall alerts be blocked?
« Last Edit: April 27, 2008, 04:59:58 PM by david banner » Logged

Thanks

David
ailef
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 433



« Reply #20 on: April 27, 2008, 07:12:29 PM »

it depends which alers u got, when the test wants to modify protected keys or create new ones or create files or load driver and run it or try to connect to the network, u should block all activities that are dangerous, like accessing high privileges too. all those activities can be allowed for safe apps but with unknown files, u see that his activities are just a way to attack your system.
Logged

xp pro sp3 & vista ultimate sp1 (both 32bits) - comodo 3.0.25.378 - kav 8.0.0.357 - superadblocker 4.6.0.1000
marren
Newbie
*
Offline Offline

Posts: 5


« Reply #21 on: May 01, 2008, 05:16:22 AM »

commodo fails on test 2-4 on my system regardless if I allow or block. I've just installed this and is trying to get this to work but I must say loosing confidence in this program fast. if a program is this hard to get configured to pass a test that "any decent security app" should pass then I guess it doesn't qualify as such an application I'm really surprised it won't pass it own tests out of the box without questions
Logged
Josh123
Guest
« Reply #22 on: May 03, 2008, 09:29:58 PM »

commodo fails on test 2-4 on my system regardless if I allow or block. I've just installed this and is trying to get this to work but I must say loosing confidence in this program fast. if a program is this hard to get configured to pass a test that "any decent security app" should pass then I guess it doesn't qualify as such an application I'm really surprised it won't pass it own tests out of the box without questions

Did you read the instructions in the first post, marren?

Some Alerts you need to ALLOW in order to past this test. That's what I figured. No need to lose trust in it Smiley

Josh
Logged
don67
Comodo Member
**
Offline Offline

Posts: 37


« Reply #23 on: May 04, 2008, 08:57:57 AM »

My comodo fails all the test?



Logged
salmonela
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 365


Spy


« Reply #24 on: May 04, 2008, 09:33:27 AM »

don67, find clt.exe and remove it from "security Policy" and run test again (see picture)
Logged

XP Pro SP3, Pentium4-3Ghz, 4×512Mb DDR, Ralink RT61 WLAN PCI adapter, ZyXEL P-660HW-D3 WLAN Router DSL modem
Bad English, I know...
Thanks
PLEASE DO NOT REPLY DUMB QUESTIONS/ANSWERS
don67
Comodo Member
**
Offline Offline

Posts: 37


« Reply #25 on: May 04, 2008, 10:54:59 AM »

DLL Injection 1, 2 is error Thinking
Logged
Comofo
Guest
« Reply #26 on: May 04, 2008, 11:38:15 AM »

Yeah, um, this one's a bit vague...I got:
1) Protected
2) Protected
3) Protected
4) Error
5) Crrrrashhhh...

At least I know I got the alerts...that's something anyway... Roll Eyes
Logged
marren
Newbie
*
Offline Offline

Posts: 5


« Reply #27 on: May 04, 2008, 12:32:29 PM »

Did you read the instructions in the first post, marren?

Some Alerts you need to ALLOW in order to past this test. That's what I figured. No need to lose trust in it Smiley

Josh

Hmm yes and the first time I ran the test I did allow all, but the result was the same. I then tried blocking all just for good measure and still I got the results:
Passed; Error; Error; Error; Crash. Seems more people have problems with the test so it not unique for me.
Logged
don67
Comodo Member
**
Offline Offline

Posts: 37


« Reply #28 on: May 04, 2008, 01:19:26 PM »

here's mine
Logged
Josh123
Guest
« Reply #29 on: May 05, 2008, 02:19:34 AM »

Some funny results, eh?

Hope Paul gets back...

Josh
Logged
Tags:
Pages: 1 [2] 3 4 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.902 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com