Welcome, Guest. Please login or register.
December 29, 2009, 01:38:02 PM

Login with username, password and session length

346042 Posts
38229 Topics
86811 Members

Latest Member: faszfej

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Killed cfp.exe demonstration video by mj0011
« previous next »
Pages: [1] 2 3 4 Go Down Print
Author Topic: Killed cfp.exe demonstration video by mj0011  (Read 4101 times)
sirio
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1306



« on: November 02, 2009, 06:00:08 AM »

http://www.wilderssecurity.com/showthread.php?p=1567985#post1567985

Video download: http://e.ys168.com/note/fd.htm?http://ys-G.ys168.com/?killcis.rar_50chkk8e1dks7bkks0c0bthsjtlrlllh5bikslm1biu14z97f14z

click on left button and download killcis.rar
Logged

Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 3275



WWW
« Reply #1 on: November 02, 2009, 06:12:20 AM »

Already posted here earlier.
http://forums.comodo.com/empty-t47132.0.html;topicseen
Logged

E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM.  500gb. HDD


~~~
Trying to see if I can completely switch to linux Cheesy
sirio
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1306



« Reply #2 on: November 02, 2009, 06:27:33 AM »

Sorry, I had not attentively looked.

Thanks Kyle Smiley
Logged

SS26
Comodo's Hero
*****
Offline Offline

Posts: 1503


« Reply #3 on: November 02, 2009, 04:37:38 PM »


Drops an error on screen.  Not downloading.....
Logged
sirio
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1306



« Reply #4 on: November 03, 2009, 04:48:58 AM »

Have you tried to download it with Internet Explorer?

In the case you still had problems, I attach the file.

There are some things that make me be sceptic. For example, why CIS is not correctly (attached screen) initialized while him is performing the test?
« Last Edit: November 03, 2009, 07:33:21 PM by sirio » Logged

3DNow
Newbie
*
Offline Offline

Posts: 18


« Reply #5 on: November 03, 2009, 05:36:29 AM »

because before test cfp.exe , he was kill cmdagent.exe with killcis.exe the first.
However, process protection is still at work
Logged
sirio
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1306



« Reply #6 on: November 03, 2009, 07:18:33 AM »

because before test cfp.exe , he was kill cmdagent.exe with killcis.exe the first.

Ok, why he doesn't make it see?

Quote
However, process protection is still at work

I imagined...

Have you the PoC?
Logged

evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 341


« Reply #7 on: November 03, 2009, 09:31:35 AM »

If you have acccess to the POC it would be nice if you could share it here.
Logged
3DNow
Newbie
*
Offline Offline

Posts: 18


« Reply #8 on: November 03, 2009, 12:37:28 PM »

I'll give you some tips:
(1). in the video , the cfp.exe process is not quickly terminated , so this may be a force attack and depending on some mechanism inside the process
(2).CIS's driver donot hook the function :NtFreeVirtualMemory , which can be use to free all the memory in any process.
Logged
sirio
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1306



« Reply #9 on: November 03, 2009, 02:12:53 PM »

Thank you for the tips 3DNow,
I'm a person simple, ignorant.. and then I am as San Thomas: if I don't see I don't believe Grin
I would like to try in my pc.

My doubt remains: why he doesn't show us in the video when cmdagent comes killed?


Regards.
« Last Edit: November 03, 2009, 02:14:27 PM by sirio » Logged

SS26
Comodo's Hero
*****
Offline Offline

Posts: 1503


« Reply #10 on: November 03, 2009, 03:41:34 PM »

Have you tried to download it with Internet Explorer?
Nope.

I attach the file.
Thanks
Logged
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2151



« Reply #11 on: November 03, 2009, 03:48:48 PM »

I'll give you some tips:
(1). in the video , the cfp.exe process is not quickly terminated , so this may be a force attack and depending on some mechanism inside the process
(2).CIS's driver donot hook the function :NtFreeVirtualMemory , which can be use to free all the memory in any process.

You dont need to hook NtFreeVirtualMemory because you have to obtain PROCESS_VM_OPERATION access right to COMODO processes first and this is intercepted by CIS.
Obviously one doesnt produce videos for getting the credit. He will have to do something real.
When we see the PoC, we will see what this is about Smiley Poking our products for holes is always a good thing.
« Last Edit: November 03, 2009, 03:56:06 PM by egemen » Logged
3DNow
Newbie
*
Offline Offline

Posts: 18


« Reply #12 on: November 03, 2009, 08:12:18 PM »

oha,if your useless NtOpenProcess hook is bypassd,you still can say that?i have told u i only give u some tips..now u can still believe u open hook is unbreakable.haha Grin
Logged
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 2151



« Reply #13 on: November 03, 2009, 08:32:51 PM »

oha,if your useless NtOpenProcess hook is bypassd,you still can say that?i have told u i only give u some tips..now u can still believe u open hook is unbreakable.haha Grin

Oh you scared me now Smiley
Logged
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1284


^^^^


« Reply #14 on: November 03, 2009, 08:46:52 PM »

Providing a video but not the tool gives you pretty much the same credibility as a magician you see on tv able to turn water into gold.. I don't buy it, until they made me some..  Roll Eyes Grin

Anyone can crash anything in a video.. Heck I could even be the president of the united states in a video, don't believe everything you see, especially when it can't be confirmed..   Thumb Down Thumb Down

I buy this "crash" when I see a PoC..

Until then this video is just purely trolling.. Anyone believing something else probably needs his/her mind checked..
Logged
Tags:
Pages: [1] 2 3 4 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.043 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com