Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 21, 2010, 04:36:21 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373381
Posts
41416
Topics
94144
Members
Latest Member:
wyvernshill
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Leak Testing/Attacks/Vulnerability Research
Killed cfp.exe demonstration video by mj0011
« previous
next »
Pages:
[
1
]
2
3
4
Author
Topic: Killed cfp.exe demonstration video by mj0011 (Read 7213 times)
sirio
Global Moderator
Comodo's Hero
Offline
Posts: 1377
Killed cfp.exe demonstration video by mj0011
«
on:
November 02, 2009, 06:00:08 AM »
http://www.wilderssecurity.com/showthread.php?p=1567985#post1567985
Video download:
http://e.ys168.com/note/fd.htm?http://ys-G.ys168.com/?killcis.rar_50chkk8e1dks7bkks0c0bthsjtlrlllh5bikslm1biu14z97f14z
click on left button and download killcis.rar
Logged
Come postare un messaggio
-
Forum Policy
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3370
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #1 on:
November 02, 2009, 06:12:20 AM »
Already posted here earlier.
http://forums.comodo.com/empty-t47132.0.html;topicseen
Logged
Windows XP
E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM. 500gb. HDD
Ubuntu
P4 [at] 3ghz, Radeon x300 128mb
1gb DDR2 Ram 80GB HDD
sirio
Global Moderator
Comodo's Hero
Offline
Posts: 1377
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #2 on:
November 02, 2009, 06:27:33 AM »
Sorry, I had not attentively looked.
Thanks Kyle
Logged
Come postare un messaggio
-
Forum Policy
SS26
Comodo's Hero
Offline
Posts: 1666
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #3 on:
November 02, 2009, 04:37:38 PM »
Quote from: sirio on November 02, 2009, 06:00:08 AM
Video download:
http://e.ys168.com/note/fd.htm?http://ys-G.ys168.com/?killcis.rar_50chkk8e1dks7bkks0c0bthsjtlrlllh5bikslm1biu14z97f14z
click on left button and download killcis.rar
Drops an error on screen. Not downloading.....
Logged
sirio
Global Moderator
Comodo's Hero
Offline
Posts: 1377
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #4 on:
November 03, 2009, 04:48:58 AM »
Have you tried to download it with Internet Explorer?
In the case you still had problems, I attach the file.
There are some things that make me be sceptic. For example, why CIS is not correctly (attached screen) initialized while him is performing the test?
«
Last Edit: November 03, 2009, 07:33:21 PM by sirio
»
Logged
Come postare un messaggio
-
Forum Policy
3DNow
Newbie
Offline
Posts: 18
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #5 on:
November 03, 2009, 05:36:29 AM »
because before test cfp.exe , he was kill cmdagent.exe with killcis.exe the first.
However, process protection is still at work
Logged
sirio
Global Moderator
Comodo's Hero
Offline
Posts: 1377
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #6 on:
November 03, 2009, 07:18:33 AM »
Quote from: 3DNow on November 03, 2009, 05:36:29 AM
because before test cfp.exe , he was kill cmdagent.exe with killcis.exe the first.
Ok, why he doesn't make it see?
Quote
However, process protection is still at work
I imagined...
Have you the PoC?
Logged
Come postare un messaggio
-
Forum Policy
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 372
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #7 on:
November 03, 2009, 09:31:35 AM »
If you have acccess to the POC it would be nice if you could share it here.
Logged
3DNow
Newbie
Offline
Posts: 18
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #8 on:
November 03, 2009, 12:37:28 PM »
I'll give you some tips:
(1). in the video , the cfp.exe process is not quickly terminated , so this may be a force attack and depending on some mechanism inside the process
(2).CIS's driver donot hook the function :NtFreeVirtualMemory , which can be use to free all the memory in any process.
Logged
sirio
Global Moderator
Comodo's Hero
Offline
Posts: 1377
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #9 on:
November 03, 2009, 02:12:53 PM »
Thank you for the tips
3DNow
,
I'm a person simple, ignorant.. and then I am as San Thomas: if I don't see I don't believe
I would like to try in my pc.
My doubt remains: why he doesn't show us in the video when cmdagent comes killed?
Regards.
«
Last Edit: November 03, 2009, 02:14:27 PM by sirio
»
Logged
Come postare un messaggio
-
Forum Policy
SS26
Comodo's Hero
Offline
Posts: 1666
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #10 on:
November 03, 2009, 03:41:34 PM »
Quote from: sirio on November 03, 2009, 04:48:58 AM
Have you tried to download it with Internet Explorer?
Nope.
Quote from: sirio on November 03, 2009, 04:48:58 AM
I attach the file.
Thanks
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2191
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #11 on:
November 03, 2009, 03:48:48 PM »
Quote from: 3DNow on November 03, 2009, 12:37:28 PM
I'll give you some tips:
(1). in the video , the cfp.exe process is not quickly terminated , so this may be a force attack and depending on some mechanism inside the process
(2).CIS's driver donot hook the function :NtFreeVirtualMemory , which can be use to free all the memory in any process.
You dont need to hook NtFreeVirtualMemory because you have to obtain PROCESS_VM_OPERATION access right to COMODO processes first and this is intercepted by CIS.
Obviously one doesnt produce videos for getting the credit. He will have to do something real.
When we see the PoC, we will see what this is about
Poking our products for holes is always a good thing.
«
Last Edit: November 03, 2009, 03:56:06 PM by egemen
»
Logged
3DNow
Newbie
Offline
Posts: 18
Re: Killed cfp.exe demonstration video by mj0011h
«
Reply #12 on:
November 03, 2009, 08:12:18 PM »
oha,if your useless NtOpenProcess hook is bypassd,you still can say that?i have told u i only give u some tips..now u can still believe u open hook is unbreakable.haha
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 2191
Re: Killed cfp.exe demonstration video by mj0011h
«
Reply #13 on:
November 03, 2009, 08:32:51 PM »
Quote from: 3DNow on November 03, 2009, 08:12:18 PM
oha,if your useless NtOpenProcess hook is bypassd,you still can say that?i have told u i only give u some tips..now u can still believe u open hook is unbreakable.haha
Oh you scared me now
Logged
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #14 on:
November 03, 2009, 08:46:52 PM »
Providing a video but not the tool gives you pretty much the same credibility as a magician you see on tv able to turn water into gold.. I don't buy it, until they made me some..
Anyone can crash anything in a video.. Heck I could even be the president of the united states in a video, don't believe everything you see, especially when it can't be confirmed..
I buy this "crash" when I see a PoC..
Until then this video is just purely trolling.. Anyone believing something else probably needs his/her mind checked..
Logged
Tags:
Pages:
[
1
]
2
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.064 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com