Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
January 03, 2010, 07:51:58 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
347043
Posts
38368
Topics
87213
Members
Latest Member:
markandmerejen
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Leak Testing/Attacks/Vulnerability Research
Killed cfp.exe demonstration video by mj0011
« previous
next »
Pages:
1
[
2
]
3
4
Author
Topic: Killed cfp.exe demonstration video by mj0011 (Read 4429 times)
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1285
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #15 on:
November 03, 2009, 09:08:48 PM »
Not that I think anyone here thinks so, but if anyone in here is thinking this video "must" be real.. Take a look at this as well:
Melih is at the white house.. And they has the CFP logo there now.. as you can see with your own eyes..
And what is this:
http://www.youtube.com/watch?v=Sr4n7nnu7q8
T. REX are alive again, in a park near you!
The point is, believing someone who refuses to provide some kind of evidence is just stupid.. =) This guy could so easily provide his PoC but chose not to..
Logged
3DNow
Newbie
Offline
Posts: 18
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #16 on:
November 03, 2009, 09:10:00 PM »
haha you can doubt this video,and i will never give u the PoC and your useless protection are still been bypassd.for i have nothing bad.when someday u see the real attack by malware author,u will see how they turn water to glod
Logged
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1285
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #17 on:
November 03, 2009, 09:33:18 PM »
Quote from: 3DNow on November 03, 2009, 09:10:00 PM
haha you can doubt this video,and i will never give u the PoC and your useless protection are still been bypassd.for i have nothing bad.when someday u see the real attack by malware author,u will see how they turn water to glod
Why would you do that.. If you spread it to the public then then we will end up getting hold of your PoC probably sooner or later..
And if you plan on infecting a lot of users you will need to use some sort of product flaw probably as well.. And CIS is quite capable at preventing many infections that way.. and your malware can't just be aimed at killing CIS.. What are you planning? Making a huge botnet? stealing passwords?
And what about the users that uses other products....?? Oh and I guess you are going to make your file so badass that it survives a format (not unusuall for people to do when infected..)..
Anyhow if you are the creator of this video (I don't think you are, but well) have you tested this PoC is against something else than CIS? (to be honest I hasn't watched the video..)
Anyhow, CIS is the product that passes all HIPS/firewall tests on matousec.. (unlike the others) and the product probably intercept more stuff than most suites out there.. So Iam sure you could poke a hole in some other suites as well.. Thats usually what happens when something new "pops up".. But yeah, sure its possible that you could have found a flaw.. No offense but without a PoC your just a troll..
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 1703
The only thing i ask for are eggs.
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #18 on:
November 03, 2009, 09:38:23 PM »
Send it to me over a PM.. I will send it to Comodo, if you dont want it public.
Logged
Happy New Year and Holidays
Please follow forum policy. Thank you.
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1285
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #19 on:
November 03, 2009, 09:40:36 PM »
Quote from: OmeletGuy on November 03, 2009, 09:38:23 PM
Send it to me over a PM.. I will send it to Comodo, if you dont want it public.
The guy is going to take over the Internet with this flaw, he is the Bill gates of hackers.. Just wait, he has no intention to share it..
Logged
ssj100
Comodo's Hero
Offline
Posts: 242
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #20 on:
November 04, 2009, 06:48:10 AM »
I believe there probably is a POC that can bypass CIS (perhaps more than one). Apparently there are at least 3 POCs (from the same guy?) that can bypass Malware Defender's protection - I think the creator of Malware Defender ("Xiaolin") has been spending the last few days trying to patch these vulnerabilities:
Here, he fixes the first POC bypass:
http://www.wilderssecurity.com/showpost.php?p=1566408&postcount=27
And here, the second:
http://www.wilderssecurity.com/showpost.php?p=1566522&postcount=31
And in this post, he admits he is trying to fix the third POC bypass and has resigned to the fact that Malware Defender will need to be re-designed:
http://www.wilderssecurity.com/showpost.php?p=1568038&postcount=56
I don't know about you guys, but this sounds like pretty big stuff. Malware Defender is arguably the best classical HIPS out there.
Logged
Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 344
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #21 on:
November 04, 2009, 07:08:34 AM »
Quote from: 3DNow on November 03, 2009, 09:10:00 PM
haha you can doubt this video,and i will never give u the PoC and your useless protection are still been bypassd.
You only killed the cfp.exe process. What about the cmdagent.exe? And even if you killed both you still didn't bypass protection because all unknown requests are blocked.
It's just untransparent trolling what you are doing. If you don't want to appear like a criminal loser with some psychich problems you should share the POC...
Logged
dkmc
Newbie
Offline
Posts: 14
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #22 on:
November 04, 2009, 12:00:36 PM »
Monkey boy, [* cut *]
Quote from: evil_religion on November 04, 2009, 07:08:34 AM
It's just untransparent trolling what you are doing. If you don't want to appear like a criminal loser with some psychich problems you should share the POC...
If you do not want to appear like vulgar loudmouthed creature then....think yourself.
«
Last Edit: November 06, 2009, 09:10:42 AM by dkmc
»
Logged
Be polite. Be professional. But, have a plan to kill everyone you meet.
[
from
USMC Rules for Gunfighting ]
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1285
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #23 on:
November 04, 2009, 12:48:46 PM »
[Post removed..]
«
Last Edit: November 06, 2009, 02:51:30 PM by Monkey_Boy=)
»
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 1703
The only thing i ask for are eggs.
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #24 on:
November 04, 2009, 12:52:54 PM »
Monkey_Boy & dkmc stop fighting with each other please.
Logged
Happy New Year and Holidays
Please follow forum policy. Thank you.
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1285
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #25 on:
November 04, 2009, 01:40:02 PM »
[Post removed..]
«
Last Edit: November 06, 2009, 02:51:52 PM by Monkey_Boy=)
»
Logged
Dennis2
Global Moderator
Comodo's Hero
Offline
Posts: 2267
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #26 on:
November 04, 2009, 02:05:26 PM »
Please read the
Forum Policy
before anyone posts in this topic again.
Thank you
Dennis
Forum Policy
§8. Unacceptable behaviours
Logged
Moderator:
Aims to keep the forum a friendly place. Any concerns? Please PM me and/or review the
NEW forum policy
.
System:
Windows 7 (UAC)x32, CIS 3.13,Sandboxie 3.40
Vista Home P. (UAC)x32 SP2, CIS 3.13, W.D.
dkmc
Newbie
Offline
Posts: 14
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #27 on:
November 04, 2009, 02:27:42 PM »
Quote from: Monkey_Boy=) on November 04, 2009, 01:40:02 PM
If he thinks Iam wrong somewhere then I would appreciate if he explain where and about what so I know..
I doubt that your serious about that.
Anyway: Re-read thread slowly and thoroughly and pay attention to your comments. Simple as that.
Logged
Be polite. Be professional. But, have a plan to kill everyone you meet.
[
from
USMC Rules for Gunfighting ]
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1285
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #28 on:
November 04, 2009, 03:00:05 PM »
Quote from: dkmc on November 04, 2009, 02:27:42 PM
I doubt that your serious about that.
Anyway: Re-read thread slowly and thoroughly and pay attention to your comments. Simple as that.
Explain yourself or just cut it.. My comments are about how easy it is to fake a crash, and that this video has very little credibility, I know for a fact that I can "crash" CIS using the task manager if I tamper a bit with it..
I did watch the video now however.. Isn't it a bit "questionable" how even prior to this guy doing his attack CIS is not showing the usual "all okay" under system status..?
Logged
ssj100
Comodo's Hero
Offline
Posts: 242
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #29 on:
November 04, 2009, 03:36:02 PM »
Quote from: dkmc on November 04, 2009, 02:27:42 PM
I doubt that your serious about that.
Anyway: Re-read thread slowly and thoroughly and pay attention to your comments. Simple as that.
I don't see what the big deal is. I'm sure there are several ways of bypassing classical HIPS, whether it be Defense+ or Malware Defender, if the malicious file is allowed to be executed on the REAL system. This is why it's so important to implement another layer of protection - virtualisation. I use Sandboxie myself.
Regardless, it's unlikely CIS users will ever get infected if they handle Defense+ properly. Sure, there are theoretical bypasses, but how likely are real people going to face them in real life?
Logged
Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
Tags:
Pages:
1
[
2
]
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.052 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com