Welcome, Guest. Please login or register.
January 03, 2010, 07:51:58 AM

Login with username, password and session length

347043 Posts
38368 Topics
87213 Members

Latest Member: markandmerejen

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Killed cfp.exe demonstration video by mj0011
« previous next »
Pages: 1 [2] 3 4 Go Down Print
Author Topic: Killed cfp.exe demonstration video by mj0011  (Read 4429 times)
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1285


^^^^


« Reply #15 on: November 03, 2009, 09:08:48 PM »

Not that I think anyone here thinks so, but if anyone in here is thinking this video "must" be real.. Take a look at this as well:



Melih is at the white house.. And they has the CFP logo there now.. as you can see with your own eyes..

And what is this: http://www.youtube.com/watch?v=Sr4n7nnu7q8 T. REX are alive again, in a park near you!

The point is, believing someone who refuses to provide some kind of evidence is just stupid.. =) This guy could so easily provide his PoC but chose not to..  Roll Eyes Roll Eyes
Logged
3DNow
Newbie
*
Offline Offline

Posts: 18


« Reply #16 on: November 03, 2009, 09:10:00 PM »

haha you can doubt this video,and i will never give u the PoC and your useless protection are still been bypassd.for i have nothing bad.when someday u see the real attack by malware author,u will see how they turn water to glod Evil
Logged
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1285


^^^^


« Reply #17 on: November 03, 2009, 09:33:18 PM »

haha you can doubt this video,and i will never give u the PoC and your useless protection are still been bypassd.for i have nothing bad.when someday u see the real attack by malware author,u will see how they turn water to glod Evil

Why would you do that..  If you spread it to the public then then we will end up getting hold of your PoC probably sooner or later..  Kiss And if you plan on infecting a lot of users you will need to use some sort of product flaw probably as well.. And CIS is quite capable at preventing many infections that way.. and your malware can't just be aimed at killing CIS.. What are you planning? Making a huge botnet? stealing passwords?  Roll Eyes Wink And what about the users that uses other products....?? Oh and I guess you are going to make your file so badass that it survives a format (not unusuall for people to do when infected..)..

Anyhow if you are the creator of this video (I don't think you are, but well) have you tested this PoC is against something else than CIS? (to be honest I hasn't watched the video..)  Grin Anyhow, CIS is the product that passes all HIPS/firewall tests on matousec.. (unlike the others) and the product probably intercept more stuff than most suites out there.. So Iam sure you could poke a hole in some other suites as well.. Thats usually what happens when something new "pops up".. But yeah, sure its possible that you could have found a flaw.. No offense but without a PoC your just a troll..
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1703


The only thing i ask for are eggs.


WWW
« Reply #18 on: November 03, 2009, 09:38:23 PM »

Send it to me over a PM.. I will send it to Comodo, if you dont want it public.
Logged

Happy New Year and Holidays
Please follow forum policy. Thank you.
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1285


^^^^


« Reply #19 on: November 03, 2009, 09:40:36 PM »

Send it to me over a PM.. I will send it to Comodo, if you dont want it public.

The guy is going to take over the Internet with this flaw, he is the Bill gates of hackers.. Just wait, he has no intention to share it..  Roll Eyes Grin
Logged
ssj100
Comodo's Hero
*****
Offline Offline

Posts: 242



« Reply #20 on: November 04, 2009, 06:48:10 AM »

I believe there probably is a POC that can bypass CIS (perhaps more than one).  Apparently there are at least 3 POCs (from the same guy?) that can bypass Malware Defender's protection - I think the creator of Malware Defender ("Xiaolin") has been spending the last few days trying to patch these vulnerabilities:

Here, he fixes the first POC bypass:
http://www.wilderssecurity.com/showpost.php?p=1566408&postcount=27

And here, the second:
http://www.wilderssecurity.com/showpost.php?p=1566522&postcount=31

And in this post, he admits he is trying to fix the third POC bypass and has resigned to the fact that Malware Defender will need to be re-designed:
http://www.wilderssecurity.com/showpost.php?p=1568038&postcount=56

I don't know about you guys, but this sounds like pretty big stuff.  Malware Defender is arguably the best classical HIPS out there.
Logged

Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
evil_religion
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 344


« Reply #21 on: November 04, 2009, 07:08:34 AM »

haha you can doubt this video,and i will never give u the PoC and your useless protection are still been bypassd.
You only killed the cfp.exe process. What about the cmdagent.exe? And even if you killed both you still didn't bypass protection because all unknown requests are blocked.

It's just untransparent trolling what you are doing. If you don't want to appear like a criminal loser with some psychich problems you should share the POC...
Logged
dkmc
Newbie
*
Offline Offline

Posts: 14


« Reply #22 on: November 04, 2009, 12:00:36 PM »

Monkey boy, [* cut *]

It's just untransparent trolling what you are doing. If you don't want to appear like a criminal loser with some psychich problems you should share the POC...
If you do not want to appear like vulgar loudmouthed creature then....think yourself.
« Last Edit: November 06, 2009, 09:10:42 AM by dkmc » Logged

Be polite. Be professional. But, have a plan to kill everyone you meet.
[ from USMC Rules for Gunfighting ]
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1285


^^^^


« Reply #23 on: November 04, 2009, 12:48:46 PM »

[Post removed..]
« Last Edit: November 06, 2009, 02:51:30 PM by Monkey_Boy=) » Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1703


The only thing i ask for are eggs.


WWW
« Reply #24 on: November 04, 2009, 12:52:54 PM »

Monkey_Boy & dkmc stop fighting with each other please.  Police
Logged

Happy New Year and Holidays
Please follow forum policy. Thank you.
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1285


^^^^


« Reply #25 on: November 04, 2009, 01:40:02 PM »

[Post removed..]
« Last Edit: November 06, 2009, 02:51:52 PM by Monkey_Boy=) » Logged
Dennis2
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2267



« Reply #26 on: November 04, 2009, 02:05:26 PM »

Please read the Forum Policy before anyone posts in this topic again.

Thank you
Dennis

Forum Policy

§8. Unacceptable behaviours
Logged

Moderator: Aims to keep the forum a friendly place. Any concerns? Please PM me and/or review the NEW forum policy.
System: Windows 7 (UAC)x32, CIS 3.13,Sandboxie 3.40
Vista Home P. (UAC)x32 SP2, CIS 3.13, W.D.
dkmc
Newbie
*
Offline Offline

Posts: 14


« Reply #27 on: November 04, 2009, 02:27:42 PM »

If he thinks Iam wrong somewhere then I would appreciate if he explain where and about what so I know..
I doubt that your serious about that.
Anyway: Re-read thread slowly and thoroughly and pay attention to your comments. Simple as that.
Logged

Be polite. Be professional. But, have a plan to kill everyone you meet.
[ from USMC Rules for Gunfighting ]
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1285


^^^^


« Reply #28 on: November 04, 2009, 03:00:05 PM »

I doubt that your serious about that.
Anyway: Re-read thread slowly and thoroughly and pay attention to your comments. Simple as that.

Explain yourself or just cut it.. My comments are about how easy it is to fake a crash, and that this video has very little credibility, I know for a fact that I can "crash" CIS using the task manager if I tamper a bit with it..

I did watch the video now however.. Isn't it a bit "questionable" how even prior to this guy doing his attack CIS is not showing the usual "all okay" under system status..?
Logged
ssj100
Comodo's Hero
*****
Offline Offline

Posts: 242



« Reply #29 on: November 04, 2009, 03:36:02 PM »

I doubt that your serious about that.
Anyway: Re-read thread slowly and thoroughly and pay attention to your comments. Simple as that.

I don't see what the big deal is.  I'm sure there are several ways of bypassing classical HIPS, whether it be Defense+ or Malware Defender, if the malicious file is allowed to be executed on the REAL system.  This is why it's so important to implement another layer of protection - virtualisation.  I use Sandboxie myself.

Regardless, it's unlikely CIS users will ever get infected if they handle Defense+ properly.  Sure, there are theoretical bypasses, but how likely are real people going to face them in real life?
Logged

Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
Tags:
Pages: 1 [2] 3 4 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.052 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com