Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
January 02, 2010, 06:01:29 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
346767
Posts
38333
Topics
87085
Members
Latest Member:
silkybar
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Leak Testing/Attacks/Vulnerability Research
Killed cfp.exe demonstration video by mj0011
« previous
next »
Pages:
1
2
[
3
]
4
Author
Topic: Killed cfp.exe demonstration video by mj0011 (Read 4372 times)
dkmc
Newbie
Online
Posts: 14
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #30 on:
November 04, 2009, 03:59:17 PM »
Quote from: Monkey_Boy=) on November 04, 2009, 03:00:05 PM
Explain yourself or just cut it.. My comments are about how easy it is to fake a crash, and that this video has very little credibility, I know for a fact that I can "crash" CIS using the task manager if I tamper a bit with it..
In tWo words. You do not know this video and code are fakes. That's for sure.
But despite of this:
* you called some people "trolls" for the fact they didn't want to pass code (supposing they have working code). They may have reasons for this.
* You started to hijack this thread using fraudulent approach to distort case - idiocy about magicians, gold, water, Melih in white house etc.
That's why i said what i said.
Quote from: Monkey_Boy=) on November 04, 2009, 03:00:05 PM
I did watch the video now however.. Isn't it a bit "questionable" how even prior to this guy doing his attack CIS is not showing the usual "all okay" under system status..?
Maybe because:
Quote from: 3DNow on November 03, 2009, 05:36:29 AM
before test cfp.exe , he was kill cmdagent.exe with killcis.exe the first.
Logged
Be polite. Be professional. But, have a plan to kill everyone you meet.
[
from
USMC Rules for Gunfighting ]
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 341
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #31 on:
November 04, 2009, 04:26:55 PM »
Quote from: dkmc on November 04, 2009, 12:00:36 PM
If you do not want to appear like vulgar loudmouthed creature then....think yourself.
Why do you answer with personal offense only? Didn't I give some arguments?
I will repeat them here in case you didn't get them:
Quote
And even if you killed both you still didn't bypass protection because all unknown requests are blocked.
So Comodo hasn't been "bypassed". Make some malware which kills CIS and send it me, I would be pleased to run it.
And BTW: What are the reasons not to share such code which only's purpose seem to be to perform criminal actions?
And BTW2: You should learn more English, some sentences of you two Chinese hacker boys are only hardly to understand.
«
Last Edit: November 04, 2009, 04:29:08 PM by evil_religion
»
Logged
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1285
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #32 on:
November 04, 2009, 04:30:12 PM »
Quote from: dkmc on November 04, 2009, 03:59:17 PM
In tWo words. You do not know this video and code are fakes. That's for sure.
Yes you are 100% correct I don't know if the video is fake or not.. If you got that impression well that was not my intention Ill try to explain myself:
Quote from: Monkey_Boy=) on November 03, 2009, 08:46:52 PM
I buy this "crash" when I see a PoC..
(I pretty much said that I don't rule out that this may be real)
Quote from: Monkey_Boy=) on November 03, 2009, 09:33:18 PM
sure its possible that you could have found a flaw..
Pretty much again one of my comments said that its possible this is real..
My posts was mostly directed at pointing out that this video can't be trusted. But as you say, its possible that it is real as well.. But I guess we are never going to find out since there are no evidence pointing either way..
Logged
dkmc
Newbie
Online
Posts: 14
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #33 on:
November 05, 2009, 02:31:36 AM »
[at] evil_religion
Let's make things clear. You left no choice for 3dnow if he refuses to share code (supposing he has one): "criminal loser with psychic problems". After that it is at least strange you talk about personal offenses... And by the way, Your arguments are perfect.
Quote
What are the reasons not to share such code which only's purpose seem to be to perform criminal actions?
Haven't you seen answer followed by official Comodo representative? Sense of answer (if we translate diplomatic message into normal words): this code is a crap, but alright, we would make you a favor and look at it.
[at] Monkey_Boy=)
Excuse me for that word. Those flood with magicians, alchemists, white house etc drove me nuts. Maybe it is better to stay silent instead of flooding next time.
Logged
Be polite. Be professional. But, have a plan to kill everyone you meet.
[
from
USMC Rules for Gunfighting ]
ssj100
Comodo's Hero
Online
Posts: 241
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #34 on:
November 05, 2009, 03:38:22 AM »
Quote from: dkmc on November 05, 2009, 02:31:36 AM
[at] evil_religion
Let's make things clear. You left no choice for 3dnow if he refuses to share code (supposing he has one): "criminal loser with psychic problems". After that it is at least strange you talk about personal offenses... And by the way, Your arguments are perfect.
Haven't you seen answer followed by official Comodo representative? Sense of answer (if we translate diplomatic message into normal words): this code is a crap, but alright, we would make you a favor and look at it.
[at] Monkey_Boy=)
Excuse me for that word. Those flood with magicians, alchemists, white house etc drove me nuts. Maybe it is better to stay silent instead of flooding next time.
Are you being a bit negative on the Comodo forums because Comodo are providing a very good classical HIPS for absolutely free, and Xiaolin isn't?
To be honest, I really don't know of any other classical HIPS that is completely free and as strong as Defense+. Pity I've moved on from classical HIPS and found a setup that is much stronger and without all the computer "house-work".
Logged
Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1285
^^^^
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #35 on:
November 05, 2009, 04:04:29 AM »
Quote from: dkmc on November 05, 2009, 02:31:36 AM
[at] Monkey_Boy=)
Excuse me for that word. Those flood with magicians, alchemists, white house etc drove me nuts. Maybe it is better to stay silent instead of flooding next time.
No problems! Ofc if you disagree with something feel free to speak up. Its possible my text was misleading to some extent. So I guess thanks to your post its now more clear what I was trying to say.
Logged
dkmc
Newbie
Online
Posts: 14
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #36 on:
November 05, 2009, 11:13:54 AM »
[at] ssj100
Keep this kind of questions to someone else, doc.
But anyway, i would say normally this time.
I'm not Chinese, nor i am political martyr who is against Comodo. I do not defend position of 3dnow, i don't care about this "bypass" and code (because defense plus driver was not unloaded, but that's mine imo and irrelevant). Seriously.
I simply argued with 2 men here.
Logged
Be polite. Be professional. But, have a plan to kill everyone you meet.
[
from
USMC Rules for Gunfighting ]
ailef
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 703
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #37 on:
November 14, 2009, 08:08:34 PM »
i start from the idea that the video is true.
wich OS is used ? is it 32bit OS or 64bit OS ?
does this exploit work on win7 64bit ?
Logged
xps M1330[at]T9500 - Windows 7 ultimate 64bit - comodo 3.13 build 574 - KAV 2010 build 736
3DNow
Newbie
Offline
Posts: 18
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #38 on:
November 15, 2009, 01:12:06 PM »
i test it on XP SP2 (x86),but it can also kill cfp under win7 x64.
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
Offline
Posts: 1704
The only thing i ask for are eggs.
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #39 on:
November 15, 2009, 01:31:43 PM »
Can you please PM me a link, i will have it look at.
Thanks.
Logged
Happy New Year and Holidays
Please follow forum policy. Thank you.
wj32
Comodo Loves me
Offline
Posts: 123
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #40 on:
November 17, 2009, 05:37:30 AM »
Quote from: 3DNow on November 15, 2009, 01:12:06 PM
i test it on XP SP2 (x86),but it can also kill cfp under win7 x64.
Sorry if this is a redundant post (I haven't read the earlier posts), but would you care to elaborate on how this is done?
Logged
blueshadowlaser
Newbie
Offline
Posts: 4
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #41 on:
November 29, 2009, 08:23:44 AM »
Mj is a stuff in a security guard software of china named "360 guard". He is a bit arrogant by his technology.
He said the "KILLCIS" is not only can terminate the cis process, but also can Inject the CIS process.
The method is a secret but I heard about add a "driver". So it is probably not worked at X64 system.
We need more safety software. For example, CIS is intercept the namepipe like "\Device\NamedPipe\lsass" at before, but now is could not intercept this. A Malware can delete all user by "\Device\NamedPipe\lsass" and CIS could do anything.
Logged
3DNow
Newbie
Offline
Posts: 18
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #42 on:
November 29, 2009, 11:29:01 AM »
Quote from: blueshadowlaser on November 29, 2009, 08:23:44 AM
Mj is a stuff in a security guard software of china named "360 guard". He is a bit arrogant by his technology.
He said the "KILLCIS" is not only can terminate the cis process, but also can Inject the CIS process.
The method is a secret but I heard about add a "driver". So it is probably not worked at X64 system.
We need more safety software. For example, CIS is intercept the namepipe like "\Device\NamedPipe\lsass" at before, but now is could not intercept this. A Malware can delete all user by "\Device\NamedPipe\lsass" and CIS could do anything.
not add a "driver" , i said this demo only implement its function under ring3,and it can work under x64/x86.
Logged
3DNow
Newbie
Offline
Posts: 18
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #43 on:
November 29, 2009, 11:30:39 AM »
i see the new version of CIS is coming out , i will test it using my old "killcis.exe" if i am free
Logged
3DNow
Newbie
Offline
Posts: 18
Re: Killed cfp.exe demonstration video by mj0011
«
Reply #44 on:
December 01, 2009, 04:00:34 AM »
i has been tested the newest version(3.13.121240.574) , unfortunately , our lovely killcis.exe still can terminate and inject cfp.exe.
Logged
Tags:
Pages:
1
2
[
3
]
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.052 seconds with 17 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com