Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 21, 2010, 11:53:14 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373453
Posts
41427
Topics
94164
Members
Latest Member:
luchtbedcommando
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Leak Testing/Attacks/Vulnerability Research
Some tests
« previous
next »
Pages:
[
1
]
2
3
...
5
Author
Topic: Some tests (Read 14919 times)
MagisDing
Comodo Family Member
Offline
Posts: 54
Some tests
«
on:
April 21, 2009, 04:31:00 AM »
Here are some samples transhipped from
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
, attached in the accessory.
Stop.exe and Stop2.exe can lock the mouse;
htaaa.exe can terminate the processes(may include processes of system and HIPS), so does htbbb.exe, but the latter one cannot be run in the virutual environment. htccc.exe can terminate the explorer.exe.
So, try your HIPS
Mod edit : URL removed. Please do not post URL for sites containing objects that can do material harm to an unsuspecting users PC in the publicly accessible boards.
«
Last Edit: April 21, 2009, 04:58:20 PM by panic
»
Logged
metalforlife
Comodo's Hero
Online
Posts: 327
Re: Some tests
«
Reply #1 on:
April 21, 2009, 05:00:28 AM »
Does Comodo pass this test?
Logged
MagisDing
Comodo Family Member
Offline
Posts: 54
Re: Some tests
«
Reply #2 on:
April 21, 2009, 08:44:11 AM »
Well, why not have a try first?
They don't do harm to your PC indeed
Actually, Comodo faild to pass most of them
since V3 can't intercept some functions.
So can any developers test all of these above and discuss the possiblities of using the "flaws" by malwares to penetrated the Comodo shield
«
Last Edit: April 21, 2009, 09:34:27 AM by MagisDing
»
Logged
mjj09
Comodo Loves me
Offline
Posts: 192
Re: Some tests
«
Reply #3 on:
April 21, 2009, 09:19:46 AM »
Quote from: MagisDing on April 21, 2009, 08:44:11 AM
Actually, Comodo faild most of them
since can't intercept some functions.
Such as?
BTW, cannot download the file without registering for the site, which I'm not inclined to do.
Logged
MagisDing
Comodo Family Member
Offline
Posts: 54
Re: Some tests
«
Reply #4 on:
April 21, 2009, 09:36:33 AM »
Quote from: mjj09 on April 21, 2009, 09:19:46 AM
Such as?
BTW, cannot download the file without registering for the site, which I'm not inclined to do.
I've attached a compressed file in the accessory, and here is a direct download link:xxxxxxxxxxxxx
Mod edit : Link removed
«
Last Edit: April 23, 2009, 06:14:50 AM by panic
»
Logged
metalforlife
Comodo's Hero
Online
Posts: 327
Re: Some tests
«
Reply #5 on:
April 21, 2009, 11:21:51 AM »
There must be an abundance of such advanced malicious codes, breaching, even the heavily armoured sentries of Comodo.
Doesn't really make Comodo seem all that invincible. I believe, in general terms, rather than finding new solutions for newer problems, strengthening the base, makes a solution at all circumstances and all times.
I don't even know if what I wrote made any sense, or if any of it was at least one percent relevant to PC security.
But one thing is true, once malware writers start focusing, specifically, on circumventing HIPSs, cases as such as this will become more common.
Logged
metalforlife
Comodo's Hero
Online
Posts: 327
Re: Some tests
«
Reply #6 on:
April 21, 2009, 11:27:37 AM »
I'll wait till I hear from the developers before reaching a conclusion.
Logged
Creasy
Product Translator
Comodo's Hero
Offline
Posts: 858
I'm watching you.
Re: Some tests
«
Reply #7 on:
April 21, 2009, 04:00:46 PM »
Do not visit that website.
It's from china.
The site is one of websites which has tons of security holes (eg,
SQL Injection
).
It was an issue that some of webpages of that site put malwares to connected PCs automatically.
Also some of pages can make people infected and attacked by
XSS attack
.
One of moderator should delete the link.
«
Last Edit: April 21, 2009, 04:13:55 PM by Creasy
»
Logged
Wrong messages are dangerous, but wrong interpretation of correct messages is even more dangerous.
-Andre Kostolany-
I'm a MAN!!
I'm not a girl!
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: Some tests
«
Reply #8 on:
April 21, 2009, 05:31:37 PM »
Someone willing to run the termination test?
Logged
burebista
Comodo Loves me
Offline
Posts: 199
Re: Some tests
«
Reply #9 on:
April 22, 2009, 12:42:39 AM »
Yep, stop2.exe kill my mouse (not able to click anymore) and htccc.exe kills explorer.
D+ in safe mode, everything checked in Monitor settings.
Logged
If it ain't broke... fix it until it is.
ssj100
Comodo's Hero
Offline
Posts: 284
Re: Some tests
«
Reply #10 on:
April 22, 2009, 02:51:27 AM »
Easy, use Sandboxie and configure it appropriately to run your web browser sandboxed with reduced rights etc. I use CIS 3.9 beta and Sandboxie. CIS alone is not really enough. On the other hand, Sandboxie alone and configured properly is arguably enough.
«
Last Edit: April 22, 2009, 02:53:53 AM by ssj100
»
Logged
Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
MagisDing
Comodo Family Member
Offline
Posts: 54
Re: Some tests
«
Reply #11 on:
April 22, 2009, 03:49:31 AM »
Quote from: ssj100 on April 22, 2009, 02:51:27 AM
Easy, use Sandboxie and configure it appropriately to run your web browser sandboxed with reduced rights etc. I use CIS 3.9 beta and Sandboxie. CIS alone is not really enough. On the other hand, Sandboxie alone and configured properly is arguably enough.
Have you ever tried these programmes with Sbie?
Logged
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: Some tests
«
Reply #12 on:
April 22, 2009, 06:10:37 AM »
Quote from: ssj100 on April 22, 2009, 02:51:27 AM
Easy, use Sandboxie and configure it appropriately to run your web browser sandboxed with reduced rights etc. I use CIS 3.9 beta and Sandboxie. CIS alone is not really enough. On the other hand, Sandboxie alone and configured properly is arguably enough.
Nice combo.. To me however CIS is enough. Also can sandboxie protect you from keylogging? can sandboxie prevent malware dialing home and sending your info somewhere? If no then sandboxie is not enough..
Sandboxie has a history of letting stuff escape from time to time as well. I wouldn't pick sandboxie over CIS..
Especially not if your definition of properly configured means "run your web browser sandboxed".
Thats not a "total" protection but could serve as a compliment. As it would guard one thing, the web browser.. And the stuff it might "install".
However all your other applications (whatever those might be), would still connect home with no checking and with no firewall there to guard them (your system is still there running in the back, its not just a browser).. + you would lack info on the stuff thats already on your computer and what they are doing sandboxie would never detect any baddie you already got.. Something that CIS actually does. =)
Logged
ssj100
Comodo's Hero
Offline
Posts: 284
Re: Some tests
«
Reply #13 on:
April 22, 2009, 06:15:04 AM »
Mate, I don't think you understand the power of Sandboxie. Yes, it does protect against keyloggers etc. When my browser is opened, I have restricted file run access and also file internet access. Also I have dropped the rights of the programs running in that sandbox. Easy.
Sure, but I do agree that Sandboxie can only protect certain programs at a time. That's why I use CIS! CIS is great!
«
Last Edit: April 22, 2009, 06:55:20 AM by ssj100
»
Logged
Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
Breen
Product Translator
Comodo's Hero
Offline
Posts: 324
Re: Some tests
«
Reply #14 on:
April 22, 2009, 11:54:22 AM »
I've checked those files, and D+ was penetrated! I hope devs will check this up.
Logged
100% organic software
Tags:
Pages:
[
1
]
2
3
...
5
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.078 seconds with 16 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com