Welcome, Guest. Please login or register.
March 21, 2010, 09:01:57 PM

Login with username, password and session length

373569 Posts
41451 Topics
94200 Members

Latest Member: shchen22

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Leak Testing/Attacks/Vulnerability Research
| | |-+  Some tests
« previous next »
Pages: [1] 2 3 ... 5 Go Down Print
Author Topic: Some tests  (Read 14924 times)
MagisDing
Comodo Family Member
***
Offline Offline

Posts: 54


« on: April 21, 2009, 04:31:00 AM »

Here are some samples transhipped from xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx, attached in the accessory.
Stop.exe and Stop2.exe can lock the mouse;
htaaa.exe can terminate the processes(may include processes of system and HIPS), so does htbbb.exe, but the latter one cannot be run in the virutual environment. htccc.exe can terminate the explorer.exe.
So, try your HIPS

Mod edit : URL removed. Please do not post URL for sites containing objects that can do material harm to an unsuspecting users PC in the publicly accessible boards.
« Last Edit: April 21, 2009, 04:58:20 PM by panic » Logged
metalforlife
Comodo's Hero
*****
Offline Offline

Posts: 327


« Reply #1 on: April 21, 2009, 05:00:28 AM »

Does Comodo pass this test?
Logged
MagisDing
Comodo Family Member
***
Offline Offline

Posts: 54


« Reply #2 on: April 21, 2009, 08:44:11 AM »

Well, why not have a try first? Wink They don't do harm to your PC indeed Evil
Actually, Comodo faild to pass most of them Wink since V3 can't intercept some functions.
So can any developers test all of these above and discuss the possiblities of using the "flaws" by malwares to penetrated the Comodo shield Wink
« Last Edit: April 21, 2009, 09:34:27 AM by MagisDing » Logged
mjj09
Comodo Loves me
****
Offline Offline

Posts: 192


« Reply #3 on: April 21, 2009, 09:19:46 AM »

Actually, Comodo faild most of them Wink since can't intercept some functions.

Such as?

BTW, cannot download the file without registering for the site, which I'm not inclined to do.
Logged
MagisDing
Comodo Family Member
***
Offline Offline

Posts: 54


« Reply #4 on: April 21, 2009, 09:36:33 AM »

Such as?

BTW, cannot download the file without registering for the site, which I'm not inclined to do.
I've attached a compressed file in the accessory, and here is a direct download link:xxxxxxxxxxxxx

Mod edit : Link removed
« Last Edit: April 23, 2009, 06:14:50 AM by panic » Logged
metalforlife
Comodo's Hero
*****
Offline Offline

Posts: 327


« Reply #5 on: April 21, 2009, 11:21:51 AM »

There must be an abundance of such advanced malicious codes, breaching, even the heavily armoured sentries of Comodo.

Doesn't really make Comodo seem all that invincible. I believe, in general terms, rather than finding new solutions for newer problems, strengthening the base, makes a solution at all circumstances and all times.

I don't even know if what I wrote made any sense, or if any of it was at least one percent relevant to PC security.

But one thing is true, once malware writers start focusing, specifically, on circumventing HIPSs, cases as such as this will become more common.
Logged
metalforlife
Comodo's Hero
*****
Offline Offline

Posts: 327


« Reply #6 on: April 21, 2009, 11:27:37 AM »

I'll wait till I hear from the developers before reaching a conclusion.
Logged
Creasy
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 858


I'm watching you.


« Reply #7 on: April 21, 2009, 04:00:46 PM »

Do not visit that website.
It's from china.

The site is one of websites which has tons of security holes (eg,SQL Injection).
It was an issue that some of webpages of that site put malwares to connected PCs automatically.

Also some of pages can make people infected and attacked by XSS attack.

One of moderator should delete the link.

« Last Edit: April 21, 2009, 04:13:55 PM by Creasy » Logged

Wrong messages are dangerous, but wrong interpretation of correct messages is even more dangerous.-Andre Kostolany-
I'm a MAN!!
I'm not a girl!
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1401


^^^^


« Reply #8 on: April 21, 2009, 05:31:37 PM »

Someone willing to run the termination test? comodo110 Comodo Needs You
Logged
burebista
Comodo Loves me
****
Offline Offline

Posts: 199



« Reply #9 on: April 22, 2009, 12:42:39 AM »

Yep, stop2.exe kill my mouse (not able to click anymore) and htccc.exe kills explorer.
D+ in safe mode, everything checked in Monitor settings.
Logged

If it ain't broke... fix it until it is.
ssj100
Comodo's Hero
*****
Offline Offline

Posts: 284



« Reply #10 on: April 22, 2009, 02:51:27 AM »

Easy, use Sandboxie and configure it appropriately to run your web browser sandboxed with reduced rights etc.  I use CIS 3.9 beta and Sandboxie.  CIS alone is not really enough.  On the other hand, Sandboxie alone and configured properly is arguably enough.
« Last Edit: April 22, 2009, 02:53:53 AM by ssj100 » Logged

Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
MagisDing
Comodo Family Member
***
Offline Offline

Posts: 54


« Reply #11 on: April 22, 2009, 03:49:31 AM »

Easy, use Sandboxie and configure it appropriately to run your web browser sandboxed with reduced rights etc.  I use CIS 3.9 beta and Sandboxie.  CIS alone is not really enough.  On the other hand, Sandboxie alone and configured properly is arguably enough.
Have you ever tried these programmes with Sbie?
Logged
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1401


^^^^


« Reply #12 on: April 22, 2009, 06:10:37 AM »

Easy, use Sandboxie and configure it appropriately to run your web browser sandboxed with reduced rights etc.  I use CIS 3.9 beta and Sandboxie.  CIS alone is not really enough.  On the other hand, Sandboxie alone and configured properly is arguably enough.

Nice combo.. To me however CIS is enough. Also can sandboxie protect you from keylogging? can sandboxie prevent malware dialing home and sending your info somewhere? If no then sandboxie is not enough..

Sandboxie has a history of letting stuff escape from time to time as well. I wouldn't pick sandboxie over CIS..
Especially not if your definition of properly configured means "run your web browser sandboxed".

Thats not a "total" protection but could serve as a compliment. As it would guard one thing, the web browser.. And the stuff it might "install".

However all your other applications (whatever those might be), would still connect home with no checking and with no firewall there to guard them (your system is still there running in the back, its not just a browser).. + you would lack info on the stuff thats already on your computer and what they are doing sandboxie would never detect any baddie you already got.. Something that CIS actually does. =)
Logged
ssj100
Comodo's Hero
*****
Offline Offline

Posts: 284



« Reply #13 on: April 22, 2009, 06:15:04 AM »

Mate, I don't think you understand the power of Sandboxie.  Yes, it does protect against keyloggers etc.  When my browser is opened, I have restricted file run access and also file internet access.  Also I have dropped the rights of the programs running in that sandbox.  Easy.

Sure, but I do agree that Sandboxie can only protect certain programs at a time.  That's why I use CIS!  CIS is great!
« Last Edit: April 22, 2009, 06:55:20 AM by ssj100 » Logged

Sandboxie + LUA + KAfU + SRP + DEP + SuRun
Windows Firewall + NAT Router
Avira AntiVir Personal (on-demand)
VirtualBox (on-demand)
Breen
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 324



« Reply #14 on: April 22, 2009, 11:54:22 AM »

I've checked those files, and D+ was penetrated! I hope devs will check this up.
Logged

100% organic software
Tags:
Pages: [1] 2 3 ... 5 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.058 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com