Welcome, Guest. Please login or register.
December 09, 2009, 10:50:37 AM

Login with username, password and session length

341195 Posts
37725 Topics
85625 Members

Latest Member: Thornet

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  Virus is partially bypasing Defence Plus
« previous next »
Pages: [1] Go Down Print
Author Topic: Virus is partially bypasing Defence Plus  (Read 904 times)
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« on: November 07, 2009, 07:05:29 PM »

Original thread is here.

http://www.wilderssecurity.com/showthread.php?p=1571584#post1571584

I allowed the virus( vbs script) to execute and then denied all actions by scripting host with all custom rules and paranoid settings, all filters/ monitors of Defence Plus enabled.

CFP doesn,t monitor about putting hidden attributes to files and folders and malware is able to hide ALL  folders in C drive including windows directory and program files folder.

Hope they can add this feature.
Logged
HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1471


« Reply #1 on: November 07, 2009, 07:39:55 PM »

I allowed the virus( vbs script) to execute and then denied all actions by scripting host with all custom rules and paranoid settings, all filters/ monitors of Defence Plus enabled.

Not sure how you feel it's partially bypassing anything when you allowed it to run...
Logged

wj32
Comodo Loves me
****
Offline Offline

Posts: 122



WWW
« Reply #2 on: November 07, 2009, 10:37:42 PM »

CFP doesn,t monitor about putting hidden attributes to files and folders and malware is able to hide ALL  folders in C drive including windows directory and program files folder.

Setting the hidden attribute doesn't really do anything... It's just a hint to programs to hide the file. But yes, monitoring it would be useful.
Logged
ssj100
Comodo's Hero
*****
Offline Offline

Posts: 208


« Reply #3 on: November 07, 2009, 11:53:41 PM »

Not sure how you feel it's partially bypassing anything when you allowed it to run...

That's exactly right, and more people need to understand the importance of that statement.

Remember how most people thought Malware Defender (MD) was bullet-proof?  Well, 3 POCs were released recently that has caused Xiaolin to think about re-desgining MD!

If you let something unknown/untrusted run on your REAL system, there are many ways for malware to pounce.  The only way to be truly "100%" is to deny execution at the gate.  This is one big reason why I no longer use Classical HIPS in the everyday usage of my computer - there's just no need.  A simple anti-executable program is the way to go, and there really isn't anything stronger (or cheaper or lighter) than (LUA) + SRP.  Combine this with Sandboxie blocking/containing all your malware "threat-gates" and you have the strongest, lightest, (cheapest), and "set and forget" setup ever!

However, aigle does have a point here I think.  Defense+ could probably be improved on to control the behaviour of files better (for whatever reason).  I was just making the point of how to truly be "100%" haha.  Cheers.
Logged
aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #4 on: November 09, 2009, 07:59:31 PM »

Yes, my main point is that, CFP should monitor asigning hidden attributes to files/ folders.
Logged
HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1471


« Reply #5 on: November 09, 2009, 08:02:06 PM »

Then perhaps the thread title should reflect that?
Logged

aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #6 on: November 10, 2009, 01:12:51 PM »

It may be a bypass for some atleast. Important IMO too. see original thread.
Logged
HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1471


« Reply #7 on: November 10, 2009, 03:16:46 PM »

It may be a bypass for some atleast. Important IMO too. see original thread.

Yes, I guess you are correct. It may be a bypass for some malware that people have partially allowed to run...  Roll Eyes
Logged

eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 6516


Why not ? The choice is yours !


« Reply #8 on: November 10, 2009, 03:20:37 PM »

Has anyone alerted a developer yet if this bypass is really existing ?

eXPerience
Logged

aigle
Comodo's Hero
*****
Offline Offline

Posts: 504



« Reply #9 on: November 11, 2009, 07:38:37 PM »

Yes, I guess you are correct. It may be a bypass for some malware that people have partially allowed to run...  Roll Eyes

It,s more tricky as it,s a vbs script infact,  one can just allow scripting host to execute.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.041 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com