Welcome, Guest. Please login or register.
March 21, 2010, 08:09:50 AM

Login with username, password and session length

373421 Posts
41422 Topics
94154 Members

Latest Member: Quiksilver93

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Learn about Computer Security and Interact with Security Experts
| |-+  Leak Testing/Attacks/Vulnerability Research
| | |-+  WallBreaker simply bypasses comodo firewall!!! [Resolved]
« previous next »
Pages: [1] Go Down Print
Author Topic: WallBreaker simply bypasses comodo firewall!!! [Resolved]  (Read 3171 times)
soygul
Newbie
*
Offline Offline

Posts: 3


« on: June 05, 2007, 06:50:56 PM »

WallBreaker.exe simply leaks data to internet and cannot be stopped by comodo firewall!! Does anyone know any way to configure the firewall to stop this kind of leaks?

info: http://www.firewallleaktester.com/leaktest11.htm
exe file: http://www.firewallleaktester.com/leaks/WallBreaker.exe
« Last Edit: June 06, 2007, 12:15:59 PM by soygul » Logged
Toggie
Guest
« Reply #1 on: June 05, 2007, 06:57:10 PM »

Hi soygul, welcome to the forum.

You might want to look at these results:

http://www.matousec.com/projects/windows-personal-firewall-analysis/leak-tests-results.php

Toggie
Logged
soygul
Newbie
*
Offline Offline

Posts: 3


« Reply #2 on: June 05, 2007, 07:26:49 PM »

Yeah i've seen the results and it says "On the highest security settings, Comodo passed all leak-tests" but how to get that highest security Smiley I've messed around the firewall quite a bit but still couldn't stop the leakage...
Logged
Toggie
Guest
« Reply #3 on: June 05, 2007, 07:47:06 PM »

I just ran the WallBreaker tests and CFP passed every test. Meaning that IE didn't connect to the website. Just simply a case of denying IE when CFP prompts.

I'm not sure what their definition of 'Highest Settings' is, and they don't seem to indicate how they performed their tests, at least I can't find it...

I'm going to move this to the firewall leak testing forum. It's a better place for it.

Toggie
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5364


I'm not a complete idiot, some bits are missing.


« Reply #4 on: June 06, 2007, 06:40:21 AM »

Hi soygul

With regards to the Highest Security level, I think that Matousec might have been referring to CFPs Alert Frequency Level (Security - Advanced - Miscellaneous) of Very High.
Logged

Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #5 on: June 06, 2007, 10:02:00 AM »

The concept behind these leaktests it to see if the application (iexplorer) loaded by various means is able to connect to the internet.

CPF with standard settings is able to block this leaktest.

How many application rules for iexploere.exe do you have?
Is there a parent application specified in these rules?
Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
soygul
Newbie
*
Offline Offline

Posts: 3


« Reply #6 on: June 06, 2007, 12:11:44 PM »

Hi soygul

With regards to the Highest Security level, I think that Matousec might have been referring to CFPs Alert Frequency Level (Security - Advanced - Miscellaneous) of Very High.

Exactly! When Alert Frequency Level = Medium -or- High, the leaktest fails (a popup warns about wallbreaker.exe trying to launch ie in order to connect to the net...). So problem fixed. Thanks for the help.
Logged
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6258



« Reply #7 on: June 06, 2007, 12:59:19 PM »

Melih told me before, regarding those "highest settings" that it means High Alert Frequency, and uncheck the box "Do not show alerts for applications certified by Comodo." 

Hope that helps,

LM
Logged

You read my sig block.  That's enough personal interaction for one day. Kewl
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #8 on: June 07, 2007, 08:26:08 AM »

Exactly! When Alert Frequency Level = Medium -or- High, the leaktest fails (a popup warns about wallbreaker.exe trying to launch ie in order to connect to the net...). So problem fixed. Thanks for the help.

CPF passed wallbreaker leaktests using very low alert frequency setting and don't show any alert for application certified by comodo here.

I ran wallbreaker as intended and got no problem.

But using a slight testing procedure variation I managed to fail Test 1 and 3 until i disabled don't show any alert for application certified by comodo.

Before every leaktest I killed explorer.exe process then reloaded explorer.exe and ran one of the leaktests.
CPF passed all of them this way under admin account usinig IE6.

But If I kill explorer.exe and let wallbreaker load it (using test 1 and 3) CFP fails those tests.
The test is exploited using the default browser (it doesn't have to be iexplore.exe).

Disabling don't show any alert for application certified by comodo somewhat solved this issue because CPF alerted me that explorer.exe attempted to run iexplore.exe through windows messages (explorer.exe modified the user interface of iexplore.exe...but mentioned that explorer.exe was a safe application) instead of directly loading it.

Knowing that I was running a leaktest I blocked those attempts but under real-life conditions I would have failed to notice that. Cry

If iexplore 6 is not the default browser the test fails... Sad

 [ at ]  all: Do you mind running wallbreaker test one more time?


« Last Edit: June 07, 2007, 09:05:45 AM by gibran » Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.055 seconds with 16 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com