Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 29, 2009, 06:25:46 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
346092
Posts
38234
Topics
86832
Members
Latest Member:
amma
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Leak Testing/Attacks/Vulnerability Research
ZAbypass
« previous
next »
Pages:
[
1
]
2
Author
Topic: ZAbypass (Read 2654 times)
korben
Comodo Member
Offline
Posts: 47
ZAbypass
«
on:
August 14, 2009, 12:51:53 PM »
Net Sec Policy : block
Comp Sec Policy: isolated
Fail
any ideas why? I know I'm missing some of the settings from Proactive... I've got it configured the way useres of the forum had suggested, yet I need to work it out w/t Proactive since when it is ON I simply cannot acces this file but that's not the point.
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4347
Re: ZAbypass
«
Reply #1 on:
August 15, 2009, 05:56:54 PM »
What test are you failing? What does ZAbypass mean?
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
gleach
Comodo Loves me
Offline
Posts: 128
Re: ZAbypass
«
Reply #2 on:
August 15, 2009, 07:35:54 PM »
bypass zone alarm firewall tool
Logged
korben
Comodo Member
Offline
Posts: 47
Re: ZAbypass
«
Reply #3 on:
August 16, 2009, 02:01:19 AM »
the full name of the test is Bypassing Personal Firewall (Zone Alarm Pro)
it's designed for ZAP but apparently should work with ANY other
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2731
Follow the White Rabbit...
Re: ZAbypass
«
Reply #4 on:
August 16, 2009, 03:25:24 AM »
Hi Korben, the leaktest uses DDE to try and bypass the firewall. Would you mind providing a little more information, please.
The Net Sec Block was applied to what? I assume the Com Sec Policy was applied to zabypass.exe?
Thanks
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
korben
Comodo Member
Offline
Posts: 47
Re: ZAbypass
«
Reply #5 on:
August 16, 2009, 06:25:45 AM »
Quill is here!
Yes, you are right as for zabypass.exe
Basically what I did was apply my knowledge gathered during other tests/leaks but it didn't work this time.
on a side note, still new thing to me so sometimes you guys post assuming I know what you're talkin about and sometimes I post assuming it's obvious - but I'm learning thanks to you so dont give up on me lol
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2731
Follow the White Rabbit...
Re: ZAbypass
«
Reply #6 on:
August 16, 2009, 06:58:02 AM »
If we start speaking gibberish, just tell us, especially me
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
korben
Comodo Member
Offline
Posts: 47
Re: ZAbypass
«
Reply #7 on:
August 16, 2009, 10:27:59 AM »
Roger that!
hehe
so? what am I supposed to do with comodo FW to PASS the freakin test?
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 4347
Re: ZAbypass
«
Reply #8 on:
August 16, 2009, 04:10:49 PM »
Where can I download the test?
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
Bad Frogger
Global Moderator
Comodo's Hero
Online
Posts: 701
Re: ZAbypass
«
Reply #9 on:
August 16, 2009, 04:17:41 PM »
http://www.testmypcsecurity.com/securitytests/zabypass.html
Logged
CIS
Firefox
NoScript
Please remember to follow
The Forum Policy
.
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2731
Follow the White Rabbit...
Re: ZAbypass
«
Reply #10 on:
August 17, 2009, 02:44:52 AM »
Hi korben, see the attached screen shots for what happens when I run zabypass:
The first alert zabypass is making a call to csrss.exe (the client server subsystem) This is not terribly significant in itself, but it would probably make me want to see what happens next.
The second alert has zabypass making a call to firefox (substitute your browser here) Personally, unless I knew specifically what zabypass was, it would be stopped at this point.
The third alert is the most strange, firefox making a call to a COM (Component Object Model) interface. That would definitely set my radar off.
The documentation says zabypass uses the DDE-IPC protocol, well DDE is not COM but IPC messaging is part and parcel of both. Without knowing exactly what zabypass is doing behind the scenes, it's hard to know how it uses IPC (Inter Process Communication) exactly.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
korben
Comodo Member
Offline
Posts: 47
Re: ZAbypass
«
Reply #11 on:
August 17, 2009, 05:57:09 AM »
Appreciate the input, mate!
It's still rather complicated...
let me break it down like this
I use Installer_Updater config, I run the zabypass.exe, I change the config to Proactive and... trying to run the test I clearly see that nothing happens, i.e. no popup window appears, which is good, right?
Perhaps in the near future I will find some time to analyze the issue in detail.
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
Offline
Posts: 2731
Follow the White Rabbit...
Re: ZAbypass
«
Reply #12 on:
August 17, 2009, 06:09:15 AM »
Apologies, I'm not sure I follow the first part of your break down. zabypass is just a single executable, there's nothing to install. That aside, I'm surprised you don't receive any kind of pop-up when it attempts to access the Internet. What are your security settings for the firewall and D+, aside from running proactive.
Logged
"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."
Forum Policy
layman
Comodo's Hero
Offline
Posts: 362
Re: ZAbypass
«
Reply #13 on:
August 17, 2009, 06:51:18 AM »
I did this test and CIS easily passed it. You said you use 'installer updater' configuration do that mean you selected 'installer' in the predetermined policy when the alert came up??? If yes, defense+ will definitely give it a clean chit.
When the exe try to inject it into IE block it... but once injected you get the alert that IE (which is safe) try to connect internet, which nobody will doubt for that matter... But blocking it to connect definitely works.
Logged
korben
Comodo Member
Offline
Posts: 47
Re: ZAbypass
«
Reply #14 on:
August 17, 2009, 11:19:06 AM »
I followed these instructions:
http://forums.comodo.com/feedbackcommentsannouncementsnews_cis/configuring_cis_for_maximum_security_with_zero_alerts_disccusion-t41405.0.html
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.044 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com