Welcome, Guest. Please login or register.
December 11, 2009, 11:06:26 AM

Login with username, password and session length

341690 Posts
37762 Topics
85739 Members

Latest Member: tomoni2

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  ZAbypass
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: ZAbypass  (Read 2327 times)
korben
Comodo Member
**
Offline Offline

Posts: 31



« on: August 14, 2009, 12:51:53 PM »

Net Sec Policy : block
Comp Sec Policy: isolated

Fail

any ideas why? I know I'm missing some of the settings from Proactive... I've got it configured the way useres of the forum had suggested, yet I need to work it out w/t Proactive since when it is ON I simply cannot acces this file but that's not the point.
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4160



« Reply #1 on: August 15, 2009, 05:56:54 PM »

What test are you failing? What does ZAbypass mean?
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
gleach
Comodo Loves me
****
Offline Offline

Posts: 128


« Reply #2 on: August 15, 2009, 07:35:54 PM »

bypass zone alarm firewall tool
Logged
korben
Comodo Member
**
Offline Offline

Posts: 31



« Reply #3 on: August 16, 2009, 02:01:19 AM »

the full name of the test is Bypassing Personal Firewall (Zone Alarm Pro)
it's designed for ZAP but apparently should work with ANY other
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2731


Follow the White Rabbit...


« Reply #4 on: August 16, 2009, 03:25:24 AM »

Hi Korben, the leaktest uses DDE to try and bypass the firewall. Would you mind providing a little more information, please.

The Net Sec Block was applied to what? I assume the Com Sec Policy was applied to  zabypass.exe?

Thanks

Logged

"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."

Forum Policy
korben
Comodo Member
**
Offline Offline

Posts: 31



« Reply #5 on: August 16, 2009, 06:25:45 AM »

Quill is here!

Yes, you are right as for zabypass.exe

Basically what I did was apply my knowledge gathered during other tests/leaks but it didn't work this time.

on a side note, still new thing to me so sometimes you guys post assuming I know what you're talkin about and sometimes I post assuming it's obvious - but I'm learning thanks to you so dont give up on me lol
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2731


Follow the White Rabbit...


« Reply #6 on: August 16, 2009, 06:58:02 AM »

If we start speaking gibberish, just tell us, especially me Smiley
Logged

"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."

Forum Policy
korben
Comodo Member
**
Offline Offline

Posts: 31



« Reply #7 on: August 16, 2009, 10:27:59 AM »

Roger that!

hehe

so? what am I supposed to do with comodo FW to PASS the freakin test?
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 4160



« Reply #8 on: August 16, 2009, 04:10:49 PM »

Where can I download the test?
Logged

Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , Always the latest CIS or CIS Beta (too lazy to update my sig) Athlon XP 2600 1 GB RAM. Opera Browser always using the latest snapshots; Opera 10.10 as of now
Bad Frogger
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 698



« Reply #9 on: August 16, 2009, 04:17:41 PM »

http://www.testmypcsecurity.com/securitytests/zabypass.html
Logged

CIS    Firefox  NoScript  Please remember to follow The Forum Policy.
Quill
Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2731


Follow the White Rabbit...


« Reply #10 on: August 17, 2009, 02:44:52 AM »

Hi korben, see the attached screen shots for what happens when I run zabypass:

The first alert zabypass is making a call to csrss.exe (the client server subsystem) This is not terribly significant in itself, but it would probably make me want to see what happens next.

The second alert has zabypass making a call to firefox (substitute your browser here) Personally, unless I knew specifically what zabypass was, it would be stopped at this point.

The third alert is the most strange, firefox making a call to a COM (Component Object Model) interface. That would definitely set my radar off.

The documentation says zabypass uses the DDE-IPC protocol, well DDE is not COM but IPC messaging is part and parcel of both. Without knowing exactly what zabypass is doing behind the scenes, it's hard to know how it uses IPC (Inter Process Communication) exactly.

 



Logged

"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."

Forum Policy
korben
Comodo Member
**
Offline Offline

Posts: 31



« Reply #11 on: August 17, 2009, 05:57:09 AM »

Appreciate the input, mate!  Thumb Up

It's still rather complicated...  Huh

let me break it down like this  Grin

I use Installer_Updater config, I run the zabypass.exe, I change the config to Proactive and... trying to run the test I clearly see that nothing happens, i.e. no popup window appears, which is good, right? Wink

Perhaps in the near future I will find some time to analyze the issue in detail.
Logged
Quill
Volunteer
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2731


Follow the White Rabbit...


« Reply #12 on: August 17, 2009, 06:09:15 AM »

Apologies, I'm not sure I follow the first part of your break down. zabypass is just a single executable, there's nothing to install. That aside, I'm surprised you don't receive any kind of pop-up when it attempts to access the Internet. What are your security settings for the firewall and D+, aside from running proactive.
Logged

"Well, I've wrestled with reality for 35 years, Doctor, and I'm happy to state I finally won out over it."

Forum Policy
layman
Comodo's Hero
*****
Offline Offline

Posts: 360


« Reply #13 on: August 17, 2009, 06:51:18 AM »

I did this test and CIS easily passed it. You said you use 'installer updater' configuration do that mean you selected 'installer' in the predetermined policy when the alert came up??? If yes, defense+ will definitely give it a clean chit.

When the exe try to inject it into IE block it... but once injected you get the alert that IE (which is safe) try to connect internet, which nobody will doubt for that matter... But blocking it to connect definitely works.
Logged
korben
Comodo Member
**
Offline Offline

Posts: 31



« Reply #14 on: August 17, 2009, 11:19:06 AM »

I followed these instructions:

http://forums.comodo.com/feedbackcommentsannouncementsnews_cis/configuring_cis_for_maximum_security_with_zero_alerts_disccusion-t41405.0.html
Logged
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.188 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com