Welcome, Guest. Please login or register.
Did you miss your activation email?
June 19, 2013, 10:49:51 AM

Login with username, password and session length

668904 Posts
71132 Topics
145741 Members

Latest Member: DeRo 0000

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  CIS 5.9 bypassed by java_rhino exploit
« previous next »
Pages: 1 [2] 3 4 5 Go Down Print
Author Topic: CIS 5.9 bypassed by java_rhino exploit  (Read 16305 times)
Chiron
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5772



Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #15 on: December 21, 2011, 05:37:10 PM »

What happens if you have CIS configured as I suggest here?

Thanks.
Logged

languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #16 on: December 21, 2011, 07:32:51 PM »

how about turning off enhanced security mode?
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
Kruis
Comodo's Hero
*****
Offline Offline

Posts: 1242



Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #17 on: December 21, 2011, 08:51:05 PM »

Java Downloader Comodo Not Detected  embarassed
Logged

Security Professional
OmeletGuy
Back for a while.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2905


Dragon Theme Maker


Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #18 on: December 21, 2011, 08:54:08 PM »

Dragon can stand up to this.. It asks if you want to run Java or not..  Grin

As for CIS.. I >believe< 6.0 will help protect vs this..
Logged

Comodo Dragon themes, including windows Aero options. Download  Here

System Details: W7-64bit | 4GB DDR2 | Intel Core 2 Extreme X6800 | CIS 5.10 | Geforce 560 GTX 1
liosant
Comodo's Hero
*****
Offline Offline

Posts: 259



Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #19 on: December 21, 2011, 11:06:49 PM »

try this procedure disables antivirus, firewall, defense +, quit the CIS, terminate cmdagent, uncheck Run cloud behavior analysis based on unrecognized files and automatically check the files not recognized in the cloud
remove all files Trusted Files

important: delete all files in the folder C: \ Program Files \ COMODO \ COMODO Internet Security \ database
and restart the pc  and redo the test
oops! after restart active  antivirus, firewall and defense +, except the check in the clouds Grin
  does not hurt to try Thumb Up

sorry my english!
« Last Edit: December 21, 2011, 11:35:31 PM by liosant » Logged

Comodo internet security 6 - installation and configuration http://www.youtube.com/watch?v=EmbhbCzxThM
had a doubt, and it was resolved?
add the tag (solved)
thus helps those who have the same doubts, besides avoiding repeated questions on the same subject.
clockwork
Comodo's Hero
*****
Offline Offline

Posts: 1942


Oxygen requires Chuck Norris to live


Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #20 on: December 22, 2011, 01:29:31 AM »

I think, procedures should reflect used settings, and not all possible settings which could have an effect.

The exploit and the payload seems not to be asked by defense+ as its described.
Logged

"If there is a problem, it`s something interesting. Try to circumvent or fix it.
In the old ages there was no support. That`s why we got the brain we have today.
Otherwise we would only be able to call a number and listen."
naren
Comodo's Hero
*****
Offline Offline

Posts: 3914


Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #21 on: December 22, 2011, 03:43:55 AM »

Yes, I hope so too. I think a possibility could be that Comodo just starts blocking all known payloads. This way a exploit could run, but it can't make contact with the hackers machine. This would be more efficient then blocking all exploits I think.

When opening the page and starting the exploit Avast detected the exploit with a signature. It detected the exploit, not the payload. The PC was thereby not compromised.

This is Avast description after blocking the infection: http://www.avast.com/en-eu/lp-security-information-fp2?p_ext=0&utm_campaign=Virus_alert&utm_source=prg_fav_60_3&utm_medium=prg_systray&utm_content=.%2Ffa%2Fen-eu%2Fvirus-alert-challenger2&p_vir=java:Agent-AGH%20

Which Avast shield detected it? Does File Shield detects it? I guess Script or WebShield detected it?

Can you check & tell me if UnThreat Free detects it? I am currently running UnThreat so wanna know.

Or post VirusTotal link.

Thanx
Naren
Logged
webbie146
Comodo's Hero
*****
Offline Offline

Posts: 262



Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #22 on: December 22, 2011, 03:53:30 AM »

Which Avast shield detected it? Does File Shield detects it? I guess Script or WebShield detected it?

Can you check & tell me if UnThreat Free detects it? I am currently running UnThreat so wanna know.

Or post VirusTotal link.

Thanx
Naren

I will try all suggestions i got just to test this out. Thing is CIS is bypassed in the default config, which is what most people use. I will test it out though.

Sure i can test UnThreat if you want  Thumb Up
Problem is uploading to VT is not that easy. These exploit go straight to memory, meterpreter does not even touch the disk. I can try though.
Logged
naren
Comodo's Hero
*****
Offline Offline

Posts: 3914


Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #23 on: December 22, 2011, 04:47:32 AM »

I will try all suggestions i got just to test this out. Thing is CIS is bypassed in the default config, which is what most people use. I will test it out though.

Sure i can test UnThreat if you want  Thumb Up
Problem is uploading to VT is not that easy. These exploit go straight to memory, meterpreter does not even touch the disk. I can try though.

Yes plzz test UnThreat Free & report here. I bet UnThreat Free will detect it Smiley

Thanx
Naren
Logged
SpeedyPC
Comodo's Hero
*****
Offline Offline

Posts: 510



Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #24 on: December 22, 2011, 05:12:41 AM »

Detected with Signature, so the exploit was blacklisted on their AV.

I guess Avast is by far to clever for Comodo Cheesy
Logged

ASUS G75VX-T4153H, Avast Free v8.0.1489, Outpost Firewall Pro 8.1, W8 64bit, Firefox & IceDragon (NS/AdP/LP/TSB/TL/Web/Ghost/VT), Thunderbird (AdP), Hitman Pro, MBAM, WinPatrol, EEK, Secunia PSI, CCleaner, Zemana AL Free, Macrium Reflect Free
B-boy/StyLe/
Newbie
*
Offline Offline

Posts: 5


Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #25 on: December 22, 2011, 09:08:04 AM »

Will NoScript help in stopping this even JAVA is installed on the machine ? Smiley
Can you test the exploit with NoScript enabled and  java installed and NoScript enabled without Java installed.
Thanks !



Regards,
Georgi
Logged
webbie146
Comodo's Hero
*****
Offline Offline

Posts: 262



Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #26 on: December 22, 2011, 10:19:33 AM »

how about turning off enhanced security mode?

Just tested, there is no change. CIS still bypassed, and no alerts.

What happens if you have CIS configured as I suggest here?

Thanks.

Still bypassed, with no alerts.

Yes plzz test UnThreat Free & report here. I bet UnThreat Free will detect it Smiley

Thanx
Naren

I tested Unthreat free. I updated it, and left all settings stock. Opened the link and the PC got exploited. Unthreat did not pop-up any alert at all.
Unthreat get's bypassed.

Will NoScript help in stopping this even JAVA is installed on the machine ? Smiley
Can you test the exploit with NoScript enabled and  java installed and NoScript enabled without Java installed.
Thanks !

Regards,
Georgi

Noscript can block this. Once u open up the link Noscript will automatically block the exploit.
Tested sandboxie for someone too. Sandboxed the browser, and emptied the sandbox.
The connection between the hacker and victim PC is interrupted. Sandboxie is effective against this exploit.
Logged
languy99
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3943



Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #27 on: December 22, 2011, 12:25:00 PM »

make one change and you will see how it is being exploited. Go to d+ security policy, protected com interfaces tab, select add com components, in the add new item area add * then select ok to everything. Try to run the exploit again and see if you get any popups now, fiy there might be a lot.
Logged

http://www.youtube.com/languy99

Software Reviews for all.

Follow me on Twitter http://twitter.com/#!/languy99
harsha_mic
Computer Security Testing Group
Comodo Loves me
*****
Offline Offline

Posts: 154


Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #28 on: December 22, 2011, 12:28:35 PM »

webbie146, if you don't mind, i'm interested to see if OA free/premium blocks it or not..
Logged

W7 64 bit | Comodo Fw v5.8 | Eset NOD32 AV v5 | Hitman (ondemand)
WinDefend
Comodo Member
**
Offline Offline

Posts: 26



Re: CIS 5.9 bypassed by java_rhino exploit
« Reply #29 on: December 22, 2011, 12:58:45 PM »

Hi webbie,

Is it possible to run a re-test, if you have time? The latest Java 6 is update 30, update 27 was released in September and 29 in October. (28 was skipped.)
Logged
Tags:
Pages: 1 [2] 3 4 5 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.065 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com