Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 22, 2013, 02:54:01 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663495
Posts
70539
Topics
145203
Members
Latest Member:
kaziu687
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
« previous
next »
Pages:
[
1
]
2
3
...
13
Author
Topic: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown (Read 34920 times)
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
on:
August 09, 2009, 06:33:45 PM »
This is a critical request for urgent and immediate action(s).
I downloaded Process Hacker in order to test CIS capability for self protection and CIS failed miserably. Yesterday however, I downloaded Process Explorer from Microsoft Sysinternals and tried to kill CIS processes and CIS then succeeded to defend itself.
Today is a whole different story Process Hacker was able to kill both cfp.exe and cmdagent.exe.
1) I downloaded CIS 3.10
2) I installed CIS 3.10
3)I downloaded Process Hacker from:
http://processhacker.sourceforge.net/
4) I installed Process Hacker and ran it.
5) CIS D+ gave me a warning that Process Hacker was trying to modify some registry key(s)
6) I unticked remember my answer and allow the file to completely execute.
7) Therefore, Process Hacker gui appeared on the screen.
I located CIS processes and right click; I selected kill and the processes were killed one after the other.
CIS was completely dead. I really do not know what's going now. FYI I also tried Online Armor and I also killed Online Armor Processes with Process Hacker. However, One of Online Armor processes put up a fight I had to select Terminator from the list, and OA was dead. I'm quite scared right now. I thought CIS self-protection was impregnable.
Could some of you guys repeat the test and see If you could replicate the same results in order to verify my findings. Please.
Mayday, Mayday, Mayday. This is NOT a joke. The situation is extremely important.
Virtual System: VirtualBox
Operating System: Windows XP SP2
Software Installed: CIS 3.10 and Process hacker.
Host Operating System: Windows Vista SP1
Software Installed: CIS 3.10 Avira free.
Peace.
«
Last Edit: August 09, 2009, 06:46:39 PM by Jaki
»
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
OmeletGuy
Back for a while.
Global Moderator
Comodo's Hero
Offline
Posts: 2905
Dragon Theme Maker
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #1 on:
August 09, 2009, 06:48:38 PM »
It does selfprotect itself, all CIS exe's can be killed by Process Hacker, but D+ loads into the Kernel so if you run a application D+ will Default Deny, in other words D+ cant be killed by shutting down cmdagent.exe or cfp.exe.
Oh and the firewall is kernel also, i have tryed this and killed cmdagent also, i tested it after and D+ and the FW where silent but both still doing there jobs.
Logged
Comodo Dragon themes, including windows Aero options. Download
Here
System Details: W7-64bit | 4GB DDR2 | Intel Core 2 Extreme X6800 | CIS 5.10 | Geforce 560 GTX 1
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #2 on:
August 09, 2009, 06:53:33 PM »
Quote from: OmeletGuy on August 09, 2009, 06:48:38 PM
It does selfprotect itself, all CIS exe's can be killed by Process Hacker, but D+ loads into the Kernel so if you run a application D+ will Default Deny, in other words D+ cant be killed by shutting down cmdagent.exe or cfp.exe.
Oh and the firewall is kernel also, i have tryed this and killed cmdagent also, i tested it after and D+ and the FW where silent but both still doing there jobs.
The bottom line to me is that CIS processes were terminated, whether D+ loaded in kernels is irrelevant because D+ was not even able to protect CIS processes from termination. That's a fact. Urgent action needed to build CIS defenses in order to succesfully protect its own processes.
Peace.
«
Last Edit: August 09, 2009, 06:55:06 PM by Jaki
»
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3678
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #3 on:
August 09, 2009, 08:12:52 PM »
Agreed.
I also think the the setting "Block all unknown requests if the application is closed" Should be considered as a tick box option when installing CIS so that more people use and are aware of it.
Logged
Windows 7 x64
AMD FX 8120, 8gb ram, ATI 6870 1gb
SiberLynx
Comodo's Hero
Offline
Posts: 2159
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #4 on:
August 09, 2009, 08:49:11 PM »
Hi Jaki,
There were several discussions already in the forum re: Process Hacker
Please read this one in the first place:
https://forums.comodo.com/leak_testingattacksvulnerability_research/process_hacker_can_terminate_cis_processes_a_concern-t38772.0.html
(probably you've read that already)
That may answer many questions, especially considering
#5
& your action in
#6
My regards
Logged
admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #5 on:
August 09, 2009, 09:11:48 PM »
Quote from: SiberLynx on August 09, 2009, 08:49:11 PM
Hi Jaki,
There were several discussions already in the forum re: Process Hacker
Please read this one in the first place:
https://forums.comodo.com/leak_testingattacksvulnerability_research/process_hacker_can_terminate_cis_processes_a_concern-t38772.0.html
(probably you've read that already)
That may answer many questions, especially considering
#5
& your action in
#6
My regards
Thanks for the link. Am I to believe that Comodo is not interested in fixing the problem? Since the problem still exist. Or are they still working on a solution? The notion that CIS can always self protect its processes has been refuted. What's next? A malware that will prevent CIS to load in kernel and then that will be the end of the computer security world.
Tonight I feel really sad and depressed.
Peace anyway.
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
PhyxionNL
Comodo Loves me
Offline
Posts: 141
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #6 on:
August 10, 2009, 01:31:42 AM »
Well, on Windows 7 you can just kill the processes in taskmanager, this really needs some work.
Logged
Dennis2
Global Moderator
Comodo's Hero
Offline
Posts: 6580
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #7 on:
August 10, 2009, 01:42:46 AM »
Quote from: Jaki on August 09, 2009, 09:11:48 PM
Thanks for the link. Am I to believe that Comodo is not interested in fixing the problem? Since the problem still exist. Or are they still working on a solution? The notion that CIS can always self protect its processes has been refuted. What's next? A malware that will prevent CIS to load in kernel and then that will be the end of the computer security world.
Tonight I feel really sad and depressed.
Peace anyway.
Sorry but.
You install it
You allowed it to run
You shutdown CIS
Dennis
Logged
Moderator:
Aims Forum a friendly place. Any concerns? Please PM me and/or review the
Forum Policy 2012Updated
.
System:
Windows 7 SP1(UAC)x32, LUA, CIS6.2813, Sandboxie 3.76
Vista Home P.(UAC)x32 SP2, LUA,C. 5.12.
SiberLynx
Comodo's Hero
Offline
Posts: 2159
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #8 on:
August 10, 2009, 02:58:46 AM »
Quote from: Dennis2 on August 10, 2009, 01:42:46 AM
Sorry but.
You install it
You allowed it to run
You shutdown CIS
Dennis
This response is much appreciated, Dennis.
And that's
precisely
what I meant when referring to that link for
Jaki
Quote from: Jaki
Tonight I feel really sad and depressed
Please don't be depressed.
When we are - our reaction to events in most cases are not very relevant (don't be offended. I said: "we"= "all of us"
).
What that discussion said, and what
Dennise2
confirmed - that is not a real issue
Find the Registry Setting / startups / devices / drivers ... disable basic protection or "allow" actions yourself and go ahead and disable / uninstall / devices/ remove /crash whatever you want... You do that - you will succeed.
When the "Alien Application" will try to perform that and you are not - alerted that would be a big concern... but that wasn't the case.
Cheers!
Logged
admin; XP Pro, SP3 (32bit); CIS 3.14.130099.587 (firewall only; Proactive with Defense+)- that is the only Comodo's thing I need; Emsisoft - Mamutu Behavioural Blocker or Full EAM
Win 7 x64: Comodo Firewall 3.14; Emsisoft Anti-Malware
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #9 on:
August 10, 2009, 05:53:35 AM »
Quote from: SiberLynx on August 10, 2009, 02:58:46 AM
This response is much appreciated, Dennis.
And that's
precisely
what I meant when referring to that link for
Jaki
Please don't be depressed.
When we are - our reaction to events in most cases are not very relevant (don't be offended. I said: "we"= "all of us"
).
What that discussion said, and what
Dennise2
confirmed - that is not a real issue
Find the Registry Setting / startups / devices / drivers ... disable basic protection or "allow" actions yourself and go ahead and disable / uninstall / devices/ remove /crash whatever you want... You do that - you will succeed.
When the "Alien Application" will try to perform that and you are not - alerted that would be a big concern... but that wasn't the case.
Cheers!
You both missed the point here. By allowing it to run meant the software did not display any malicious behavior, it just ran. The malicious behavior occurred when Process Hacker terminated CIS processes; that was the point. D+ crumbled as if though it was built on sand.
When that happened D+ contingency plan kicked in and went to a default deny mode. All my ports were still stealth and I was not able to run anything, and that is good. However, my contention point is D+ did not protect its own processes and that needs to be rectified.
Peace.
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #10 on:
August 10, 2009, 08:10:01 AM »
Hi Guys
I just tested Agnitum Outpost Security Suite 2009 with Process Hacker even though I was able to terminate its gui process; however, I was not able to terminate its core process. I think the process name is acs.exe. When I tried to kill it, it went back up right away. That process simply would not stay dead.
Consequently, I proceeded to use Process Hacker Terminator and Outpost core process resisted the attempt to be terminated. Process Hacker failed to terminate it even though I allowed Process Hacker to do so after several warnings from OSS 2009 I might add.
To me it is essential that CIS, beside the contingency plan of default deny, be able to defend its processes successfully. If this is a bug, then it is a major one. I only hope that Comodo finds a solution to that problem soon.
Peace.
«
Last Edit: August 10, 2009, 01:35:44 PM by Jaki
»
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 476
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #11 on:
August 10, 2009, 08:17:47 AM »
1. On Windows 7 you
cannot
kill CIS' processes via Taskmanager if D+ is working correctly what should be the normal case.
2. The option of D+ to block all unknown events if CIS is closed doesn't provide more security because CIS will automatically enable such an option if it gets closed in a non usual manner, e.g. killing it with other processes such as Process Hacker.
3. If you deny Process Hacker to load it's kernel mode driver it can't kill CIS' processes.
There can't be protection anymore once a kernel mode driver is loaded.
Just a brief summary of everything one need to know regarding this issue here.
Logged
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #12 on:
August 10, 2009, 08:26:22 AM »
Quote from: evil_religion on August 10, 2009, 08:17:47 AM
1. On Windows 7 you
cannot
kill CIS' processes via Taskmanager if D+ is working correctly what should be the normal case.
2. The option of D+ to block all unknown events if CIS is closed doesn't provide more security because CIS will automatically enable such an option if it gets closed in a non usual manner, e.g. killing it with other processes such as Process Hacker.
3. If you deny Process Hacker to load it's kernel mode driver it can't kill CIS' processes.
There can't be protection anymore once a kernel mode driver is loaded.
Just a brief summary of everything one need to know regarding this issue here.
The warning that I got when I ran Process Hacker could be the same warning that I could get when I run other applications such as a download manager, a cleaner, a video player etc... There is no malicious behavior by running Process Hacker. However, when I initiated Process Hacker to terminate a process and successfully did so, that's the malicious behavior. Can you deny that? Default deny is just a contingency plan after the fact. The fact is CIS processes were terminated.
Peace.
«
Last Edit: August 10, 2009, 08:37:54 AM by Jaki
»
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
evil_religion
Malware Research Group
Comodo's Hero
Offline
Posts: 476
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #13 on:
August 10, 2009, 12:20:02 PM »
If your D+ is set up correctly Comodo doesn't fail Process Hacker:
Logged
Jaki
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 550
Re: Mayday, Mayday. This is NOT a Joke: CIS Processes shutdown
«
Reply #14 on:
August 10, 2009, 12:35:49 PM »
Quote from: evil_religion on August 10, 2009, 12:20:02 PM
If your D+ is set up correctly Comodo doesn't fail Process Hacker:
Evil Religion
You probably forgot that Process Hacker is not a rogue application. It is an application that allows someone to test his or her security apparatus. How can you really test a security apparatus if you do not allow the testing application to be fully loaded. If, for the sake of argument, Process Hacker was a piece of malware I would not even have allowed it to run, of course. Your screenshots of D+ blocking Process Hacker is beside the point.
I would consider success for CIS if it had blocked Process Hacker even after being fully loaded like Outpost Security Suite 2009 did.
Please read reply #10
. OSS 2009 did successfully prevented its core process from being terminated even when Process Hacker was fully loaded.
You stated also that: "There can't be protection anymore once a kernel mode driver is loaded." Well that is not true at least with respect to OSS 2009. Process Hacker kernel mode driver was indeed fully loaded and yet it could not terminate OSS 2009 core process. That is exactly the same thing I want CIS to do.
Peace.
«
Last Edit: August 10, 2009, 01:27:19 PM by Jaki
»
Logged
"Anything you scan will be scanned against you; if you are smart, you will stop scanning." --Vundo
"Detecting and cleaning are futile, my growing family members will eventually hack you." --Virut
Tags:
Pages:
[
1
]
2
3
...
13
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.057 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com