Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2013, 02:54:50 PM

Login with username, password and session length

664071 Posts
70633 Topics
145265 Members

Latest Member: sharf224

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo SiteInspector - CSI
| | |-+  False positives and exploits which are undetected
« previous next »
Pages: [1] 2 3 Go Down Print
Author Topic: False positives and exploits which are undetected  (Read 71419 times)
vadim
Comodo Loves me
****
Offline Offline

Posts: 191



« on: April 29, 2011, 07:24:56 AM »

We would be grateful for any information about false positives and exploits which are undetected by SiteInspector detection engine.

Thank you for all your feedbacks which help us to improve the detection technology.
Logged
EricJH
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 16723



« Reply #1 on: April 29, 2011, 08:42:00 AM »

Stickied.
Logged

morphiusz
Star Group
Comodo's Hero
*****
Online Online

Posts: 2197


Comodo's śmieć :)


WWW
« Reply #2 on: April 29, 2011, 10:45:04 AM »

http://siteinspector.comodo.com/public/reports/21003

http://siteinspector.comodo.com/public/reports/21007

Smiley

--> http://siteinspector.comodo.com/public/reports/21016
« Last Edit: April 29, 2011, 05:04:51 PM by morphiusz » Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 3061



WWW
« Reply #3 on: April 30, 2011, 12:47:44 AM »

idk if SI uses just the cloud or not.

but this is caught by comodo av but is said to be safe by SI

http://siteinspector.comodo.com/public/reports/21137

http://valkyrie.comodo.com/Result.aspx?sha1=328DFE45945A3E555614B8D83624C3D31BAB6453&&query=0&&filename=Le

http://www.virustotal.com/file-scan/report.html?id=3585fcbe71d13aeb9fb1f0e9a63f0e3e5b264d9b86249747ffe3cd04d4067e0e-1304142320
« Last Edit: April 30, 2011, 12:50:12 AM by wasgij6 » Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
morphiusz
Star Group
Comodo's Hero
*****
Online Online

Posts: 2197


Comodo's śmieć :)


WWW
« Reply #4 on: April 30, 2011, 02:52:04 PM »

exploit:

> http://siteinspector.comodo.com/public/reports/22005

>
Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 3061



WWW
« Reply #5 on: April 30, 2011, 10:32:54 PM »

http://siteinspector.comodo.com/public/reports/22441
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
morphiusz
Star Group
Comodo's Hero
*****
Online Online

Posts: 2197


Comodo's śmieć :)


WWW
« Reply #6 on: May 02, 2011, 04:20:49 PM »

This exploit http://siteinspector.comodo.com/public/reports/24028

creates this file on desktop: http://www.virustotal.com/file-scan/report.html?id=819805e042c621d2565b050fbce6f9dcde781d4ee2c4f7a8f2fa56b61d1cbe05-1304371147

and wants to run it.

(when you are using IE).

> http://siteinspector.comodo.com/public/reports/30696 exploit not detected by si engine

active java exploit - http://siteinspector.comodo.com/public/reports/32379

undetected - http://siteinspector.comodo.com/public/reports/38213
« Last Edit: May 25, 2011, 02:59:18 PM by morphiusz » Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 3061



WWW
« Reply #7 on: June 05, 2011, 12:01:32 AM »

it took a while but i finally found something thats undetected
http://siteinspector.comodo.com/public/reports/46941

http://valkyrie.comodo.com/Result.aspx?sha1=BDB0AEC982BFBCFBE65E16BB5BD832784ECB5CD5&&query=0&&filename=atualizar.exe

http://www.virustotal.com/file-scan/report.html?id=d68abae55e1dc9e8a20512437ea337a2404fcdf4a4e890a3de80f8852f989965-1307249089
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
morphiusz
Star Group
Comodo's Hero
*****
Online Online

Posts: 2197


Comodo's śmieć :)


WWW
« Reply #8 on: June 05, 2011, 03:55:11 AM »

It's only because Comodo AV cannot detect it..
When it will be added to AV database it will be detected.
SI didn't fail Smiley.
Submit this file to the AV lab.
Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 3061



WWW
« Reply #9 on: July 04, 2011, 01:35:26 AM »

undetected java exploit
http://siteinspector.comodo.com/public/reports/108904
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
morphiusz
Star Group
Comodo's Hero
*****
Online Online

Posts: 2197


Comodo's śmieć :)


WWW
« Reply #10 on: July 28, 2011, 02:06:28 PM »

http://siteinspector.comodo.com/public/reports/171236

false positive

http://siteinspector.comodo.com/public/reports/171236 - FP? and other reffering to google

i believe that they are FP also:

http://siteinspector.comodo.com/public/reports/171426
http://siteinspector.comodo.com/public/reports/171379
http://siteinspector.comodo.com/public/reports/171658
http://siteinspector.comodo.com/public/reports/171625
http://siteinspector.comodo.com/public/reports/171553
http://siteinspector.comodo.com/public/reports/171497
« Last Edit: July 28, 2011, 02:13:06 PM by morphiusz » Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 3061



WWW
« Reply #11 on: July 28, 2011, 02:22:26 PM »


if this is a FP then there are a lot because all its saying is a file was downloaded into temporary internet files which is what happens when you install a program
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
morphiusz
Star Group
Comodo's Hero
*****
Online Online

Posts: 2197


Comodo's śmieć :)


WWW
« Reply #12 on: July 28, 2011, 03:32:59 PM »

i think that it is working differently. it checks action preformed by browser without user premission.
Logged
wasgij6
Global Moderator
Comodo's Hero
*****
Online Online

Posts: 3061



WWW
« Reply #13 on: July 28, 2011, 03:36:44 PM »

i think that it is working differently. it checks action preformed by browser without user premission.

maybe but i have tested SI against some legit download sites like filehippo.com and i put the link it for ccleaner installer and it flags it as a medium risk.

http://siteinspector.comodo.com/public/reports/172069
Logged

| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
morphiusz
Star Group
Comodo's Hero
*****
Online Online

Posts: 2197


Comodo's śmieć :)


WWW
« Reply #14 on: July 28, 2011, 03:57:38 PM »

so that should be fixed asap ...
Logged
Tags:
Pages: [1] 2 3 Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.037 seconds with 20 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com