Welcome, Guest. Please login or register.
October 07, 2008, 10:51:25 AM

Login with username, password and session length

197841 Posts
22772 Topics
54723 Members

Latest Member: inetbizo

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Which Product do you want Comodo to develop next?
| | |-+  Drive by downloads
« previous next »
Pages: [1] Go Down Print
Author Topic: Drive by downloads  (Read 1135 times)
cypressotter
Newbie
*
Offline Offline

Posts: 4


« on: March 18, 2008, 10:28:24 AM »

I'm running CAV (2.0.17.58).
I got hit by a nice drive by download. With lots of detective work 4 hours later I finished nixing the half-dozen .exe's that appeared in my system32 dir.
Google has a whitepaper on drive by downloads dated Feb. 2008 claiming a huge volume of "malicious URL's" in their research.
From the whitepaper:
"Unfortunately, we also find that even state-of-the-art anti-virus engines are lacking in
their ability to protect against drive-by downloads. While this is to be expected, it does call for
more elaborate defense mechanisms to curtail this rapidly increasing threat."

Request: "Comodo anti-drive by"
Logged
Ragwing
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 3108


Sailor Warrior of Love and Justice


« Reply #1 on: March 18, 2008, 11:32:07 AM »

Greetings!

As most drive-by downloads uses buffer overflow, Comodo Memory Firewall should be able to stop these.
Comodo Firewall Pro 3 with Defense+ enabled should be able to prevent the download of .exe-files (as it'll warn about the creation). They're the biggest threat, as they're able to execute malicious code.

Cheers,
Ragwing
Logged



XP SP3 2 GHz 768 MB RAM
5 services / 12 processes
cypressotter
Newbie
*
Offline Offline

Posts: 4


« Reply #2 on: March 18, 2008, 12:30:28 PM »

Good news! Thanks for the quick reply! I can see my choice to eschew CFP for XP Firewall after an OS reinstall was not the best decision...
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5644



WWW
« Reply #3 on: March 18, 2008, 05:34:08 PM »

As Ragwing pointed out Comodo Memory Firewall was designed to do that..

between CMF and CFP... you are pretty safe....

Melih
Logged

Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.167 seconds with 18 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com