Details of HIPS/Firewall/BO tests that CIS fails

I’m starting this topic with the sole intention of creating a list containing any IMPORTANT HIPS/Firewall/Buffer Overflow test - i.e. one that actually matters - that CIS fails/could do better in, for the Comodo devs to look into. I’m sure there aren’t many :wink:

What I would love to hear about is real world malware that we fail on. Pls feel free to create another thread if you wish.

Isn’t there already a dedicated thread for that? Maybe I’m mistaken, but isn’t that what this is for?

It says in the title “Malware that CIS has not detected” as well as FP’s ???

I got a pretty good collection. However CIS seems to block almost every sample I launch. I have over 80K files so I cant test each one of it.

However if any one knows a nice nasty peace of malware please PM me. DO NOT POST IT HERE.
PM me and I will test it right away.

Just so you know, until now, D+ blocks everything I put to the test.

I tried something similar…

Didn’t get a single PM…

Guess CIS is pretty solid! =)

CIS is too overpowerd for simple malwares… :smiley: it needs some kind of lab generated unrealistic super baddie where you click allow once or twice and with a code designed especially to avoid detection by D+ ! :wink:

EDIT:: still a good thread Beanie, I think Clipboard logger detection is not there atm, Melih happens to know if catching this “behaivior” is in the planning maby for 3.9?

Yeah, AFAIK there’s no clipboard logger detection as yet.

I don’t know about webcam logging though… is that a valid concern, do you think? ???

You can bypass the x64 version although real world malware most likely won’t do so.
I hope they will make a full x64 ring 0 HIPS, hopefully with 3.9 soon.

rejzor said something about that D+ doesn’t catch Virut but

  1. he didn’t tell if he used proactive config profile (which is needed to prevent patching any executables)
  2. he doesn’t share the sample.

I don’t share malware samples with anyone that is not a malware expert that i know or someone from an anti-malware company.
And as i said, i used default Safe Mode profile for Defense+. I haven’t changed anything else.

I made this thread with the sole intention of creating a list of tests/malware etc that CIS is not incredibly strong against, so that the devs could make it incredible strong against them (not saying CIS isn’t strong, it’s one of the strongest security solutions out there ;D)

