In Sandbox Commands Issued From Command Line Affect Real System [M620]

1. The full product and its version:
COMODO Internet Security 8.0.332922.4281 BETA
2. Your Operating System (32 or 64 bit) and ServicePack revision. and if using a virtual machine, which one:
windows 7 x64 in real system
3. List all the configuration changes you did. Are you using Default configuration? If no, whats the difference?:
Default configuration, Only been changed Viruscope to work inside and outside the sandbox
4. Did you install over a previous version without uninstalling first, or import a previous configuration file?:
Clean install
5. Other Security, Sandboxing or Utility Software Installed:
No
6. Step by step description to reproduce the issue. Or if you cannot reproduce it, what you actually did before it happened, step by step:
1: As an example, run the script sandboxed as Virtually and see that it is able to kill the internet connection.
2: This sample is a .bat file which uses command line.

7. What actually happened when you carried out these steps:
Applications sandboxed as fully virtualized are able to affect the real system if the files are programmed to use command line.

8. What you expected to see or happen when you carried out these steps, and why (if not obvious):
Applications virtualized as fully virtualized should not be able to affect the real system through command line commands.

I just thought of something. Does this malware kill the internet by using command line? If so this has been reported in the tracker (M620), but not yet through the forum. Please check and let me know if this is the same issue.

Thanks.

yes by tybe *bat , Please possible link to issue M620

Thank you. I have just modified the first post. Does everything seems correct? If it does then please send me a PM with a download link to the sample and I will forward this.

Thanks again.

Everything be correct ,thank you :-TU

Thank you very much for your report in standard format, with all information supplied. The care you have taken is much appreciated by Comodo, and will increase the likelihood that this bug can be fixed.

Developers may or may not communicate with you in the forum or by PM/IM, depending on time availability and need. Because you have supplied complete information they may be able to replicate and fix the bug without doing so.

Many thanks again.

This issue has not been resolved

Thank you for checking this. I have updated the tracker.

The devs have not marked this as Fixed in the tracker. However, sometimes bugs are fixed by the release of new versions, but not marked as Fixed in the tracker.

If you are able please check with the newest version (CIS version 8.0.0.4337) and let me know if this is fixed on your computer with that version.

Thank you.

This issue has not been resolved

Thank you for checking this. I’ve updated the tracker.

Hello,

The devs have not marked this as Fixed in the tracker. However, sometimes bugs are fixed by the release of new versions, but not marked as Fixed in the tracker.

If you are able please check with the newest version (CIS version 8.1.0.4426) and let me know if this is fixed on your computer with that version.

Thank you.