Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #176  
Old August 4th, 2011, 07:03 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

Blackday successfully bypassed both restricted and untrusted sandboxes. GPCode did not manag to bypass Untrusted nor Partially Limited.

Both would have been blocked had I not disabled the heuristics/ other stuff.


Screenies in the next few posts.
Attached Thumbnails
Click image for larger version

Name:	betainstall.PNG
Views:	2
Size:	87.5 KB
ID:	228399  

Click image for larger version

Name:	blackdaysandboxlevel.PNG
Views:	470
Size:	12.1 KB
ID:	228403  

Attached Images
   
__________________

Last edited by Hungry Man : August 4th, 2011 at 07:34 PM.
  #177  
Old August 4th, 2011, 07:04 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

More. In order.

Next post will include GPCode. This concludes the Black-Day test.

edit oops
Attached Thumbnails
Click image for larger version

Name:	blackdaysandboxlevel.PNG
Views:	469
Size:	12.1 KB
ID:	228404  

Attached Images
  
__________________
  #178  
Old August 4th, 2011, 07:06 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

GPCode.

Last pic is the system info.
Attached Thumbnails
Click image for larger version

Name:	gpcodesandbox.PNG
Views:	1
Size:	10.3 KB
ID:	228408  

Attached Images
    
__________________
  #179  
Old August 4th, 2011, 07:07 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

I didn't bother posting the partially limited results as they are the same. No infection from GPCode on this machine.

I'll try on Windows 7 later.
__________________
  #180  
Old August 4th, 2011, 07:50 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: COMODO Internet Security 5.x Thread

__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
  #181  
Old August 4th, 2011, 07:58 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

Again, to reiterate, the default settings of Comodo WILL block this. It's just that the sandbox was not enough on its own.
__________________
  #182  
Old August 5th, 2011, 05:38 AM
lordraiden's Avatar
lordraiden lordraiden is offline
Very Frequent Poster
 
Join Date: Jan 2006
Posts: 2,201
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by Hungry Man
Again, to reiterate, the default settings of Comodo WILL block this. It's just that the sandbox was not enough on its own.

Have you report this "problem"?
Anyway since they are planning a full sandbox for CIS 6 probably it will be "fixed"
They are already talking about CIS 2012 so it must be around the corner

An interesting test about CIS 5.8 BETA http://forums.comodo.com/beta-corner....html;msg0#new
__________________
Comodo Internet Security (No AV)
ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI
Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/

Last edited by lordraiden : August 5th, 2011 at 05:46 AM.
  #183  
Old August 5th, 2011, 12:17 PM
jasonbourne's Avatar
jasonbourne jasonbourne is offline
Frequent Poster
 
Join Date: Aug 2010
Posts: 227
Default Re: COMODO Internet Security 5.x Thread

Very nice information there Hungry Man.

Quote:
Originally Posted by Hungry Man
...Both would have been blocked had I not disabled the heuristics/ other stuff.

May I ask what specifically did you disabled? I might be tampering on something that will make me vulnerable there.

Will await results for the Windows 7 test.

More reason's to wait for version 6 with utmost eagerness.
  #184  
Old August 5th, 2011, 12:18 PM
CogitoTesting CogitoTesting is offline
Frequent Poster
 
Join Date: Jul 2009
Location: Sea of Tranquility, Luna
Posts: 898
Default Re: COMODO Internet Security 5.x Thread

@ everybody

I think that CIS already got you covered. The only thing you have to do is to automatically sandbox your browser(s); even as partially limited gpcode or blackday will not be able to cause any harm whatsoever.

Thanks
__________________
Genuine Machine : On Access and On Demand Security Apparatus: Olivia, My Dearest Beloved
Fake Machine (Windows 7): Private Firewall 7, Avast Antivirus 7 (free), and BufferZone 4
  #185  
Old August 5th, 2011, 12:42 PM
cruelsister cruelsister is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Paris
Posts: 604
Default Re: COMODO Internet Security 5.x Thread

Jason- I believe HungryMan Disabled Defense Plus and just ran things in the Sandbox for testing purposes. You really don't want to do that on your main computer! Defense+ and the Sandbox work synergistically against malware, and you really want such a setup against the zero-day stuff that is currently out there.
__________________
Whom the Gods would destroy, they first make Proud
  #186  
Old August 5th, 2011, 01:48 PM
kjdemuth's Avatar
kjdemuth kjdemuth is online now
Very Frequent Poster
 
Join Date: Jul 2005
Location: Boston, MA
Posts: 2,387
Default Re: COMODO Internet Security 5.x Thread

That's why I'm running sandboxie along with CIS. Not much getting through that combo.
__________________
Realtime:
WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS.
On-Demand:
MBAM+EAM
Hitman pro (Scans daily)
  #187  
Old August 5th, 2011, 01:59 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by lordraiden
Have you report this "problem"?
Anyway since they are planning a full sandbox for CIS 6 probably it will be "fixed"
They are already talking about CIS 2012 so it must be around the corner

An interesting test about CIS 5.8 BETA http://forums.comodo.com/beta-corner....html;msg0#new
Black-Day was reported to them a long time ago. I may let them know it's still an issue.

Quote:
Originally Posted by jasonbourne
Very nice information there Hungry Man.



May I ask what specifically did you disabled? I might be tampering on something that will make me vulnerable there.

Will await results for the Windows 7 test.

More reason's to wait for version 6 with utmost eagerness.
I disabled literally everything except for sandboxing.

Quote:
Quote:
Originally Posted by CogitoTesting
@ everybody

I think that CIS already got you covered. The only thing you have to do is to automatically sandbox your browser(s); even as partially limited gpcode or blackday will not be able to cause any harm whatsoever.

Thanks
Unfortunately you can't autosandbox both Chrome and its plugins or they both crash. I'd rather sandbox Java than Chrome.

Also, if you were to autosandbox your browser and use NONE of CIS's other defenses than blackday would still break free and infect you.
__________________
  #188  
Old August 5th, 2011, 03:37 PM
aigle's Avatar
aigle aigle is online now
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by Hungry Man
I didn't bother posting the partially limited results as they are the same. No infection from GPCode on this machine.

I'll try on Windows 7 later.
Gpcode will not give you infected executables. Don,t scan with mBAM. Just look for the files encrypted by gpcode. You will find them even if gpcode is sandboxed aspcode bypasses CIS sandbox( did not test this beta though).

Did you specifiaclly looked for these encrypted files?
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #189  
Old August 5th, 2011, 03:37 PM
aigle's Avatar
aigle aigle is online now
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by CogitoTesting
@ everybody

I think that CIS already got you covered. The only thing you have to do is to automatically sandbox your browser(s); even as partially limited gpcode or blackday will not be able to cause any harm whatsoever.

Thanks
It will not. Blackday and probably gpode bypass the sandbox of CIS.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #190  
Old August 5th, 2011, 03:38 PM
aigle's Avatar
aigle aigle is online now
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by cruelsister
Jason- I believe HungryMan Disabled Defense Plus and just ran things in the Sandbox for testing purposes.
Sure he did not otherwise there is no fun in testing the sandbox as sandbox doesn,t even work if you disable the defence plus.
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #191  
Old August 5th, 2011, 03:45 PM
mhl6493 mhl6493 is offline
Frequent Poster
 
Join Date: Apr 2010
Location: Tennessee
Posts: 200
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by kjdemuth
That's why I'm running sandboxie along with CIS. Not much getting through that combo.

+1
  #192  
Old August 5th, 2011, 03:46 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

I didn't disable defense+. Just the other modules in it that didn't include autosandboxing.

I thought that gpcode changed the desktop background? I'll try it again this time looking for the specific patched files. Which ones should I be checking and for what?

EDIT: I see from your old test. I'll try it now.

I'm not seeing any changes to .txt files.
__________________

Last edited by Hungry Man : August 5th, 2011 at 04:11 PM.
  #193  
Old August 5th, 2011, 04:21 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

An interesting find. Manually sandboxing black-day (through teh defense security policy) as anything, including partially limited, will break it/ stop it from infecting.

The only difference between the auto and manual is that auto does not virtualize. This function is coming in V6.

So in V6 we'll have the fix to this.
__________________
  #194  
Old August 5th, 2011, 04:41 PM
harsha_mic harsha_mic is offline
Frequent Poster
 
Join Date: Mar 2009
Location: India
Posts: 276
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by Hungry Man
An interesting find. Manually sandboxing black-day (through teh defense security policy) as anything, including partially limited, will break it/ stop it from infecting.

The only difference between the auto and manual is that auto does not virtualize. This function is coming in V6.

So in V6 we'll have the fix to this.
thanks for confirming this.
I used to have this belief tht manual sandbox would stop infecting the machine from this threat..
Yes, Manual Sandbox does actual virtualizing, whereas Auto Sandboxing applies some kind of restrictions depending on the level set.

Thanks,
Harsha.
__________________
Laptop - Win 8 - ESS 7 Beta
Desktop - Win 7 - NOD32 AV v5 and Comodo
  #195  
Old August 5th, 2011, 04:51 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

Autosandboxing only has partial virtualization. This is the same for all levels (partially limited through untrusted) and the only thing that changes is what further security methods are forced onto the program (I'd love more details on what these methods are.)

Manual sandboxing has full virtualization of the file system/ registry as well as the standard levels of restrictions. Even Partially Limited will give you full virtualization so on it's own it's very powerful.
__________________
  #196  
Old August 6th, 2011, 08:48 AM
cruelsister cruelsister is offline
Frequent Poster
 
Join Date: Nov 2007
Location: Paris
Posts: 604
Default Re: COMODO Internet Security 5.x Thread

Kind of off topic, but as I temporarily had a spare Malware Box I installed an AV solution that must go unnamed (no a vs b comparison here!) and did testing on it. Not very pretty results at all. Maybe they should make the icon dance.


-http://www.youtube.com/watch?v=rrtFwmunj3U-
__________________
Whom the Gods would destroy, they first make Proud

Last edited by cruelsister : August 6th, 2011 at 10:45 AM.
  #197  
Old August 6th, 2011, 10:05 AM
NSG001's Avatar
NSG001 NSG001 is offline
Frequent Poster
 
Join Date: Jul 2006
Location: London, Innit!
Posts: 218
Thumbs up Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by cruelsister
I installed an AV solution that must go unnamed (no a vs b comparison here!) and did tested on it. Not very pretty results at all. Maybe they should make the icon dance.


-http://www.youtube.com/watch?v=rrtFwmunj3U-

PMSL
  #198  
Old August 6th, 2011, 03:07 PM
jasonbourne's Avatar
jasonbourne jasonbourne is offline
Frequent Poster
 
Join Date: Aug 2010
Posts: 227
Default Re: COMODO Internet Security 5.x Thread

Quote:
Originally Posted by aigle
Sure he did not otherwise there is no fun in testing the sandbox as sandbox doesn,t even work if you disable the defence plus.


Quote:
Originally Posted by Hungry Man
I didn't disable defense+. Just the other modules in it that didn't include autosandboxing.

@aigle/Hungry Man,

A minute ago I was confused by the "D+ disabling"..nice there

So indeed gpcode/blackday is still a factor until full virtualization in version 6.

Awaiting W7 results
  #199  
Old August 6th, 2011, 04:33 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: COMODO Internet Security 5.x Thread

Well... if a 0day version of blackday came out it would still be caught by the heuristics... but if it were modified to get around that somehow you'd be boned without an extra layer of defense.
__________________
  #200  
Old August 6th, 2011, 05:52 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,849
Default Re: COMODO Internet Security 5.x Thread

extra layer like what hungryman?any recomendation man?thanks
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:51 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums