![]() |
|
#176
|
||||
|
||||
|
Blackday successfully bypassed both restricted and untrusted sandboxes. GPCode did not manag to bypass Untrusted nor Partially Limited.
Both would have been blocked had I not disabled the heuristics/ other stuff. Screenies in the next few posts.
__________________
Last edited by Hungry Man : August 4th, 2011 at 07:34 PM. |
|
#177
|
||||
|
||||
|
More. In order.
Next post will include GPCode. This concludes the Black-Day test. edit oops
__________________
|
|
#178
|
||||
|
||||
|
GPCode.
Last pic is the system info.
__________________
|
|
#179
|
||||
|
||||
|
I didn't bother posting the partially limited results as they are the same. No infection from GPCode on this machine.
I'll try on Windows 7 later.
__________________
|
|
#180
|
||||
|
||||
|
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268 |
|
#181
|
||||
|
||||
|
Again, to reiterate, the default settings of Comodo WILL block this. It's just that the sandbox was not enough on its own.
__________________
|
|
#182
|
||||
|
||||
|
Quote:
Have you report this "problem"? Anyway since they are planning a full sandbox for CIS 6 probably it will be "fixed" They are already talking about CIS 2012 so it must be around the corner An interesting test about CIS 5.8 BETA http://forums.comodo.com/beta-corner....html;msg0#new
__________________
Comodo Internet Security (No AV) ZeroVulnerabilityLabs ExploitShield | Trusteer Rapport | TrueCrypt | EMET | Secunia PSI Firefox: Addon security and privacy collection: https://addons.mozilla.org/en-us/fir...den/favorites/ Last edited by lordraiden : August 5th, 2011 at 05:46 AM. |
|
#183
|
||||
|
||||
|
Very nice information there Hungry Man.
Quote:
May I ask what specifically did you disabled? I might be tampering on something that will make me vulnerable there. Will await results for the Windows 7 test. More reason's to wait for version 6 with utmost eagerness. |
|
#184
|
|||
|
|||
|
@ everybody
I think that CIS already got you covered. The only thing you have to do is to automatically sandbox your browser(s); even as partially limited gpcode or blackday will not be able to cause any harm whatsoever. Thanks
__________________
Genuine Machine : On Access and On Demand Security Apparatus: Olivia, My Dearest Beloved Fake Machine (Windows 7): Private Firewall 7, Avast Antivirus 7 (free), and BufferZone 4 |
|
#185
|
|||
|
|||
|
Jason- I believe HungryMan Disabled Defense Plus and just ran things in the Sandbox for testing purposes. You really don't want to do that on your main computer! Defense+ and the Sandbox work synergistically against malware, and you really want such a setup against the zero-day stuff that is currently out there.
__________________
Whom the Gods would destroy, they first make Proud |
|
#186
|
||||
|
||||
|
That's why I'm running sandboxie along with CIS. Not much getting through that combo.
__________________
Realtime: WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS. On-Demand: MBAM+EAM Hitman pro (Scans daily) |
|
#187
|
||||
|
||||
|
Quote:
Quote:
Quote:
Also, if you were to autosandbox your browser and use NONE of CIS's other defenses than blackday would still break free and infect you.
__________________
|
|
#188
|
||||
|
||||
|
Quote:
Did you specifiaclly looked for these encrypted files?
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#189
|
||||
|
||||
|
Quote:
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#190
|
||||
|
||||
|
Quote:
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#191
|
|||
|
|||
|
Quote:
+1 |
|
#192
|
||||
|
||||
|
I didn't disable defense+. Just the other modules in it that didn't include autosandboxing.
I thought that gpcode changed the desktop background? I'll try it again this time looking for the specific patched files. Which ones should I be checking and for what? EDIT: I see from your old test. I'll try it now. I'm not seeing any changes to .txt files.
__________________
Last edited by Hungry Man : August 5th, 2011 at 04:11 PM. |
|
#193
|
||||
|
||||
|
An interesting find. Manually sandboxing black-day (through teh defense security policy) as anything, including partially limited, will break it/ stop it from infecting.
The only difference between the auto and manual is that auto does not virtualize. This function is coming in V6. So in V6 we'll have the fix to this.
__________________
|
|
#194
|
|||
|
|||
|
Quote:
I used to have this belief tht manual sandbox would stop infecting the machine from this threat.. Yes, Manual Sandbox does actual virtualizing, whereas Auto Sandboxing applies some kind of restrictions depending on the level set. Thanks, Harsha.
__________________
Laptop - Win 8 - ESS 7 Beta Desktop - Win 7 - NOD32 AV v5 and Comodo |
|
#195
|
||||
|
||||
|
Autosandboxing only has partial virtualization. This is the same for all levels (partially limited through untrusted) and the only thing that changes is what further security methods are forced onto the program (I'd love more details on what these methods are.)
Manual sandboxing has full virtualization of the file system/ registry as well as the standard levels of restrictions. Even Partially Limited will give you full virtualization so on it's own it's very powerful.
__________________
|
|
#196
|
|||
|
|||
|
Kind of off topic, but as I temporarily had a spare Malware Box I installed an AV solution that must go unnamed (no a vs b comparison here!) and did testing on it. Not very pretty results at all. Maybe they should make the icon dance.
-http://www.youtube.com/watch?v=rrtFwmunj3U-
__________________
Whom the Gods would destroy, they first make Proud Last edited by cruelsister : August 6th, 2011 at 10:45 AM. |
|
#197
|
||||
|
||||
|
Quote:
PMSL ![]() |
|
#198
|
||||
|
||||
|
Quote:
Quote:
@aigle/Hungry Man, A minute ago I was confused by the "D+ disabling"..nice there ![]() So indeed gpcode/blackday is still a factor until full virtualization in version 6. Awaiting W7 results ![]() |
|
#199
|
||||
|
||||
|
Well... if a 0day version of blackday came out it would still be caught by the heuristics... but if it were modified to get around that somehow you'd be boned without an extra layer of defense.
__________________
|
|
#200
|
||||
|
||||
|
extra layer like what hungryman?any recomendation man?thanks
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268 |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|