Stuxnet .(lnk exploit malware) versus HIPS

Discussion in 'other anti-malware software' started by aigle, Apr 20, 2011.

Thread Status:
Not open for further replies.
  1. shadek

    shadek Registered Member

    You're conducting some very interesting tests. Could you please share the hash of the file you're doing the tests with? I think I might be in possession of it!
     
  2. aigle

    aigle Registered Member

    To all, pls I aologize in advance that I can,t do tests on request. Anyone interested can PM me to get the sample( just PM, don,t ask openly in the thread) and do their own testing. Hope you people will not mind! :)
     
  3. aigle

    aigle Registered Member

    1- No outgoing alert with FW in safe mode.
    2- Windows XP Home SP2 not fully patched
     
  4. aigle

    aigle Registered Member

    Yes, just like Comodo v 3 but practically you can,t use these settings, totally impractical.
     
  5. aigle

    aigle Registered Member

    MD5 055a3421813caf77e1387ff77b2e2e28
     
  6. SUPERIOR

    SUPERIOR Registered Member

    umm...i run comodo version 5.3.50343.1237 on xp sp2 and it stopped the attack partially if it could be said so
    look pictures
     

    Attached Files:

    Last edited: Apr 21, 2011
  7. aigle

    aigle Registered Member

    Will try later with Allah,s will. I don,t expect it will pass as rundll32.exe is not involved here at all.
     
  8. aigle

    aigle Registered Member

    Any thing in Comodo log?

    May be it,s due to the way Comodo deals with shell32.dll, and not due to interception of malicious dll itself by Comodo. Just a wild guess.
     
  9. arran

    arran Registered Member

    Yes of course it would if configured correctly.


    Anti executable 4 would also pass, I believe AE4 intercepts dll's now
     
  10. Syobon

    Syobon Registered Member

  11. aigle

    aigle Registered Member

    Same with OA even if you allow the alerts!
     
  12. harsha_mic

    harsha_mic Registered Member

    i tested CFW v5.3 thru sandboxie. I can't see it loading dll except the attached alert from the execution of malware...
    I don't see malicious dll being loaded. I have verified with gmer and process explorer.
     

    Attached Files:

  13. aigle

    aigle Registered Member

    I don,t think that it,s a good way to test Comodo with malware running inside SBIE.

    However I can confirm that if I run it with Comodo, malicious dll is loaded but it doesn,t loads further malicious modules( as shown by gmer- see the post above by 'superior'). Same is true if I run it with OA and allow all prompts. I don,t know what does all this mean.
     
    Last edited: Apr 22, 2011
  14. harsha_mic

    harsha_mic Registered Member

    thanks for the inputs aigle.
    Yes, i know that testing malware in sbie would not correctly tell the protection efficacy of comodo.
    Are you testing comodo in virtualbox?

    Thanks,
    Harsha
     
  15. Kernelwars

    Kernelwars Registered Member

    can anyone plz test spy shelter against this? Thanks
     
  16. SUPERIOR

    SUPERIOR Registered Member

    predictable result ....epic failed :D
    i tested it i mean
     
  17. Kernelwars

    Kernelwars Registered Member

    wow . :(
     
  18. aigle

    aigle Registered Member

    No, on real system with CTM.
     
  19. Worter

    Worter Registered Member

    Comodo fails it?
    Do not worry. Microsoft have already fixed the bug :)
    Just install latest update for your OS.
    I have Win7 SP1 64 bit. No dll was injected. Previously it was possible to inject dll
     
    Last edited: Apr 22, 2011
  20. kwismer

    kwismer Registered Member

    are you offering a benign exploit of the relevant vulnerability here, or offering to distribute the actual stuxnet malware to anyone who asks in private?
     
  21. aigle

    aigle Registered Member

    Both, keep rest to PMs. :)
     
  22. Zyrtec

    Zyrtec Registered Member


    Hi,


    Did you test Comodo using settings per this YouTube video? :


    http://www.youtube.com/watch?v=D9BPONNYk_g



    I ask because I'm running just the firewall (not the AV) alongside with ESET NOD32 v4.2 on Windows 7 Pro 32-bit and I'm kind of curious if their HIPS let this worm through.

    Thanks


    Carlos
     
  23. shadek

    shadek Registered Member

    Not to sound harsh, but if you're not on a pirated copy of Windows which does not allow you to update it, you're already safe from this infection. I rarely get into these kind of discussions any longer... just my two cents.
     
  24. Ranget

    Ranget Registered Member


    :-* it allows update

    sorry for the bad news
     
  25. shadek

    shadek Registered Member

    I'm not sure I understand the meaning of your post. What is the bad news? That (your?) a pirated copy of Windows allowed you to update? Or that the actual bad news is that the infection is still valid for updated OSs? I'm not aware of that this exploit works on updated Windows machines.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice