發新話題
打印

[分享] Comodo release 5 new security tests

Comodo release 5 new security tests

Comodo developers have created a new set of security tests. The Comodo HIPS and Firewall Leak Test Suite contains five new tests that simulate a range of dangerous exploits – including Root Kits, Background Intelligent Transfer attacks and process injection attacks.

The suite is available for download here:

http://download.comodo.com/securitytests/CLT.zip  (extract zip to local drive and open clt.exe )

I've also attached the zip file to this post

Developer Notes:

Rootkit Installation 1 - Loads a driver in via ZwSetSystemInformation API. A very old, known and effective way to install a rootkit.

Rootkit Installation 2 - Loads driver by overwriting a standard driver (beep.sys) and starting it with service control manager (e.g. Trojan.Virantix.B).

DLL Injection 1 - Injects DLL into trusted process (svchost.exe) by injecting APC on LoadLibraryExA with "dll.dll" as a param. The string "dll.dll" is not written into process memory, it's from the ntdll.dll export table which has the same address in all processes. The APC is injected into second thread of the svchost.exe which is always in alertable state.

DLL Injection 2 - An old technique. The DLL is injected via remote thread creation in the trusted process, without using WriteProcessMemory.

BITS Hijack - Downloads a file from the internet using "Background Intelligent Transfer Service" which acts from the trusted process (svchost.exe)

The tests can be automatically run in sequence by selecting 'Run all Tests' or run individually. The GUI provides clear, color coded indication on whether target systems are vunerable or protected.

http://forums.comodo.com/leak_te ... tests-t21917.0.html

TOP

TOP

dll注入KIS 8.0.0.229失敗
已經回報官方
Lawliet's blog
Folding@home with GPGPU集中討論串,大家一起來努力朝著全球制霸的目標邁進!

TOP



mamutu+fortknox firewall all failed  

TOP



Dynamic Security Agent only 好过刚才一点

TOP

COMODO FIREWALL 今天又不懂要更新甚么了
       
Re: will be today available the update
« Reply #7 on: Today at 08:50:56 AM »
        Reply with quote
the guys are working on the update..
it will take between 3-6 hours all being well...( we do have a lot of procedures we have to follow for any updates as we follow strict policies for compliancy, security etc etc)

thanks
Melih
http://forums.comodo.com/feedbac ... pdate-t21936.0.html

TOP

那樣子寫真的沒人知道更新了些什麼
Lawliet's blog
Folding@home with GPGPU集中討論串,大家一起來努力朝著全球制霸的目標邁進!

TOP

那我就等..到它... UPDATE 了

TOP

Re: will be today available the update
« Reply #12 on: Today at 02:34:53 PM »
        Reply with quote
unfortunately, we missed the launch window and has been re-scheduled till tomorrow.. sorry guys...

Melih
http://forums.comodo.com/feedbac ... pdate-t21936.0.html

TOP

BITS Hijack 在小弟的虛擬機下執行會導致錯誤

ProSecurity 1.43 (預設正常模式) :
Rootkit Installation 1 : Pass
Rootkit Installation 2 : Fail
Dll Injection 1 : ProSecurity 1.43 會提示使用者偵測到危險行為, 但 Comodo Leak Test 停留在 Please Wait 階段
Dll Injection 2 : Pass
BITS Hijack : 無法測試

TOP

KIS 8.0.0.343 ALL PASS
手動可攔截DLL注入
完畢
Lawliet's blog
Folding@home with GPGPU集中討論串,大家一起來努力朝著全球制霸的目標邁進!

TOP

Y一说到ALL PASS 我又装了KIS 8.0.0.343来玩了

TOP

這麼說應該太小心眼了....〝這應該不會是針對某家free的產品而設計的吧〞
Online Armor...
栗子熟了....趕快吃吧...

TOP

發新話題