|
Cloussau
|
 |
« on: October 21, 2005, 07:02:37 AM » |
|
Ok here are a few screenshots of the gui for your interest first one (slide2) is the basic front page which has tabs for all the fine detail info the slider on the middle left is set at custom which means user defined rules in force oops i hope you guys dont mind downloading the pics . as you can tell this is not my field slide 5 is the front page with 4 changes made to 4 tabs as indicated by arrows
|
|
|
|
« Last Edit: October 21, 2005, 07:08:27 AM by Cloussau »
|
Logged
|
sys- p4 3.0D , 1024mb ddram ;arsenal :Avast! Firefox / adblock /noscript : win xp/pro/sp3
|
|
|
|
Cloussau
|
 |
« Reply #1 on: October 21, 2005, 07:11:23 AM » |
|
next 3 pics are of gui with two of the three tabs down left side depressed and finally a pic of the alert popups
|
|
|
|
« Last Edit: October 21, 2005, 07:14:43 AM by Cloussau »
|
Logged
|
sys- p4 3.0D , 1024mb ddram ;arsenal :Avast! Firefox / adblock /noscript : win xp/pro/sp3
|
|
|
|
Cloussau
|
 |
« Reply #2 on: October 21, 2005, 07:20:55 AM » |
|
last pic thank god Eddy will be freaking out 
|
|
|
|
|
Logged
|
sys- p4 3.0D , 1024mb ddram ;arsenal :Avast! Firefox / adblock /noscript : win xp/pro/sp3
|
|
|
|
Cloussau
|
 |
« Reply #3 on: October 21, 2005, 07:50:59 AM » |
|
here`s the "sheilds up" opinion in case anyone is interested
Your Internet port 139 does not appear to exist! One or more ports on this system are operating in FULL STEALTH MODE! Standard Internet behavior requires port connection attempts to be answered with a success or refusal response. Therefore, only an attempt to connect to a nonexistent computer results in no response of either kind. But YOUR computer has DELIBERATELY CHOSEN NOT TO RESPOND (that's very cool!) which represents advanced computer and port stealthing capabilities. A machine configured in this fashion is well hardened to Internet NetBIOS attack and intrusion. Unable to connect with NetBIOS to your computer. All attempts to get any information from your computer have FAILED. (This is very uncommon for a Windows networking-based PC.) Relative to vulnerabilities from Windows networking, this computer appears to be VERY SECURE since it is NOT exposing ANY of its internal NetBIOS networking protocol over the Internet. I must say in addittion that I have a 4 port router between helping out
for those wanting to know the resource usage see pic
|
|
|
|
« Last Edit: October 21, 2005, 08:08:44 AM by Cloussau »
|
Logged
|
sys- p4 3.0D , 1024mb ddram ;arsenal :Avast! Firefox / adblock /noscript : win xp/pro/sp3
|
|
|
|
DavidR
|
 |
« Reply #4 on: October 21, 2005, 08:07:36 AM » |
|
It certainly looks colourful and I like the identification of the parent application in the Outbound Connection alert. It would be interesting as to how it copes with the leek tests and the zabypass.exe and breakout.exe tests that have been used as Proof of Concepts of bypassing the firewall.
|
|
|
|
|
Logged
|
Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ avast! free 5.0.396/ Outpost Firewall Pro 2009/ Firefox 3.6, NoScript, RequestPolicy/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol Plus/ Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
|
|
|
|
sZc
|
 |
« Reply #5 on: October 21, 2005, 11:39:12 AM » |
|
It certainly looks colourful and I like the identification of the parent application in the Outbound Connection alert. It would be interesting as to how it copes with the leek tests and the zabypass.exe and breakout.exe tests that have been used as Proof of Concepts of bypassing the firewall.
That's exactly why I posted this question in Cloussau's original thread dealing with Comodo firewall: http://forum.avast.com/index.php?topic=17001.msg144630#msg144630Quote by me: Now, let's get back to the topic... is there any chance you can post those screenshots any time soon ? Also, please provide some more info on how Comodo is behaving when tested with ShieldsUp! and also with TooLeaky http://tooleaky.zensoft.com/Thanks in advance Cloussau Also, Cloussau, please enable VM Size (Virtual Memory Size) in your Task Manager, so we can see real memory usage that CPF.exe uses...  Thanks !
|
|
|
|
|
Logged
|
|
|
|
|
Cloussau
|
 |
« Reply #6 on: October 21, 2005, 12:51:36 PM » |
|
ok ive done the too leaky test and because i happened to have Asquared installed alongside the intrusion test was stopped not only by A2 but also by CPF but i think it was outbound see pic and also is the other taskman screenshot
|
|
|
|
|
Logged
|
sys- p4 3.0D , 1024mb ddram ;arsenal :Avast! Firefox / adblock /noscript : win xp/pro/sp3
|
|
|
|
Cloussau
|
 |
« Reply #7 on: October 21, 2005, 12:59:05 PM » |
|
No i was wrong the too leaky alert was for incoming and when i turned A2 off I got 2 alerts from cpf which were both outgoing and incoming. seems to have everything covered 
|
|
|
|
|
Logged
|
sys- p4 3.0D , 1024mb ddram ;arsenal :Avast! Firefox / adblock /noscript : win xp/pro/sp3
|
|
|
|
DavidR
|
 |
« Reply #8 on: October 21, 2005, 01:18:21 PM » |
|
Want to try the zabypass.exe and breakout.exe tests that have been used as Proof of Concepts of bypassing the firewall. It would also be interesting to see if A 2 picks them up to. ZAbypass - Hackingspirits.com Proof-of-Concept
|
|
|
|
« Last Edit: October 21, 2005, 02:12:09 PM by DavidR »
|
Logged
|
Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ avast! free 5.0.396/ Outpost Firewall Pro 2009/ Firefox 3.6, NoScript, RequestPolicy/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol Plus/ Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
|
|
|
|
sZc
|
 |
« Reply #9 on: October 21, 2005, 01:25:55 PM » |
|
No i was wrong the too leaky alert was for incoming and when i turned A2 off I got 2 alerts from cpf which were both outgoing and incoming. seems to have everything covered  That's good to hear, really good. It looks like it deals with those things exactly as Kerio with Application Behaviour Blocking feature enabled and ZoneAlarm Pro. ZoneAlarm Freeware will not pass that test... That's really good to hear Cloussau ! Btw, In your task manager, chose Processes TAB. Now go to VIEW (dropdown menu up there) and chose SELECT COLUMNS... Now put a checkmark on Virtual Memory Size box. Click OK and now you are able to see VM Size column. Resize your Task Manager window if needed to see everything... Cheers !
|
|
|
|
|
Logged
|
|
|
|
|
Cloussau
|
 |
« Reply #10 on: October 21, 2005, 01:29:59 PM » |
|
I tried the ZAbypass exe but im a little confused because im not sure got the full gist of what it was supposed to prove a vulnerability. on executing i was transferred to a web page which didnt confirm or deny what had occurred.? getting late down here 11.30 pm and i got a 5am rise so im gonna call it quits for tonite and look at breakout exe (which i couldnt find) tomorrow . hope this has been of some use 
|
|
|
|
|
Logged
|
sys- p4 3.0D , 1024mb ddram ;arsenal :Avast! Firefox / adblock /noscript : win xp/pro/sp3
|
|
|
|
sZc
|
 |
« Reply #11 on: October 21, 2005, 01:42:40 PM » |
|
Yes of course it is useful Cloussau !
Thank you for your effort !
I see that Comodo uses little bit more resources than Kerio... KPF.exe (Kerio) is at 9 Mb VM Size... but sure it looks like a wonderful firewall... and best of all, all those features for free. ZA free doesn't protect you on all fields as we all know...
|
|
|
|
|
Logged
|
|
|
|
|
DavidR
|
 |
« Reply #12 on: October 21, 2005, 02:10:27 PM » |
|
I tried the ZAbypass exe but im a little confused because im not sure got the full gist of what it was supposed to prove a vulnerability. on executing i was transferred to a web page which didnt confirm or deny what had occurred.? hope this has been of some use  Yes it has been very helpful, it confirms that CPF is vulnerable to this DDE exploit also. I started a thread at the Outpost forums as it too is vulnerable, there is a lot of feedback there. Bypassing Personal Firewall - Proof-of-ConceptIf you arrived at the website without your firewall or A 2 intervening, then your firewall has been bypassed (what browser did you use). You will have noticed that when you ran zabypass.exe there was a string of text (which you can change), that string is replicated at the PofC test page you were sent to. This is a demo page and has been hosted to demonstrate how a personal firewall can be bypassed and a malicious program can communicate with its master by injecting the data via other trusted programs (here it is IE) in the system. No information are logged during the demo other than the hit count. Obviously this could be more than a harmless string of meaningless text. If you don't have your browser started then it is likely that it will detect this PofC, however if it is already started which is very likely in real life (and it is a Multi Tab browser) then it is very likely to get past. Re: breakout.exe So breakout doesn't seem to be as flexible as zabypass which uses your default browser, breakout.exe is browser specific. Since a very large majority still use IE as their default browser it would work (bypass the firewall) for most people.
|
|
|
|
|
Logged
|
Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ avast! free 5.0.396/ Outpost Firewall Pro 2009/ Firefox 3.6, NoScript, RequestPolicy/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol Plus/ Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
|
|
|
|
sZc
|
 |
« Reply #13 on: October 21, 2005, 02:28:10 PM » |
|
... ... Yes it has been very helpful, it confirms that CPF is vulnerable to this DDE exploit also. I started a thread at the Outpost forums as it too is vulnerable, there is a lot of feedback there. Bypassing Personal Firewall - Proof-of-ConceptIf you arrived at the website without your firewall or A 2 intervening, then your firewall has been bypassed (what browser did you use). You will have noticed that when you ran zabypass.exe there was a string of text (which you can change), that string is replicated at the PofC test page you were sent to. ... ... Exactly, and even worse Kerio fails at that test too. So it tells us something new... Comodo Firewall didn't pass that test, but it can not be classified as worse than any other better known firewall out there. For sure it passes those tests better than ZA free.
|
|
|
|
|
Logged
|
|
|
|
|
DavidR
|
 |
« Reply #14 on: October 21, 2005, 03:12:19 PM » |
|
No one is saying it is any worse than or better than any other firewall, this is an exploit that is hitting virtually all firewalls with the exclusion of ZA Pro which picks it up. Not having ZA Pro or a second system I can't fully check it with a range of browsers as I have done with Outpost Pro.
Many firewalls are able to detect it if you don't have your browser open, once open if using a tabbed browser the likelihood is it will open in a new tab without intervention from the firewall.
If IE isn't set-up to open in a new windows (reuse existing window) then it can get past that as a new occurance of the browser isn't activated and as such won't be tested by the firewall's Hidden Process checks.
|
|
|
|
|
Logged
|
Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ avast! free 5.0.396/ Outpost Firewall Pro 2009/ Firefox 3.6, NoScript, RequestPolicy/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol Plus/ Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
|
|
|
|