I tried the ZAbypass exe but im a little confused because im not sure got the full gist of what it was supposed to prove a vulnerability. on executing i was transferred to a web page which didnt confirm or deny what had occurred.?
hope this has been of some use 
Yes it has been very helpful, it confirms that CPF is vulnerable to this DDE exploit also. I started a thread at the Outpost forums as it too is vulnerable, there is a lot of feedback there.
Bypassing Personal Firewall - Proof-of-ConceptIf you arrived at the website without your firewall or A
2 intervening, then your firewall has been bypassed (what browser did you use). You will have noticed that when you ran zabypass.exe there was a string of text (which you can change), that string is replicated at the PofC test page you were sent to.
This is a demo page and has been hosted to demonstrate how a personal firewall can be bypassed and a malicious program can communicate with its master by injecting the data via other trusted programs (here it is IE) in the system. No information are logged during the demo other than the hit count.
Obviously this could be more than a harmless string of meaningless text.
If you don't have your browser started then it is likely that it will detect this PofC, however if it is already started which is very likely in real life (and it is a Multi Tab browser) then it is very likely to get past.
Re: breakout.exe
As a matter of fact there are more programs that can bypass personal firewalls. Volker Birk, a member of the respected German Chaos Computer Club (CCC), presented a small program that establishes an internet connection, and Outpost (and probably any other PFW) simply doesn't see it.
The source code for the IE-version can be found on http://www.dingens.org/breakout.c , the executable on http://www.dingens.org/breakout.exe, the source code for Firefox on http://www.dingens.org/breakout-mozilla-firefox.c and the respective executable on http://www.dingens.org/breakout-mozilla-firefox.exe .
So breakout doesn't seem to be as flexible as zabypass which uses your default browser, breakout.exe is browser specific. Since a very large majority still use IE as their default browser it would work (bypass the firewall) for most people.