My first time installing Comodo, I used the default installation so obviously Geekbuddy was installed. Nowadays, however, I make sure to use custom install and deselect everything that isn't Comodo Firewall.
Another case of antivirus software gone horribly wrong
Google Project Zero security researcher Tavis Ormandy has discovered that one of Comodo's tech support tools packed with many of the company's security products leaves the door open for attackers to connect with admin privileges on the user's PC.
Ormandy noticed users complaining online about a VNC server that started on their Windows systems where they installed Comodo Antivirus, Comodo Firewall, or Comodo Internet Security.
Comodo tech support tool at the core of the problem
The researcher investigated the issue further and discovered that to blame for this problem was a remote desktop tool called GeekBuddy, which Comodo was bundling with its security software.
GeekBuddy was used by its tech support staff to debug problematic computers from afar. The application allowed Comodo staff to connect from remote locations by opening a VNC server on the user's PC.
If the user was connected to the Internet, anyone could access the user's computer using this backdoor. If the computer was offline, anyone could do the same from a local network.
GeekBuddy versions had no password, or used a weak one
In GeekBuddy's first iterations, the tool didn't even include a password, meaning anyone could just connect to the victim's PC using an IP port combination.
Users complained about this problem, and in later GeekBuddy versions, Comodo introduced a password. The Google researcher says that this password is easy to guess, being composed of data stored in each computer's Windows Registry.
"The password is simply the first 8 characters of SHA1 (Disk.Caption+Disk.Signature+Disk.SerialNumber+Disk.TotalTracks)," Ormandy revealed.
Since Comodo installed GeekBuddy with full admin privileges, any attacker connecting through Comodo's support tool would have had full control over the system.
To prove his point, Ormandy provided a simple three-line exploit that discovered a workstation's SHA1 string, cut the first eight digits, and supplied them to the attacker.
The researcher informed Comodo of the issue on January 19, and subsequently released GeekBuddy 4.25.380415.167 to address the reported issues.
Mr. Ormandy had previously probed Comodo's software when it discovered that the antivirus maker was also shipping an insecure version of the Chromium browser, dubbed internally Chromodo. Mr. Ormandy is famous for discovering security issues in many high-profile security companies like Avast, AVG, Malwarebytes, Trend Micro, FireEye, and many others.
No response from Comodo yet. Let's hope they're not just going to leave everyone vulnerable until the 90day clock runs out.
January 26, 2016
Well, Comodo wins as the most braindead and shady software I've seen so far. If you work for Comodo, please contact me. — Tavis Ormandy (@taviso)
January 22, 2016
Comodo Internet Security installs a VNC server with predictable password by default.
The only redeeming feature about Comodo is that it's "free"
I used to use it years ago when it was somewhat okay,but the product now is unusable,at least for me!!
The only redeeming feature about Comodo is that it's "free"
I used to use it years ago when it was somewhat okay,but the product now is unusable,at least for me!!
COMODO needs to fix some long-standing, serious bugs.
If they can accomplish that, then it will be a much better product.
It's not like other vendors haven't experienced the same with their products, it is just that they have somehow managed to fix the reported issues - whereas COMODO has not.
Despite all of this, COMODO in default Proactive Security settings is decent physical system protection.
COMODO & fanboys mis-treated and\or ignored @Umbra, so his attitude toward COMODO, Melih and their products is understandable.
Besides, he sees that COMODO product fixes are much slower than average and the bloat is completely unnecessary.
COMODO needs to fix some long-standing, serious bugs.
If they can accomplish that, then it will be a much better product.
It's not like other vendors haven't experienced the same with their products, it is just that they have somehow managed to fix the reported issues - whereas COMODO has not.
Despite all of this, COMODO in default Proactive Security settings is decent physical system protection.
COMODO & fanboys mis-treated and\or ignored @Umbra, so his attitude toward COMODO, Melih and their products is understandable.
Besides, he sees that COMODO product fixes are much slower than average and the bloat is completely unnecessary.
I got banned and a lot of (well) arrogant comments, I think their forum is byfar the worse. The all think they run the AV/malware world, and Melih is god.
cruelsister has the firewall figured out to where anyone can use it and it is all you could want with her settings, no popups and no infections. Coupled with adguard using her advice and my 4 yr. old twins don't have problems. I don't have to deal with comodo dev. or support ,simple protection must be to boring . It doesn't need micro-managed in my opinion. I rarely open comodo threads anymore unless cruelsister is involved because she is the only one who seems to be able to make it work . The rest seems to be salt in a wound.
I got banned and a lot of (well) arrogant comments, I think their forum is byfar the worse. The all think they run the AV/malware world, and Melih is god.
- no-skill fanboys telling you that what you said i false...
- bugs/flaws present across versions since years...
- bloats coming from the same no-skill fanboys, they have no skills so of course asking for bloat features...
- false promise/announcement of so-called revolutionary products...
- childish reactions from the CEO...
- forum mods locking "embarrassing" topics.
GeekBuddy has been an on-going annoyance, once it was HopSurf, PrivDog and now this. I would applaud Comodo for the discontinuation of GeekBuddy greyware, but I doubt it.
cruelsister has the firewall figured out to where anyone can use it and it is all you could want with her settings, no popups and no infections. Coupled with adguard using her advice and my 4 yr. old twins don't have problems. I don't have to deal with comodo dev. or support ,simple protection must be to boring . It doesn't need micro-managed in my opinion. I rarely open comodo threads anymore unless cruelsister is involved because she is the only one who seems to be able to make it work . The rest seems to be salt in a wound.
3 years ago I made a video about GeekBuddy.
Fresh Windows 8 x32.
I install Comodo antivirus with all the crap that comes along with it , start Comodo Dragon and it crash.
I call GeekBuddy for help...then he sad that my PC is infected...LOL (fresh Win 8).
Rest is in the video.