- Dec 23, 2014
- 8,513
I am not sure if Comodo can stop EternalBlue & DoublePulsar worm remote attack. There are some reasons for that, so I opened the new thread:
Is that true, that default deny security solutions can stop the EternalBlue & DoublePulsar attacks?
EternalBlue worm drops DLLs on disk of target machine, but they are injected in Ring 0, so any program can have problems with catching this. The injection process of DoublePulsar Dll is known (see the above link), and it is very unusual. If the EternalBlue uses the similar technique, then things are even worse.
It would be helpful if someone could perform the metasploit remote attack (with EternalBlue & DoublePulsar) directed to the machine secured by CF.
Is that true, that default deny security solutions can stop the EternalBlue & DoublePulsar attacks?
EternalBlue worm drops DLLs on disk of target machine, but they are injected in Ring 0, so any program can have problems with catching this. The injection process of DoublePulsar Dll is known (see the above link), and it is very unusual. If the EternalBlue uses the similar technique, then things are even worse.
It would be helpful if someone could perform the metasploit remote attack (with EternalBlue & DoublePulsar) directed to the machine secured by CF.
Last edited: