App Review Comodo FW bypass malware the sandbox (sandbox hips off + on) and voodooshield (autopilot)

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Davidov

Level 10
Thread author
Verified
Well-known
Sep 9, 2012
470
[Quote = "Umbra, post: 559.402, členka: 178"]. Zakázat políčko skenování v nastaveni VS, byste Meli mit řádku [/ quote]
What developer of VS say about this:

VoodooShield ?

Here, I have switched to Comodo HIPS, sandbox, etc. voodooshield and locked into lock down mode and the same succumbed .-)
In the case six minutes.

 

hamo

Level 10
Verified
Well-known
Mar 30, 2014
468
[Quote = "Umbra, post: 559.402, členka: 178"]. Zakázat políčko skenování v nastaveni VS, byste Meli mit řádku [/ quote]


Here, I have switched to Comodo HIPS, sandbox, etc. voodooshield and locked into lock down mode and the same succumbed .-)
In the case six minutes.



keep in mind, VS will auto allow sandboxed processes from other security apps (Comodo in this case), unless the Parent Process feature setting is disabled in VS... so if you are going to test VS, please do it properly. Of course, when tested with Comodo not installed, VS blocked the file perfectly.

http://www.wilderssecurity.com/threads/voodooshield.313706/reply?quote=2628048
 
H

hjlbx

keep in mind, VS will auto allow sandboxed processes from other security apps (Comodo in this case), unless the Parent Process feature setting is disabled in VS... so if you are going to test VS, please do it properly. Of course, when tested with Comodo not installed, VS blocked the file perfectly.

http://www.wilderssecurity.com/threads/voodooshield.313706/reply?quote=2628048

VS intercepts Thingthing.exe process first; sandboxing by CIS comes later\after. @Davidov selected Block in VS alert.

That is what video clearly shows...
 

Azure

Level 28
Verified
Top Poster
Content Creator
Oct 23, 2014
1,712
It always bemuses me that with particular softs it is always the fault of the person who reports something or makes a video. That their testing is the problem\defective - always.

It's a pattern...
Which is why I suggested to test it with only VoodooShield. Cause I feel if not, people are gonna keep arguing "it's bypassed" and "no, it's isn't".

You guys are already on Page 5...
 

hamo

Level 10
Verified
Well-known
Mar 30, 2014
468
I test the file now , VS + Comodo

I explosive all VS files and process from Comodo ( Firewall + HIPS )

2016-10-31_02h13_00.png

2016-10-31_02h14_50.png
 

Davidov

Level 10
Thread author
Verified
Well-known
Sep 9, 2012
470
At this time it is useless to test again voodooshield Due to a change detection on VirusTotal from 0% thus the percentages for VoodooAi. A different approach of the product to the sample than yesterday. It will not authentic.


"Like antivirus virus yesterday walking around today, but you ma in the database and blocks but yesterday it failed."


And thank you all for watching and comments and insights thanks .-)))
 
D

Deleted member 178

VS allow sandboxed processes and all its "Parent Process"

May he test again but disable "Parent Process feature setting" in VS.

He didn't so there was one of the flaw of the test.

@Davidov - you should point it out in the video.

But he didn't. it is the free version, you can't disable the Parent process feature. So VS let everything that comodo allow to execute. so if Comodo (or else) fail , VS will fail. When i setup VS , this feature is the first thing i disable among others.
 
Last edited by a moderator:

cruelsister

Level 42
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,147
I'm really curious as to what is happening here. If you note the Killswitch results in my video versus the Killswitch settings in David's video in Post 77 above (the part 2 video) you will see that in mine running the file results in a Fully Virtualized restriction and Virtualization is Enabled, whereas in David's there is no Restriction and Virtualization shows up as being Disabled.

As the settings that Davidov uses are totally fine and are actually more restrictive than those used in my video, I wonder if having VS installed on the same system is resulting in Comodo not being able to utilize the sandbox.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top