Help - Search - Members - Calendar
Full Version: Comodo Test 1-3
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
Rivalen
Please run this test and tell me the outcome.

http://www.personalfirewall.comodo.com/onlinetest.html

Comodo Parent Injection Leak Test Suite

I run with special testdriver Ive got from Ilya so its not ordinary 1.71 driver. I run in normal mode.

I downloaded and unzipped (WinZip). I supposed the unzipped test was also protected by DW - right? So I just doubleclicked the .exe

As I understand it this test managed to let explorer start iexplore.

Even when I ran the test explicitly as untrusted Outpost warned about a hidden process wanting outbound connection. Then a warninh window that explorer had some problem.

Afterwards my iexplore starts as trusted though DW is running and iexplore is in untrusted. Not until I reboot DW seems to work allright.

After one of the test I made I wanted to Rollback everything - the downloaded zipfile was there in files and registry tracks and was removed.

The unzipped testfile - shall I be able to see that in F&Reg Tracks?
I didnt.

With new driver I have only one or 2-3 entries in F&R T per day - before I had several 10s of entries - why the difference?

Anyhow - after Rollback - DW hangs - havnet seen that for quite a while.

Best Regards
Rivalen
Maybe I should have mailed you about this and not post here since I run a test driver.

As a nontech user I would say the test driver was no good.

I reinstalled original 1.71 over the testdriver DW-version.

With 1.71 I got all the entries in F&R Tracks also the unzipped test exe file.

The test - all 3 could not break out of the sandbox and do anything - at least as long as I waited for something to happen.

I Rolled Back - DW hanged and thats a problem - but when forced reboot all entries including the test exe file were gone - thats good! Better than with the test driver that didnt even enter the test exe into F&R Tracks.

Anyway - if some else would test and we can share results.

Best Regards
Ilya Rabinovich
I've runed all the test set examples. All of them failed against DW.

As about low level of new enties- with new driver I check IE temp files folder more accurately. Not sure about History- its path contains into HKCU and may vary (theoretically) from user to user.

The questions is: how you have unziped the test set? With built-in WinXP unzip tool or somehow else?
Rivalen
AS said I had no problems with original 1.71 river - only with test driver. Said to say I was so surprised I forgot to send you a log before I reinstalled over the test driver version.

My intention originally was to test my Firewall, but I decided to test with DW first.

I use WINZIP ver 8 something and during original 1.71 test it was running untrusted automatically as it should.
When I ran the test driver I didnt check so carefully since I didnt expect any problems.


What driver did you use for your test?

Could you Rollback all entries? Did 1.71 - or whatever you used - hang? Do you want the log for my last Rollback-hang.

Feel better with the 1.71 original driver.

Edit: Maybe you can run this test with the DW test-driver I used when first time testing?

Best Regards
Ilya Rabinovich
Ah, I see. I suppose, you have runned executable file just directly from the archive, without all its folder unzipping to hard drive?
Rivalen
Unzipped to C: Files from internet and ran the test from there.

Did you try the test driver? Any difference against aordinary 1.71 driver in this test? Did you Rollback? Was all the entries in the Rollback list with the test driver compared to ordinary 1.71? Did your Rollback hang with any of the drivers?

Best Regards
Ilya Rabinovich
Just tested this staff one more time. Had no problems with rollback and untrusted attribute inherition. Used the latest driver.
Rivalen
Latest driver" is that the DW test-driver you mailed me. If so - did also the Comodo-test .exe file show in Rollback?

Never did so for me with DW test-driver, but with default 1.71 driver all was OK except hang when Rolledback.

Will do this test again with next upgrade of DW.

Best Regards
Rivalen
Ilya, probably me again not understanding how DW is supposed to work. Tried again with 1.71 original driver.

IE untrusted - download and when download finished;

1st - from download window pressed open and winzip starts untrusted - good.

2nd - instead open explorer and doubleclick on the zip-file - winzip starts untrusted - good.

3rd - open explorer - right click on the file - choose winzip extract to - winzip starts TRUSTED - is thats the way it should be?

I thought that untrusted zip file was untrusted until I choose right click DW Run as trusted?

Pls explain.

Best Regards
Ilya Rabinovich
Ah, I see. DW supports double-click right now. As about right-click menu- I'll think some!
Rivalen
So I probably ran the test trusted by mistake or rather being so sure I knew how DW works. crying.gif

Best Regards
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.