查看: 4013|回复: 11
收起左侧

关于11月Matousec测试comodo表现的解释

[复制链接]
Magis
头像被屏蔽
发表于 2008-11-30 19:54:37 | 显示全部楼层 |阅读模式
看来大家都还是理性对待这次测试的,至少在本区是这样。官方论坛对次测试反响颇多,有几个“官人”的回复和大家分享下:
”We have reviewed the results. Dont worry. There are 3 issues to be highlighted here.

1 - There is a single bug in CIS/CFP which affects the previsous versions too. 
This bug allows CFP/CIS to fail to detect a special type of handle duplication operation. And thats why it cause CFP/CIS to fails the following tests:

Kill1.exe kill2.exe:  kill9.exe kill12.exe crash1.exe crash2.exe crash3.exe crash4.exe crash5.exe crash6.exe

Do not worry. We have fixed the bug and you will be receiving the update on Tuesday(2/12/2008).

单的说就是12月2号有新版本啦 , 会修复一些导致没通过以上项目的bug

2 - There are errors in the test report:

CFP/CIS does not fail the following tests: kill3b.exe kill3f.exe kill3e.exe kill5.exe SSS2.exe SSS3.exe 

It is unclear why CFP is reported as failed in these tests. You might try yourself and see. Attachment contains ssts.conf file with which you can test CFP/CIS.

CFP/CIS intercepts system shutdown privilege elevation requests and hence effective blocks sss2.exe and sss3.exe tests.

CFP/CIS can not be terminated by any of those kill tests.


这条申明测试结果有误

3 - There are some insignificant tests that do not pose any real threat and hence we will not do anything about them. 

--------------
CFP/CIS is marked as failed in the following tests:   SSS.exe i.e. System Shutdown Simulation tests. 
--------------
It has been scored 50% because CFP/CIS does not intercept system shutdown requests. This is the testing methodology of the tester.

System shutdown poses no real threat. The malware waits for system shutdown to perform its harmful actions. So whether you intercept or not, it can attack the user when the user manually logs out. Original System Shutdown Simulation tests do care about this fact. 
So we do not plan to add this redundant protection to pass any tests.

--------------

socksnif.exe: This test is designed to test if a malware can snif your network connection or not. 
--------------

If "\Device\Afd\EndPoint" is added to the Defense+ My Protected Files list, this can be easily intercepted. Adding this entry to the protected files means, making Defense+ to alert you for each and every application which tries to access Windows Sockets.
(个人的My protected File里只有*.* ,拦截过这个,估计全盘监控的朋友们通过相关测试肯定没问题 )

However, we do not plan to add this to our default protected files. Because

* It poses no real threat. Malware can not sniff your everyday bank transactions because everything is already SSL encrypted,
* This is basically no different than sniffing your network traffic from another computer,
* It will increase the number of popups unnecessarily,

--------------
crash7.exe: This test tries to allocate all the memory of the computer to crash applications including the security software
--------------

It might be possible for an application to crash if there is no more computer memory available. This is usually a random case. We do not plan to make any changes to pass this test because

* The crash can be random, intermittent and ubiquitous 
* Assuming CFP/CIS processes also crashed, there is no real threat to the system because by terminating CFP/CIS, malware will not gain any advantage for byapssing Defense+.

So in summary: by terminating CFP/CIS, Defense+ will not be able to be bypassed.“


官方人认为以上三种测试所假想情况并不会带来实质性的危险,并不打算为对此做出改动。(相当“固执” 啊)

CEO 的部分回复:
”We hope he will correct it soon. We also hope as a goodwill gesture he will test the bug fixed version and update his results accordingly. 

This shows that its important not to rely on a single person's test results and use a full test application like testmypcsecurity.com in order to avoid the human error.“


貌似这个测试是由个人而非小组完成的?疏忽纰漏在所难免。

评分

参与人数 1人气 +1 收起 理由
秘书 + 1 感谢解答: )

查看全部评分

distance0
头像被屏蔽
发表于 2008-11-30 20:27:21 | 显示全部楼层
crash7还是有必要拦截的吧,没有突破防护,弄死机也不爽啊,有的病毒就是破坏性的,让你死机蓝屏就算达到目的了。
distance0
头像被屏蔽
发表于 2008-11-30 20:31:15 | 显示全部楼层
个人测试结果应该只是个expression,对应后面的application,另外在小组里面,某一项测试也可能是归某个人管的。
Magis
头像被屏蔽
 楼主| 发表于 2008-11-30 20:37:47 | 显示全部楼层

回复 3楼 distance0 的帖子

估计意思应该是应该有人来审核个人的测试结果。
周勃
发表于 2008-11-30 20:54:55 | 显示全部楼层
英文的,看不懂耳,说了些什么呀?能不能翻译一下?
loveyuwei
发表于 2008-11-30 21:03:52 | 显示全部楼层
大致的都了解了,毛豆反泄露还是不错的。
大鱼弱智
发表于 2008-11-30 21:09:04 | 显示全部楼层
继续支持毛豆,不要放弃!
爱卡巴888
发表于 2008-11-30 21:45:38 | 显示全部楼层
12月2号有新版?
零天幻星
发表于 2008-12-1 17:01:23 | 显示全部楼层
毛豆版本更新的够快的啊
X-ZZZZ
发表于 2008-12-1 17:04:00 | 显示全部楼层
期待啊 话说 我都开始爱屋及乌开始期待起comodo的杀毒了 呵呵
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-12 07:21 , Processed in 0.131634 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表