Our well‑known security researcher Tavis Ormandy of Google’s Project Zero discovered another flaw in Comodo’s “security” software. This time he found a VNC server enabled by default that has a predictable password.
Earlier this month, Tavis pointed out that Comodo's web browser, (Chromodo), is not secure.
During the installation of Comodo Anti-Virus, Comodo Firewall, or Comodo Internet Security on a Windows PC, the GeekBuddy application is also installed, which can be used by Comodo to provide remote technical support to the computers of their customers. This service is not free.
The GeekBuddy application allows remote connection by installing a VNC server that grants administrator rights to the connecting party. It is enabled by default, and is open to any local network. It allows password-based connection, but Ormandy discovered that the passwords used are predictable.
Thus, if you run Comodo software, someone from the internet could potentially take control of your computer.
“It's an obvious and ridiculous local privilege escalation, something that Comodo apparently believes they have solved by creating a password”, Ormandy said.
“However, that's not the case, as the password is simply the first 8 characters of the SHA1 (Disk.Caption + Disk.Signature + Disk.SerialNumber + Disk.TotalTracks). I imagine that Comodo thought no one would bother with how the password is generated”
The company responded that it has already released a security update... and that 90% of their software that exists online on the internet has been updated. Make sure those of you who haven't updated to upgrade your application immediately.
https://code.google.com/p/google-security-research/issues/detail?id=703
