matousec.com (site map)

Poll

Should software vendors reward independent researchers for finding vulnerabilities in their software?

  Yes, by money and credit. (78.19%)

  Yes, by credit only. (11.71%)

  No. (6.87%)

  Yes, by money only. (1.74%)

  Other answer. (1.69%)

more

results

Proactive Security Challenge

Testing levels

Contents:


Back to contents

Level 10

The product has to score at least 100% in the tests on this level to pass it.


Back to contents

Tests


BSODhook
Test type: Other
Scoring: Failure (any of the tested functions causes the system crash or seriously damage the system) – 0%; Success – 100%.
Description: BSODhook is not a part of SSTS, it is a stand-alone tool that checks the implementation of a special kind of the tested product's kernel hooks. BSODhook test in the challenge probes hooked native SSDT functions.

ShadowHook
Test type: Other
Scoring: Failure (any of the tested functions causes the system crash or seriously damage the system) – 0%; Success – 100%.
Description: ShadowHook is a codename for the second version of BSODhook that added support for GDI SSDT functions. ShadowHook test probes hooked GDI SSDT functions.


Back to contents

Result table

In the following table 100 represents the 100% result and 0 represents the 0% result. Other values are displayed as rounded whole numbers. The last two columns summarize the product's score on this level and whether it passed this level or not.


 
Product ScoreResult
II. ShadowHook
III. BSODhook
III. II. -
Comodo IS 100 100 100%PASSED
KIS 2010 100 100 100%PASSED
Malware Defender 0 0 0%FAILED
OA Premium 0 100 50%FAILED
Online Armor Free 100 100 100%PASSED
OSSS 100 100 100%PASSED
Outpost SS 100 100 100%PASSED

Back to contents

Levels