Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 06, 2008, 09:07:25 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
197723
Posts
22760
Topics
54696
Members
Latest Member:
itman2000my
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Bug Reports
My Own Safe Files is useless
« previous
next »
Pages:
[
1
]
Author
Topic: My Own Safe Files is useless (Read 1304 times)
sovereignty68
Newbie
Offline
Posts: 17
My Own Safe Files is useless
«
on:
May 06, 2008, 12:32:08 AM »
Here's the configuration I set in Comodo's Computer Security Policy
%Windir% = Windows System Applications
All Applications * = Isolated
I test run Firefox, but it won't run because D+ blocked it of course. So I was wondering if My Own Safe Files works, then
I add firefox.exe or whole Firefox directory to My Own Safe Files, unfortunately, D+ won't learn anything from the files in My Own Safe Files.
I must add Firefox.exe or firefox directory as Trusted Application in Computer Security Policy instead of My Own Safe List before the rule of "All Application = Isolated Applications" in order to allow firefox.exe to run.
This information is from Comodo's help file:
Quote
Comodo Firewall Pro allows you to define a personal safelist of files to complement the default Comodo safelist.
Files added to this area are automatically given Defense+ trusted status. If an executable is unknown to the Defense+ safelist then, ordinarily, it and all its active components will generate Defense+ alerts when they run. Of course, you could choose the 'Treat this as a Trusted Application' option at the alert but it is often more convenient to classify entire directories of files as 'My Own Safe Files'.
My Own Safe Files is pretty useless if D+ can't learn anything from it as claimed once All Applications is set to Isolated Applications.
I think in Safe/Clean PC level, files in My Own Safe Files should be learned or matched before applying any rules in Computer Security Policy.
«
Last Edit: May 06, 2008, 12:40:47 AM by sovereignty68
»
Logged
hiddenstar
Newbie
Offline
Posts: 16
Re: My Own Safe Files is useless
«
Reply #1 on:
May 06, 2008, 01:08:14 AM »
I guess
priority of the Defense + is as follows when an application is executed.
1.Check in Quarantined files
2.Check For Rule in Computer Sec. Policy.
3.If rule not found, Verify in Comodo's safe list\My Own Safe files
4.If App. is not in Safe list and Trust the Digitally signed vendor is Enabled, Verify digitally signed files in My Trusted software vendors.
5.At last, If Application is not safe\It is found in My pending files, Alert the user.
Logged
sovereignty68
Newbie
Offline
Posts: 17
Re: My Own Safe Files is useless
«
Reply #2 on:
May 06, 2008, 01:21:33 AM »
I understand what you meant,
but if I add program path in Computer Security Policy instead of My Own Safe Files(My Own Safe Files uses hash to identify the files, right?), then it wouldn't be very secure because that way I just copy a malicious file, rename it to firefox.exe, D+ would allow it to run.
If Imagine Execution Control + Safe Files use hash to recognize the files, then it will be more secure than just allow any files with same name to run.
«
Last Edit: May 06, 2008, 01:29:05 AM by sovereignty68
»
Logged
sovereignty68
Newbie
Offline
Posts: 17
Re: Image Execution Control/My Own Safe Files is broken
«
Reply #3 on:
May 07, 2008, 08:17:56 PM »
Did your executable in safe list also try to access protected folders and registry?
In My Protected Files, I have:
%windir%\*
%programfiles%\*
%userprofiles%\*
Temporary Files Group
In My Protected Registry, I have:
--Entire Registry listed--
HKEY_CLASS_ROOT*
HKEY_CURRENT_USER*
HKEY_LOCAL_MACHINE*
HKEY_USER*
KKEY_CURRENT_CONFIG*
My Safe Files:
Entire Firefox folder (%programfiles%\firefox\*)
Computer Security Policy:
Default Policies listed
%windir% = Windows System Applications
Removed All Applications rule
D+ Level = Clean PC
Logged
Yuriy
Global Moderator
Comodo's Hero
Offline
Posts: 1008
Re: My Own Safe Files is useless
«
Reply #4 on:
May 10, 2008, 02:59:26 PM »
I tested with exactly same conditions, except this:
Quote from: sovereignty68 on May 07, 2008, 08:17:56 PM
My Safe Files:
Entire Firefox folder (%programfiles%\firefox\*)
The only way i found to add objects (excluding moving from pending or quarantined files, and specifying from running processes) is to add either by browsing to exact location (folder c:\program files\mozilla in this case), then all exe's from that folder (*.dll, *.exe) will be added to safe files.
Where did you get environment variable? Added one object to safe files and renamed it to %programfiles%\firefox\*?
Anyway, here is my results: CFP does learn evething, except:
- i don't know whether it learns global hooks (as in my VM CFP doesn't catch global hooks, hence i cannot state anything);
- alerts are showed for protected files/folders activities (you are right here), but i don't have an idea whether this behavior can be considered as bug or undocumented feature:
Quote
Files added to this area are automatically given Defense+ trusted status.
From one side trusted means access everything (like trusted app policy), from other side manual doesn't state explicitly what exactly does "trusted status" mean
Logged
sovereignty68
Newbie
Offline
Posts: 17
Re: My Own Safe Files is useless
«
Reply #5 on:
May 10, 2008, 05:59:58 PM »
Quote from: Yuriy on May 10, 2008, 02:59:26 PM
Where did you get environment variable? Added one object to safe files and renamed it to %programfiles%\firefox\*?
Oh, I just use %programfiles% to represent C:\Program Files\ in previous post, I didn't mean I used environment variables to add it to safe list.
I'm realized that whatever executables in the safe list, CPF do recognize them as safe applications but still ask user for permissions. In the Alert message, it says
Quote
firefox.exe is a
safe
application. It is
about to modify the contents of C:\Program Files\Mozilla Firefox
. This usually happens when you try to install or update an application.
If you are not performing any of these operations, you mean consider
blocking this request.
So I assume, either Safe application does not get trust status as stated in help file or it's a bug.
During the test, I also find out default policy's Windows System Application and Trusted Application are not the same policy. Because I find out that Windows System Application allows its applications to create process, but Trusted Application won't. Is that right? I was having problems with Logitech SetPoint although it was given a Trusted Application status. CPF won't allow SetPoint to create process and logged in D+ events. But once I give SetPoint a Windows System Application status, SetPoint runs successfully without any errors or alerts in D+.
Logged
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3751
Sometimes words are meaningless indeed...
Re: My Own Safe Files is useless
«
Reply #6 on:
May 11, 2008, 04:34:17 AM »
AFAIK "My Own Safe Files" can be used in specifc CFP modes to trigger training/autolearning as long an app has no defined rule.
Adding a predefined policy to */All application should prevent training of all apps regardless if they were added to "My Own Safe Files".
Maybe only partially learned apps could still be trained.
Anyway this is a special case.
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
Yuriy
Global Moderator
Comodo's Hero
Offline
Posts: 1008
Re: My Own Safe Files is useless
«
Reply #7 on:
May 11, 2008, 05:09:22 AM »
Quote from: sovereignty68 on May 10, 2008, 05:59:58 PM
I'm realized that whatever executables in the safe list, CPF do recognize them as safe applications but still ask user for permissions. In the Alert message, it says
Quote
firefox.exe is a safe application. It is about to modify the contents of C:\Program Files\Mozilla Firefox. This usually happens when you try to install or update an application. If you are not performing any of these operations, you mean consider blocking this request.
So I assume, either Safe application does not get trust status as stated in help file or it's a bug.
Same here. It doesn't learn activities about modifiyng protected files/folders. We need developer's feedback in order to find out if this is a bug or expected behavior.
Quote from: sovereignty68 on May 10, 2008, 05:59:58 PM
During the test, I also find out default policy's Windows System Application and Trusted Application are not the same policy. Because I find out that Windows System Application allows its applications to create process, but Trusted Application won't. Is that right?
Yep. This is by design: the only difference between Windows System Application and Trusted Application is that Windows System Application has
*
in exceptions for "run an executable", which means it can launch everything without alerts.
Quote from: gibran on May 11, 2008, 04:34:17 AM
AFAIK "My Own Safe Files" can be used in specifc CFP modes to trigger training/autolearning as long an app has no defined rule.
It works great in clean pc and safe mode, except CFP doesn't learn activities for protected files/folders automatically.
Logged
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3751
Sometimes words are meaningless indeed...
Re: My Own Safe Files is useless
«
Reply #8 on:
May 11, 2008, 08:59:53 AM »
Quote from: Yuriy on May 11, 2008, 05:09:22 AM
It works great in clean pc and safe mode, except CFP doesn't learn activities for protected files/folders automatically.
This is because IMHO CFP was not designed to work this way.
The all application policy was used to create a baseline ruleset applicable to all application.
eg. to add %windir%\system32\ctfmon.exe to the interprocess memory access of all apps with one rule.
As it is now this is not a consistent behaviour.
IMHO existing ruleset should take the precedence over Trusted vendors and "My own Safe Files" and I'm inclined to consider */all application as a normal rule.
Anyway I was not able to find out if */all application takes the precedence over all rules or only subsequent ones.
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
Yuriy
Global Moderator
Comodo's Hero
Offline
Posts: 1008
Re: My Own Safe Files is useless
«
Reply #9 on:
May 11, 2008, 09:59:00 AM »
Quote from: gibran on May 11, 2008, 08:59:53 AM
This is because IMHO CFP was not designed to work this way.
If so (by design behavior) it seems to me this is not logical behavior. Let me explain. We don't have any executable from specific folder (e. g. %programfiles%\firefox) listed under computer security policy, we add entire folder to "my safe files".
CFP automatically learns every activity,
except
CFP gives pop-ups when firefox.exe (for example) tries to perform actions on protected files/folders. Why? If we added firefox folder we obviously want to avoid
any
pop-ups as this is purpose of "my own safe files":
Quote
If an executable is unknown to the Defense+ safelist then, ordinarily, it and all its active components will generate Defense+ alerts when they run. Of course,
you could choose the 'Treat this as a Trusted Application'
option at the alert
but it is often more convenient to classify entire directories of files as 'My Own Safe Files'.
Why does CFP give alerts about activities on protected files/folders and doesn't give alerts about accessing screen, modifiyng protected registry keys etc. ?
P.S.: I tested with and without "all application" group (with default permissions) under computer security policy. Same results in both cases.
Logged
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3751
Sometimes words are meaningless indeed...
Re: My Own Safe Files is useless
«
Reply #10 on:
May 11, 2008, 11:57:05 AM »
Yes the behaviour is inconsistent.
Quote from: Yuriy on May 11, 2008, 09:59:00 AM
P.S.: I tested with and without "all application" group (with default permissions) under computer security policy. Same results in both cases.
If I understood correctly this means that "My own Safe Files" doesn't work correctly even with untrained apps.
It looks like a regression bug.
as for this
Quote from: gibran on May 11, 2008, 08:59:53 AM
Anyway I was not able to find out if */all application takes the precedence over all rules or only subsequent ones.
sovereignty68's 1st post points out that rules are hadled from top to bottom.
The only thing missing would be if an half trained app placed before the "*/all application" group will learn the new rules regardless of what is configured in "all application" group.
In addtition to this I wonder how application added to "My trusted vendor" list will be learned.
«
Last Edit: May 11, 2008, 12:54:18 PM by gibran
»
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
Dennis2
Comodo's Hero
Offline
Posts: 577
Re: My Own Safe Files is useless
«
Reply #11 on:
May 11, 2008, 12:20:03 PM »
My Trusted Vendor does not work in this version latest the thread is on this page at the bottom.
Dennis
Logged
gibran
Forum Member
Global Moderator
Comodo's Hero
Offline
Posts: 3751
Sometimes words are meaningless indeed...
Re: My Own Safe Files is useless
«
Reply #12 on:
May 11, 2008, 12:55:31 PM »
Quote from: Dennis2 on May 11, 2008, 12:20:03 PM
My Trusted Vendor does not work in this version latest the thread is on this page at the bottom.
Dennis
Here too but few members managed to get it working (IIRC they imported their previous config).
Logged
Read First
~
FAQs
~
Forum Policy
~
CFP3 Configuration Report
THE CORE RULES OF NETIQUETTE
Yuriy
Global Moderator
Comodo's Hero
Offline
Posts: 1008
Re: My Own Safe Files is useless
«
Reply #13 on:
May 12, 2008, 09:38:04 AM »
Quote from: gibran on May 11, 2008, 11:57:05 AM
If I understood correctly this means that "My own Safe Files" doesn't work correctly even with untrained apps.
Guess so. But i was checking only exe's that were not listed at all under computer security policy, hence i'm not sure how does "my safe files" feature behave if we add half-trained apps etc.
Quote from: gibran on May 11, 2008, 12:55:31 PM
Here too but few members managed to get it working (IIRC they imported their previous config).
Lucky people
As for me i didn't succeed in importing my 3.0.21 config.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.223 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com