Welcome, Guest. Please login or register.
September 07, 2008, 12:52:28 AM

Login with username, password and session length

189241 Posts
22043 Topics
52862 Members

Latest Member: bmuth

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Bug Reports
| | | |-+  Policies aren't being applied to programs run from network (V3.0.14 - .25 X32)
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Policies aren't being applied to programs run from network (V3.0.14 - .25 X32)  (Read 2912 times)
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« on: January 02, 2008, 02:35:36 AM »

Firewall and Defense+ policies aren't being applied to any executables run from a network.  In my case, the network location is a FAT32-based share using the Shared Folders feature in a VMWare virtual machine.  Perhaps the issue happens on any executables run from any network location?  Can anybody else give feedback on whether this is the case?

Version: V3.0.14.276
CPU: 32 bit
OS: Win XP SP2
Other security programs running: Returnil, NOD32
Defense+ Security Level: Train with Safe Mode
Firewall Security Level: Custom Policy Mode
« Last Edit: July 12, 2008, 06:11:10 PM by MrBrian » Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« Reply #1 on: January 02, 2008, 04:42:40 PM »

This is a follow-up on my own post.  When I discovered this issue, I was using a program not on the Comodo whitelist.  Be sure, if you're testing this issue, to use a program not on the Comodo whitelist.  One such program is the leaktest available at http://www.grc.com/lt/leaktest.htm.
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« Reply #2 on: February 04, 2008, 08:07:25 PM »

Issue still exists in v3.0.16.295
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« Reply #3 on: February 21, 2008, 05:09:47 AM »

Issue still exists in v3.0.18.309.
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« Reply #4 on: March 26, 2008, 01:04:35 AM »

Issue still exists in v3.0.20.320.
Logged
hiddenstar
Newbie
*
Offline Offline

Posts: 14


« Reply #5 on: March 26, 2008, 05:04:21 AM »

Defense+ and firewall both blocked the Exe while adding the application thru Running process and given Isolated\Blocked application privilege... I mean to say that- its using Device name(File path) for the Network Exe's..  Huh Am i Right??


« Last Edit: March 26, 2008, 07:37:20 AM by hiddenstar » Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« Reply #6 on: March 26, 2008, 10:55:44 PM »

Defense+ and firewall both blocked the Exe while adding the application thru Running process and given Isolated\Blocked application privilege... I mean to say that- its using Device name(File path) for the Network Exe's..  Huh Am i Right??

This happens using the shared folders feature of VMware.  It's a mapped drive.  CFP will never give any alerts for a program run from this mapped drive.
Logged
hiddenstar
Newbie
*
Offline Offline

Posts: 14


« Reply #7 on: March 28, 2008, 02:29:46 AM »

Hi,
   I have attached the snapshot of the alert and the UNC path rule for the network exe's. Please verify this.

OS:Win XP x32 SP2
CFP:3.0.20.320

Thanks,
Vicky.
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« Reply #8 on: March 28, 2008, 05:22:26 PM »

Thank you hiddenstar for your testing Smiley  It appears that in your case CFP is working correctly.  However, in my case I am using a mapped drive, not a UNC path.  I gave the following command at the command prompt: 'fsutil fsinfo drivetype s:' (without quotes) and received the answer: 'S: - Remote/Network Drive'.  Volume S is the volume with the problematic behavior.
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« Reply #9 on: March 28, 2008, 06:09:04 PM »

Issue still exists in v3.0.21.329.
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« Reply #10 on: April 18, 2008, 04:36:49 PM »

Issue still exists in v3.0.22.349.
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 326


« Reply #11 on: May 07, 2008, 05:23:16 PM »

Please provide more info about your environment (e. g. guest os, VMWare version).
If you uninstall Returnil and NOD32 (and other security apps except CFP) does it make any difference?

Thank you for responding Smiley.

Host OS - Windows XP2 with all patches
Guest OS - Windows XP2 with all patches
VMWare Workstation v5.5.6
Returnil not installed in the virtual machine.
I didn't try to uninstall NOD32 in virtual machine but perhaps I will soon, just to rule it out as a possibility.
Logged
sovereignty68
Newbie
*
Offline Offline

Posts: 17


« Reply #12 on: May 07, 2008, 08:55:11 PM »

It works for me. Even the executable is in Safe list, I still get the alert.....
Logged
Yuriy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 972


« Reply #13 on: May 10, 2008, 12:48:27 PM »

MrBrian,
NP. Hopefully developers will provide some feedback.
Logged
Yuriy
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 972


« Reply #14 on: May 10, 2008, 12:52:33 PM »

It works for me. Even the executable is in Safe list, I still get the alert.....
What are your system details? Do you also use latest CFP on VMWare on Win XP SP2 x32 host and guest?
Logged
Tags: CFP 3.0.24 BUG CFP 3.0.22 BUG CFP 3.0.16 BUG CFP 3.0.18 BUG CFP 3.0.25 BUG CFP 3.0.17 BUG CFP 3.0.19 BUG CFP 3.0.20 BUG CFP 3.0.21 BUG CFP 3.0.23 BUG 
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.268 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com