Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 20, 2013, 09:35:01 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663306
Posts
70516
Topics
145177
Members
Latest Member:
gingir
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Vulnerability Analyzer - CVA
CVA improvement suggestions & Wish-List
« previous
next »
Pages:
[
1
]
2
3
Author
Topic: CVA improvement suggestions & Wish-List (Read 50599 times)
LeoniAquila
Retired moderator
Comodo's Hero
Offline
Posts: 6745
CVA improvement suggestions & Wish-List
«
on:
May 06, 2008, 03:29:36 PM »
Please post your CVA improvement suggestions and wishes in this thread! Thank you.
I'm first out:
1) Present a scan log which programs and system details CVA has scanned. If CVA, for example, doesn't know anything about a certain program - it would be nice to know that. Like a warning "this program isn't recognized by CVA, you should i) look for updates manually and ii) submit it to Comodo so we can add it to our database". In case there already is a log available (I haven't completely checked out the features of CVA), please ignore this suggestion.
2) Tell me that I had Defense+ disabled!
3) If CVA doesn't already check for the latest Microsoft hotfixes, maybe this could be a useful feature? I know that most people have Windows Automatic Updates, but if that feature for some reason misses a patch or two, CVA could cover that.
Thanks!
LA
«
Last Edit: July 11, 2008, 05:14:44 AM by LeoniAquila
»
Logged
LeoniAquila
Retired moderator
Comodo's Hero
Offline
Posts: 6745
Re: CVA improvement suggestions
«
Reply #1 on:
May 14, 2008, 03:01:06 AM »
Umesh replied here, but now his post is gone? Anyway, Umesh confirmed that my first and third suggestions are planned to be part of CVA (that's how I remember it, if I'm wrong, please correct me).
LA
Logged
herman the german
Newbie
Offline
Posts: 16
Re: CVA improvement suggestions
«
Reply #2 on:
May 28, 2008, 01:55:23 AM »
i've got a sugestion as well. i've been using rival secunia's PSI which is in rc2 atm i think and when it detects something is out of date it offers a direct link to the website where the updated version can be found i was wondering if the vulnerability advisor could do the same?
cheers
herman the german
Logged
umesh
Comodo Staff
Comodo's Hero
Offline
Posts: 860
Re: CVA improvement suggestions
«
Reply #3 on:
June 03, 2008, 07:18:37 AM »
Hi LeoniAquila,
I also wonder where my post has gone!
Yes we will have 1st and 3rd requests covered in forthcoming versions. Next version which we plan by 3rd week of June, 2008 is expected to have missing Windows patches information.
Regarding 2nd request, it was kind of connecting two products which we won't like to do, may be CFP can be improved to show you some balloon messages every often if D+ is disabled.
Regarding herman the german question if we take user as from where he can download latest version,
please check attached snap where CVA takes user to
http://www.rarlab.com/download.htm
when it finds an old version of Winrar is installed.
So CVA also has this feature.
Thanks
-umesh
Logged
Zero3K
Comodo Loves me
Offline
Posts: 100
Installed Programs
«
Reply #4 on:
June 08, 2008, 05:45:08 PM »
It should show a list of the ones that it knows about.
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13180
Volunteer Moderator
Re: CVA improvement suggestions
«
Reply #5 on:
June 10, 2008, 04:20:57 AM »
In reply to the 2nd request, i also found that a lack of CPF, the icon doesn't change if you disable the firewall or D+ to something with a red cross in it so you can see it's disabled. Therefore i wrote a small program that check's the Firewall and D+ State in the Registry and shows a balloon when the config is not in my own "default" state.
I think this would be a nice feature for an upcomming CPF release.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
LeoniAquila
Retired moderator
Comodo's Hero
Offline
Posts: 6745
Re: CVA improvement suggestions
«
Reply #6 on:
June 10, 2008, 05:19:33 AM »
Quote from: rhgtyink on June 10, 2008, 04:20:57 AM
In reply to the 2nd request, i also found that a lack of CPF, the icon doesn't change if you disable the firewall or D+ to something with a red cross in it so you can see it's disabled. Therefore i wrote a small program that check's the Firewall and D+ State in the Registry and shows a balloon when the config is not in my own "default" state.
I think this would be a nice feature for an upcomming CPF release.
I agree, but now you've gone off the CVA topic, so I suggest you put this on the CFP 3 wishlist!
Thanks,
LA
Logged
spasserfan
Comodo Family Member
Offline
Posts: 89
Re: CVA improvement suggestions
«
Reply #7 on:
July 01, 2008, 04:11:49 AM »
It would be nice if one could schedule scans. Since I do not want the program to run all the time these schedules should start the program, and if there is any updates prompt the user. When the job is finished the program should automatically close
As an addition to the above it would also be a great feature if CVA could be set to automatically install the updates by prompting the user when they are found: "updates has been found, will you update these programs now, later or manually?"
Logged
umesh
Comodo Staff
Comodo's Hero
Offline
Posts: 860
Re: CVA improvement suggestions
«
Reply #8 on:
July 02, 2008, 01:22:26 AM »
Hi spasserfan,
Quote
* It would be nice if one could schedule scans. Since I do not want the program to run all the time these schedules should start the program, and if there is any updates prompt the user. When the job is finished the program should automatically close
would you like to see this implemented as Windows Tasks? That means CVA can provide an interface and using that details like they are entered in Windows Tasks about timing can be entered. So CVA is run by Windows at that time and generates the report under specified folder.
Quote
* As an addition to the above it would also be a great feature if CVA could be set to automatically install the updates by prompting the user when they are found: "updates has been found, will you update these programs now, later or manually?"
This is not trivial thing, updates vary from product to product and they can be very product specific. Like no other product can provide updates for Comodo Firewall Pro, b'caz the nature of updates, similarly can be the case for many other products.
Even if we venture out in this, we won't be able to cover all products, so the best is product in question updates itself which is done best by itself rather any other product.
Thanks
-umesh
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5056
A bad workman always blames his tools
Re: CVA improvement suggestions
«
Reply #9 on:
July 02, 2008, 03:22:31 PM »
I guess I'll add mine too.
Making CVA act as a frontend to Windows tasks would be nice but if possible I wish for a realtime vulnerability check too.
Secunia PSI beta had a something like this (although it didn't appear to be really realtime).
Maybe some sort of realtime scanning could be added making CVA-aware a future version of CFP.
Another nice feature would be to make CMF CVA-aware that is if there is a chance to let CMF know if a specific BO event can be linked to a specific exploit/advisory.
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
umesh
Comodo Staff
Comodo's Hero
Offline
Posts: 860
Re: CVA improvement suggestions
«
Reply #10 on:
July 02, 2008, 11:49:52 PM »
Hi gibran,
Real time scanning is in the pipeline, we will have it.
We although can change CMF so when it detects any vulnerability, it can send information about it to comodo.
But even though CMF alerts about any vulnerability, that product has to be analyzed and vulnerability has to be confirmed.
As of now role of CVA is just to inform users about known vulnerabilities and as of now Comodo is not in the business of exposing vulnerabilities and publish them.
Thanks
-umesh
«
Last Edit: July 02, 2008, 11:52:23 PM by umesh
»
Logged
gibran
Average User
Comodo's Hero
Offline
Posts: 5056
A bad workman always blames his tools
Re: CVA improvement suggestions
«
Reply #11 on:
July 03, 2008, 03:27:38 AM »
Quote from: umesh on July 02, 2008, 11:49:52 PM
Real time scanning is in the pipeline, we will have it.
That's great news
Quote from: umesh on July 02, 2008, 11:49:52 PM
We although can change CMF so when it detects any vulnerability, it can send information about it to comodo.
But even though CMF alerts about any vulnerability, that product has to be analyzed and vulnerability has to be confirmed.
As of now role of CVA is just to inform users about known vulnerabilities and as of now Comodo is not in the business of exposing vulnerabilities and publish them.
Sorry I didn't explain myself as I know nearly nothing about BO and exploits. As I understand Vulnerability research require a cooperative approach and I understand that there is no way for a single company to take such a heavy task.
I always wondered if there could be a different way to warn user about a specific exploit attack. Usually AV signature-based approach can identify specific exploit code and alert the user.
However this type of detection is somewhat limited as changing the code to leverage on the same vulnerability could be undetected.
CMF instead trap BO on the fly and it can detect even new exploit code on the act. However as end user there is no sure-strike way to know if an alert was due to a malicious attempt.
As I don't have the necessary know-how I don't know it an existing BO vulnerability is able to trigger a well defined range of alerts regardless of the exploit code or end-user machine specific setups.
If there is a way to to bind an existing reported exploit/vulnerability to a specific set of alert characteristics then there would be an alternate way to detect exploits without relying on exploit code signatures.
Since CMF is monitoring BO events I wondered if there could be something like a BO signature (based for example only on memory range exception addresses, exploitable component name/signature and type of BO) specific enough to link a specific BO alert to an existing reported vulnerability (if that vulnerability provided exploit code to gather such data).
I don't know if there is a way to define something like a BO signature but I imagined if something like this was possible then it could be used an a way to complement existing AV code signature based approach (creating a chance for researchers to add such BO signature to new full disclosure advisories).
«
Last Edit: July 03, 2008, 03:29:29 AM by gibran
»
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
spasserfan
Comodo Family Member
Offline
Posts: 89
Re: CVA improvement suggestions
«
Reply #12 on:
July 04, 2008, 01:02:30 PM »
Quote from: umesh on July 02, 2008, 01:22:26 AM
Hi spasserfan,
would you like to see this implemented as Windows Tasks? That means CVA can provide an interface and using that details like they are entered in Windows Tasks about timing can be entered. So CVA is run by Windows at that time and generates the report under specified folder.
This is not trivial thing, updates vary from product to product and they can be very product specific. Like no other product can provide updates for Comodo Firewall Pro, b'caz the nature of updates, similarly can be the case for many other products.
Even if we venture out in this, we won't be able to cover all products, so the best is product in question updates itself which is done best by itself rather any other product.
Thanks
-umesh
Implementing as windows task was just what I wanted, that way the check could be done when the system is idle. If CVA doesn't find any vulnerabilities then the program just shuts down silently, but if any vulnerabilities has been found it prompts the user.
As for updating programs automatically, it would be nice if one could specify a command line which CVA should run if vulnerabilities is found in a particular program (many programs has an external updater or some could be updated by using a command line switch). Of course the command line should be an option (deselected by standard) to make CVA user friendly but also making a good program for professionals.
The way you could implement this could be like this: The first time a vulnerability has been found in a program CVA would prompt the user (if the command line option is selected
) if he wanted to:
Set a command line for this program
Not to run a command line with this program
And of course an "remember" option (like in CFP) to let CVA run the specified command line every time a vulnerability has been found for that particular program or never run a command line for that particular program but instead prompt the user to manually update.
«
Last Edit: July 04, 2008, 01:53:48 PM by spasserfan
»
Logged
umesh
Comodo Staff
Comodo's Hero
Offline
Posts: 860
Re: CVA improvement suggestions
«
Reply #13 on:
July 10, 2008, 11:16:41 PM »
Hi gibran,
Your ideas are great, we would consider it down the road.
Thanks
-umesh
Logged
3xist
Guest
Re: CVA improvement suggestions & Wish-List
«
Reply #14 on:
July 11, 2008, 02:39:02 AM »
Hi Guys,
I made this a sticky. This is now also the wish list for CVA.
Josh
Logged
Tags:
Pages:
[
1
]
2
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.054 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com