Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 19, 2013, 11:38:16 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
668914
Posts
71133
Topics
145742
Members
Latest Member:
Bukovskiy_Konstantin
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Vulnerability Analyzer - CVA
CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
« previous
next »
Pages:
[
1
]
Author
Topic: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects (Read 13473 times)
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13253
Volunteer Moderator
CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
on:
March 09, 2009, 07:44:41 AM »
Scan results from 7 - march - 2009 PSI and CVA both updated.
Running on Vista SP1, Enterprise, x32.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
valldemossa
Guest
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #1 on:
March 09, 2009, 11:08:13 AM »
CVA consistently appears to be well behind other sites. I tend to use filehippo to find and update to the latest level. Running CVA the next day usually reports to Comodo my new updates.
I would question the necessity for such software as a quick glance on the filehippo site tends to tell me everything I need. Far quicker than running the program and most software is there in one place.
CVA tends not to detect (or rather display update information) regarding the more obscure software anyway.
Questionable commitment to this project???
Another project left to flounder as it's no longer part of Comodo's bigger picture???
Dave
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13253
Volunteer Moderator
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #2 on:
March 09, 2009, 11:31:32 AM »
I don't think so, having software up2date is one of the most important things to do besides not running all day in "administrator" mode, that will prevent over 90% of all infections anyway.
I think priorities are a bit low for this at the moment, but i don't think it will be out of the picture...
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 588
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #3 on:
May 21, 2009, 01:37:29 PM »
Comodo should integrate a database that is generated by the users of CVA. That would make the program far more effective in detecting available updates: faster update info available and "knowledge of" many more obscure programs as well. The more users CVA has, the better the system works.
This could be done the way SUMo works; by reading the version info from files:
http://www.kcsoftwares.com/index.php?sumo
What could be more simple?
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13253
Volunteer Moderator
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #4 on:
May 21, 2009, 01:56:18 PM »
There is an option to generate an "unknown application list" you can send to comodo.
It's build in CVA, Edit, Options, Generate unrecognized product reports.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 588
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #5 on:
May 22, 2009, 09:00:06 AM »
That's not what I meant. That way updating the database still has to be done by Comodo.
SUMo updates its database by using info provided by the users; each time the program is run, it checks file versions against the online database. If you happen to have a new version that is not yet in the database, the DB is updated based on the new file version you just "provided".
Ergo, the DB is always as up-to-date as the fastest user (hopefully this phrasing makes any sense
). The system is brilliant in its simplicity and very effective. And, last but not least, it is maintenance free for every supported file (not all program files include version numbers). Comodo won't have to do anything any more for these files.
«
Last Edit: May 22, 2009, 09:02:11 AM by Toxteth O'Grady
»
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13253
Volunteer Moderator
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #6 on:
May 22, 2009, 09:05:50 AM »
Yes but that would also make it vulnerable to abuse i guess..... I don't mind if they review it first
Having the latest version is only important if the previous was exploitable vulnerable if you want instant alerts.
And vulnerabilities have to be reviewed by experts anyway...
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
slg123
Comodo Family Member
Offline
Posts: 55
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #7 on:
May 22, 2009, 09:12:44 AM »
Quote from: Ronny on May 22, 2009, 09:05:50 AM
Yes but that would also make it vulnerable to abuse i guess..... I don't mind if they review it first
Having the latest version is only important if the previous was exploitable vulnerable if you want instant alerts.
And vulnerabilities have to be reviewed by experts anyway...
Thats exactly the point. I believe that CVA covers softwares prioritized on vulnerabilities.
Its not an updater and I don't want it to be one.
In my opinion its a nice little piece of application.
Kudos to Comodo and CVA team.
Logged
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 588
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #8 on:
May 22, 2009, 12:00:58 PM »
Quote from: Ronny on May 22, 2009, 09:05:50 AM
Yes but that would also make it vulnerable to abuse i guess..... I don't mind if they review it first
Having the latest version is only important if the previous was exploitable vulnerable if you want instant alerts.
And vulnerabilities have to be reviewed by experts anyway...
You don't care about updating in case of bug fixes or new features? Only about fixing vulnerabilities?
And how do you mean, vulnerable? Would someone modify an exe file to mislead the system, because that's the only way it could be done.
So what? After the alert, you go to the website of the "updated" program and find there is no new version... What does the bad guy have to gain by going through this trouble? Nothing, so there is no risk.
Anyway, the current system depends on the work of people at Comodo. Which programs do they monitor, there is no list. You could be using, for example, an alternative pdf-reader or a media player (for streaming audio) that is not on their list. Who knows.
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13253
Volunteer Moderator
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #9 on:
May 22, 2009, 12:15:36 PM »
Quote from: Toxteth O'Grady on May 22, 2009, 12:00:58 PM
You don't care about updating in case of bug fixes or new features? Only about fixing vulnerabilities?
Oh yes i do but i don't care if it takes a day or 2 before i get notified
Quote
And how do you mean, vulnerable? Would someone modify an exe file to mislead the system, because that's the only way it could be done.
So what? After the alert, you go to the website of the "updated" program and find there is no new version... What does the bad guy have to gain by going through this trouble? Nothing, so there is no risk.
Okay true checking the site official site will result in "oops there is no new version"
Quote
Anyway, the current system depends on the work of people at Comodo. Which programs do they monitor, there is no list. You could be using, for example, an alternative pdf-reader or a media player (for streaming audio) that is not on their list. Who knows.
I don't agree with this, if you upload your list of unrecognized programs found on your system they will become part of their monitoring system and become part of the update list. As for the applications i have they all get detected now, and not in the beginning of this project so i have to assume they put all those apps on the database...
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 588
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #10 on:
May 23, 2009, 02:49:32 AM »
So, you DO want CVA to act as an updater, not just alert you about potential risks to some software.
Then what is there to gain by having someone at Comodo "analyse" the... whatever it is that is done? And, by the way, do they actually do that? Is every update to every program on the list actually "tested" or "examined"? Or do they simply keep track of available updates and report these?
I don't understand what needs to be analysed anyway.That would suggest some updates are deemed to be unimportant and therefore are not added to the CVA list of updates. What good would that do? An update is an update and it's always released for good reasons, be it new features, bug fixing, security risks, or whatever. I, for one, am perfectly capable of judging whether it is worth updating a program or not. I don't need someone working for Comodo to do that for me.
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 13253
Volunteer Moderator
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #11 on:
May 23, 2009, 04:15:21 AM »
That's the exact reason that they have 3 tabs
- Update available
- Vulnerable
- End of Life
As far as i know they put all software on the database that is submitted back to them so for updates there is nothing to analyze, but before a product get's marked as vulnerable there has to be some sort of verification.
That's what they have to do.
Logged
Volunteer Moderator
Any concerns?
Please send me a
PM
or review the
Forum Policy - update Jan 3rd 2013!
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.183 seconds with 20 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com