Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 20, 2010, 06:41:03 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373309
Posts
41409
Topics
94121
Members
Latest Member:
martinez38
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Discontinued Products
Comodo Firewall
Help for v3
Mars Attacks! and apparently everyone else does too.
« previous
next »
Pages:
[
1
]
Author
Topic: Mars Attacks! and apparently everyone else does too. (Read 1911 times)
Irish_Sean
Newbie
Offline
Posts: 14
Mars Attacks! and apparently everyone else does too.
«
on:
December 02, 2008, 03:02:01 PM »
CFP / Latest version, using Proactive Security config, FW Safe, D+ Safe, Stealth ports to everyone.
WIN XP PRO SP3.
Dial up, no router.
After initial install I started to define some rules for common windows components and all hell has broke loose. I have set Lsass, Svchost, System, and Explorer to outgoing only using CFP's predefined rule. CFP is now logging 100/1000's of intrusion attempts on my computer I dont know what is going on.
I have included a screen, showing examples....HELP How can I be attacked when all my ports are stealthed?
Logged
grue155
Global Moderator
Comodo's Hero
Offline
Posts: 1172
Re: Mars Attacks! and apparently everyone else does too.
«
Reply #1 on:
December 03, 2008, 08:26:17 PM »
Quote
How can I be attacked when all my ports are stealthed?
Believe it or not, this the normal amount of junk on the Internet these days. These are simply zombie probes being sent to any and all, to see if anything replies. You're stealthed, so they don't know that you're there. But it makes the logs look like a windscreen travelling down a motorway in locust season. It's unnerving, but harmless because CFP is keeping all the junk away from your machine.
To cut back on the amount of stuff being recorded in the logs, you can uncheck the box that says "log this" on the respective blocking rules.
Logged
Irish_Sean
Newbie
Offline
Posts: 14
Re: Mars Attacks! and apparently everyone else does too.
«
Reply #2 on:
December 04, 2008, 07:41:21 AM »
Good to know grue155, I felt a little naked in the wind there. I thought I had miss-configured the Firewall in some way.
I still have a problem though, while playing Warrock an on-line FPS that is using P2P technology to connect players, my logs fill up with failled UDP attempts. When I firstt ran Warrock I set FW/D+ into training mode so Im pretty sure that I allowed CFP to accept inbound UDP for Warrock. Is the fact I set most Windows components to outgoing only superceeding this?
Logged
grue155
Global Moderator
Comodo's Hero
Offline
Posts: 1172
Re: Mars Attacks! and apparently everyone else does too.
«
Reply #3 on:
December 04, 2008, 11:55:35 AM »
Maybe. The answer in probably in the way that firewall rules are evaluated. When packets are sent and received, the packets are processed in this sequence of rules:
Internet ---- Global Rules ------ Application Rules ------- application
Setting CFP for a training mode, lets CFP learn about the application and what rules need to be set for that application. Setting rules to be outgoing only doesn't allow packets to come in from the Internet if those packets are not in some kind of answer to something sent from the application.
P2P, on the other hand, has users out on the Internet who will query your machine. They just send packets to you, and those packets aren't answers, but are queries. So, those packets coming in, first encounter CFP global rules, and then the application rules. (And, if there is no specific application, the CFP "Windows Operating System" rules get used)
If those incoming packets are all coming to a single UDP port, then you'll need to set an application rule to allow those unsolicated packets to reach the application. And you'll likely need to add a global rule to allow that packet to get thru, also.
Logged
Irish_Sean
Newbie
Offline
Posts: 14
Re: Mars Attacks! and apparently everyone else does too.
«
Reply #4 on:
December 05, 2008, 04:09:27 PM »
Quote from: grue155 on December 04, 2008, 11:55:35 AM
If those incoming packets are all coming to a single UDP port, then you'll need to set an application rule to allow those unsolicated packets to reach the application. And you'll likely need to add a global rule to allow that packet to get thru, also.
Thanks for taking the time to explain that grue155, very nice of you. I didn't want to report back without trying to create these rules myself, but as you can in the logs I have made things worse. Could someone in the know check them out and determine what adjustments I need to make, or better yet if someone else plays Warrock without lag could you post your rules.
Thanks Sean.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.047 seconds with 22 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com