Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 25, 2009, 03:31:19 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
345178
Posts
38110
Topics
86539
Members
Latest Member:
vlavoile
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Vulnerability Analyzer - CVA
CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
« previous
next »
Pages:
[
1
]
Author
Topic: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects (Read 4117 times)
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 5214
CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
on:
March 09, 2009, 07:44:41 AM »
Scan results from 7 - march - 2009 PSI and CVA both updated.
Running on Vista SP1, Enterprise, x32.
Logged
Forum Volunteer - Any concerns? Please send me a PM and/or review the
Forum Policy !
valldemossa
Guest
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #1 on:
March 09, 2009, 11:08:13 AM »
CVA consistently appears to be well behind other sites. I tend to use filehippo to find and update to the latest level. Running CVA the next day usually reports to Comodo my new updates.
I would question the necessity for such software as a quick glance on the filehippo site tends to tell me everything I need. Far quicker than running the program and most software is there in one place.
CVA tends not to detect (or rather display update information) regarding the more obscure software anyway.
Questionable commitment to this project???
Another project left to flounder as it's no longer part of Comodo's bigger picture???
Dave
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 5214
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #2 on:
March 09, 2009, 11:31:32 AM »
I don't think so, having software up2date is one of the most important things to do besides not running all day in "administrator" mode, that will prevent over 90% of all infections anyway.
I think priorities are a bit low for this at the moment, but i don't think it will be out of the picture...
Logged
Forum Volunteer - Any concerns? Please send me a PM and/or review the
Forum Policy !
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 537
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #3 on:
May 21, 2009, 01:37:29 PM »
Comodo should integrate a database that is generated by the users of CVA. That would make the program far more effective in detecting available updates: faster update info available and "knowledge of" many more obscure programs as well. The more users CVA has, the better the system works.
This could be done the way SUMo works; by reading the version info from files:
http://www.kcsoftwares.com/index.php?sumo
What could be more simple?
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 5214
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #4 on:
May 21, 2009, 01:56:18 PM »
There is an option to generate an "unknown application list" you can send to comodo.
It's build in CVA, Edit, Options, Generate unrecognized product reports.
Logged
Forum Volunteer - Any concerns? Please send me a PM and/or review the
Forum Policy !
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 537
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #5 on:
May 22, 2009, 09:00:06 AM »
That's not what I meant. That way updating the database still has to be done by Comodo.
SUMo updates its database by using info provided by the users; each time the program is run, it checks file versions against the online database. If you happen to have a new version that is not yet in the database, the DB is updated based on the new file version you just "provided".
Ergo, the DB is always as up-to-date as the fastest user (hopefully this phrasing makes any sense
). The system is brilliant in its simplicity and very effective. And, last but not least, it is maintenance free for every supported file (not all program files include version numbers). Comodo won't have to do anything any more for these files.
«
Last Edit: May 22, 2009, 09:02:11 AM by Toxteth O'Grady
»
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 5214
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #6 on:
May 22, 2009, 09:05:50 AM »
Yes but that would also make it vulnerable to abuse i guess..... I don't mind if they review it first
Having the latest version is only important if the previous was exploitable vulnerable if you want instant alerts.
And vulnerabilities have to be reviewed by experts anyway...
Logged
Forum Volunteer - Any concerns? Please send me a PM and/or review the
Forum Policy !
slg123
Comodo Family Member
Offline
Posts: 55
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #7 on:
May 22, 2009, 09:12:44 AM »
Quote from: Ronny on May 22, 2009, 09:05:50 AM
Yes but that would also make it vulnerable to abuse i guess..... I don't mind if they review it first
Having the latest version is only important if the previous was exploitable vulnerable if you want instant alerts.
And vulnerabilities have to be reviewed by experts anyway...
Thats exactly the point. I believe that CVA covers softwares prioritized on vulnerabilities.
Its not an updater and I don't want it to be one.
In my opinion its a nice little piece of application.
Kudos to Comodo and CVA team.
Logged
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 537
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #8 on:
May 22, 2009, 12:00:58 PM »
Quote from: Ronny on May 22, 2009, 09:05:50 AM
Yes but that would also make it vulnerable to abuse i guess..... I don't mind if they review it first
Having the latest version is only important if the previous was exploitable vulnerable if you want instant alerts.
And vulnerabilities have to be reviewed by experts anyway...
You don't care about updating in case of bug fixes or new features? Only about fixing vulnerabilities?
And how do you mean, vulnerable? Would someone modify an exe file to mislead the system, because that's the only way it could be done.
So what? After the alert, you go to the website of the "updated" program and find there is no new version... What does the bad guy have to gain by going through this trouble? Nothing, so there is no risk.
Anyway, the current system depends on the work of people at Comodo. Which programs do they monitor, there is no list. You could be using, for example, an alternative pdf-reader or a media player (for streaming audio) that is not on their list. Who knows.
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 5214
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #9 on:
May 22, 2009, 12:15:36 PM »
Quote from: Toxteth O'Grady on May 22, 2009, 12:00:58 PM
You don't care about updating in case of bug fixes or new features? Only about fixing vulnerabilities?
Oh yes i do but i don't care if it takes a day or 2 before i get notified
Quote
And how do you mean, vulnerable? Would someone modify an exe file to mislead the system, because that's the only way it could be done.
So what? After the alert, you go to the website of the "updated" program and find there is no new version... What does the bad guy have to gain by going through this trouble? Nothing, so there is no risk.
Okay true checking the site official site will result in "oops there is no new version"
Quote
Anyway, the current system depends on the work of people at Comodo. Which programs do they monitor, there is no list. You could be using, for example, an alternative pdf-reader or a media player (for streaming audio) that is not on their list. Who knows.
I don't agree with this, if you upload your list of unrecognized programs found on your system they will become part of their monitoring system and become part of the update list. As for the applications i have they all get detected now, and not in the beginning of this project so i have to assume they put all those apps on the database...
Logged
Forum Volunteer - Any concerns? Please send me a PM and/or review the
Forum Policy !
Toxteth O'Grady
Comodo's Hero
Offline
Posts: 537
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #10 on:
May 23, 2009, 02:49:32 AM »
So, you DO want CVA to act as an updater, not just alert you about potential risks to some software.
Then what is there to gain by having someone at Comodo "analyse" the... whatever it is that is done? And, by the way, do they actually do that? Is every update to every program on the list actually "tested" or "examined"? Or do they simply keep track of available updates and report these?
I don't understand what needs to be analysed anyway.That would suggest some updates are deemed to be unimportant and therefore are not added to the CVA list of updates. What good would that do? An update is an update and it's always released for good reasons, be it new features, bug fixing, security risks, or whatever. I, for one, am perfectly capable of judging whether it is worth updating a program or not. I don't need someone working for Comodo to do that for me.
Logged
Ronny
Product Translator
Global Moderator
Comodo's Hero
Offline
Posts: 5214
Re: CVA missing updates/vulnerability Opera and Filezilla Server - PSI detects
«
Reply #11 on:
May 23, 2009, 04:15:21 AM »
That's the exact reason that they have 3 tabs
- Update available
- Vulnerable
- End of Life
As far as i know they put all software on the database that is submitted back to them so for updates there is nothing to analyze, but before a product get's marked as vulnerable there has to be some sort of verification.
That's what they have to do.
Logged
Forum Volunteer - Any concerns? Please send me a PM and/or review the
Forum Policy !
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.044 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com