Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 15, 2010, 09:24:52 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
371514
Posts
41131
Topics
93720
Members
Latest Member:
jrovida21
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products & Services
Comodo Internet Security - CIS
Bug Report - CIS
COMODO CIS disables WinSSHD
« previous
next »
Pages:
[
1
]
Author
Topic: COMODO CIS disables WinSSHD (Read 622 times)
pmorenoger
Newbie
Offline
Posts: 9
COMODO CIS disables WinSSHD
«
on:
February 11, 2010, 03:40:22 AM »
I have Windows 7 (x64) and I was planning to use CIS for firewall and antivirus and WinSSHD as an ssh server. Unfortunately, installing CIS makes it impossible to connect from a remote workstation and open an ssh session.
I have configured winsshd.exe as a trusted application, granted all kind of permissions and tried to leave it as "authorized" as possible. Not working.
Then I tried disabling Antivirus, D+, and firewall. Not working.
Then I uninstalled Comodo and it worked.
How can Comodo break WinSSHD even when disabled? After discussion with WinSSHD developers, they mentioned that apparently Comodo was preventing them from executing cmd.exe to support the ssh session.
Thank you for any help you may be able to provide.
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 8080
substance constant, depth variable
Re: COMODO CIS disables WinSSHD
«
Reply #1 on:
February 11, 2010, 04:20:16 AM »
G'day,
If yourPC was going to act as the SSH host and receive unsolicited request for the internet, then you would have to have Global Rules in place to allow the unsolicited packets past the firewall filter.
This is how CIS is designed. The first thing an unsolicited inbound request strikes is the firewall filter. If there aren't any rules that will allow the unsolicited request in, then it will be blocked.
Were there any relevant entries in your logs?
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
pmorenoger
Newbie
Offline
Posts: 9
Re: COMODO CIS disables WinSSHD
«
Reply #2 on:
February 11, 2010, 04:35:41 AM »
Hi!
The problem does not seem to be related to actual inbound network traffic. I can establish the connection from the remote machine, enter my password and get it accepted/rejected. The problem comes when WinSSHD tries to open a cmd.exe session to give me a terminal. It fails to initialize cmd.exe properly and THEN closes the connection.
This behavior happens with the firewall, AV and D+ disabled or enabled (it wouldn't be a rule problem then, right?).
About the logs, I've been looking and cannot find anything related to this. Any hints about where I should be looking?
Thanks!
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 8080
substance constant, depth variable
Re: COMODO CIS disables WinSSHD
«
Reply #3 on:
February 11, 2010, 05:47:16 AM »
Quote from: pmorenoger on February 11, 2010, 04:35:41 AM
The problem comes when WinSSHD tries to open a cmd.exe session to give me a terminal. It fails to initialize cmd.exe properly and THEN closes the connection.
This is definitely Defense+ related then, as D+ is the component that controls executables on the local host.
The quickest way to fix this is to 1) delete whatever policy has been assigend to WinSSHD and then 2) make WinSSHD a "safe file" (providing, of course, that you are certain this executable is actually safe).
STEP 1
Open CIS and click DEFENSE+ -> ADVANCED -> COMPUTER SECURITY POLICY. This will display the listings of all current executable policies. Locate the entry for WinSSHD, click once to select it, click REMOVE and then click APPLY.
STEP 2
Open CIS and click DEFENSE+ -> COMMON TASKS -> MY OWN SAFE FILES. Click ADD -> BROWSE FILES and navigate to the folder containing the WinSSHD executable. Select it and click the "->" button to add the executable to the right hand "Selected Items" panel. Click APPLY. This will add the WinSSHD executable to your personal safe list.
Try and connect via WinSSHD again.
Hope this helps,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
pmorenoger
Newbie
Offline
Posts: 9
Re: COMODO CIS disables WinSSHD
«
Reply #4 on:
February 11, 2010, 06:15:31 AM »
I have tried those steps, unfortunately the behavior has not changed, it still dies when trying to launch cmd.exe. The problem is really weird, why does it lock any behavior even if disabled?
When this happens nothing is written to the log.
Thanks for your interest in this thread.
Logged
EricJH
Global Moderator
Comodo's Hero
Online
Posts: 5685
Re: COMODO CIS disables WinSSHD
«
Reply #5 on:
February 11, 2010, 01:01:41 PM »
Are there entries regarding WinSSHD in the Defens + logs?
Logged
Please read:
Introduction to the Sandbox
Using CIS v4 and always the latest snapshot of Opera browser.
AMD Phenom 925 quad core with 4 GB RAM on MSI 785G E53
pmorenoger
Newbie
Offline
Posts: 9
Re: COMODO CIS disables WinSSHD
«
Reply #6 on:
February 11, 2010, 01:05:16 PM »
Not really. I believe you refer to the window from "View Defense+ Events", which is the closest thing to a log I have seen. In that case, there are no events related to WinSSHd (or cmd.exe).
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 8080
substance constant, depth variable
Re: COMODO CIS disables WinSSHD
«
Reply #7 on:
February 11, 2010, 03:53:29 PM »
Time and circumatances permitting, I'l download it and set it up over the weekend and do some more tests.
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
pmorenoger
Newbie
Offline
Posts: 9
Re: COMODO CIS disables WinSSHD
«
Reply #8 on:
February 12, 2010, 04:22:23 AM »
Thanks for your help, I appreciate the effort.
Logged
pmorenoger
Newbie
Offline
Posts: 9
Re: COMODO CIS disables WinSSHD
«
Reply #9 on:
March 03, 2010, 07:07:00 AM »
I was wondering if there are any updates on this topic.
This is not the only case we are aware of in which COMODO interferes with application launching even when disabled: We also filed a support ticket a few months ago because the presence of COMODO aborts the execution of the "Installer version" of our opensource game-development platform (our README includes a warning stating that the installer cannot work in the presence of COMODO, and we prompt users to download the generic multiplatform version instead).
Both cases seem to be related with applications that launch other applications as a support: WinSSHD is trying to launch cmd.exe and our platform is trying to launch the java virtual machine. In both cases, the malfunction occurs even with comodo disabled (!) and the only solution is to uninstall.
I really like the COMODO platform, more than anything else in the market, but this side-effect is problematic. Are these behaviors and limitations already known? Can they be solved or are they a trade-off from the hooks required to provide good security? (there is at least another firewall solution that presents the same problem)
Logged
futuretech
Comodo Member
Offline
Posts: 40
Re: COMODO CIS disables WinSSHD
«
Reply #10 on:
March 03, 2010, 11:05:07 AM »
Just to be on the same page, when you disable comodo, you mean you right click the CIS tray icon and click disable under Firewall and/or Defence + and not clicking Exit? If yes I will test this out later today after classes. Also make sure you have "Block all the unknown requests when the application is closed" is UN-Checked, which can be found by opening the cis window click Defense+, Advanced, Defense+ Settings.
Logged
pmorenoger
Newbie
Offline
Posts: 9
Re: COMODO CIS disables WinSSHD
«
Reply #11 on:
March 03, 2010, 11:49:16 AM »
Same page:
I mean that I right click the icon, and select "Disabled" for all three services (Defense+, Firewall, AV). The icon remains on screen.
"Block all unknown requests..." is UNchecked.
Thank you!
Logged
futuretech
Comodo Member
Offline
Posts: 40
Re: COMODO CIS disables WinSSHD
«
Reply #12 on:
March 03, 2010, 11:59:53 AM »
Okay good, I will test this out the best that I can. Btw, is this were the offical website to get this software or do I get it somewhere else?
http://www.bitvise.com/winsshd
Logged
pmorenoger
Newbie
Offline
Posts: 9
Re: COMODO CIS disables WinSSHD
«
Reply #13 on:
March 03, 2010, 02:31:43 PM »
Yes, it was there. They have a "Lite" free version.
I actually spent some time in that forum troubleshooting the problem until we narrowed it to COMODO preventing the execution of cmd.exe:
https://fogbugz.bitvise.com/default.asp?WinSSHD.1.13653.0
Thanks!
Logged
futuretech
Comodo Member
Offline
Posts: 40
Re: COMODO CIS disables WinSSHD
«
Reply #14 on:
March 03, 2010, 05:47:24 PM »
I can confirm this, with av/fw/d+ disabled I can not open a terminal, I am using windows 7 x64 too. However, I tested winsshd on my windows xp sp3 32-bit machine and I can open a terminal when I connect from windows 7. The xp also has comodo installed but I kept it enabled, it has defense+ set to safe mode and firewall set to custom policy. When I go to open a terminal using the tunnelier client, comodo on the xp machine alerts that winsshd is trying to execute toterms.exe, I click allow and then get another alert that toterms is trying to execute cmd.exe which in turn I select allow and I am dropped into a cmd prompt. With that being said, I think there is an issue with WinSSHD and windows 7 x64, but you said it worked fine when comodo was uninstalled witch is weird. So I dont know whats going on here, but maybe you can try to use a different ssh server implantation for windows, that is if you are using the lite free version and you didnt pay for the full version already.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.054 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com