Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
June 19, 2013, 07:53:07 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
668872
Posts
71127
Topics
145735
Members
Latest Member:
Broderic
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
Help - CIS
Defense+ / Sandbox Help - CIS
D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
« previous
next »
Pages:
[
1
]
Author
Topic: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on? (Read 7218 times)
Swordfish
Newbie
Offline
Posts: 14
D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
on:
October 31, 2008, 02:28:29 PM »
Hello,
yesterday, I installed CIS (haiving previously uninstalled CPF - was very happy with that and decided to give a CIS a try) and found out something strange. Maybe it's not exactly a bug, but for me it's a bit weird.
CASE #1:
I run, for example a Sandboxed (SandboxIE) uTorrent from ObjectDock and D+ doesn't ask me if I allow an ObjectDock.exe to start Start.exe (SandboxIE component), the first notification I get about is whether to allow uTorrent to connect to the net. No notifications about running Sandbox IE components, running uTorrent..
In this case, when I go into settings and D+ tab, in Computer Security Policy I see new rules (but, while clickig on allow I wasn't marking the box to remember my choice, so where are these new rules from? - it would be normal in Learing Mode but D+ is all the time in Safe Mode setting).
I manually delete the new rules for all the above applications but D+ acts like they were still there (still no monits about running Start.exe, uTorrent and SandboIE components).
However, when trying do install a new app (that wasn't there on my pc when CIS was being installed) I get all the monits, just like everything would be fine. In Computer Security Policy there are no new rules emerging. All this happens in Safe Mode.
To me looks like if D+ in Safe Mode was acting like if it was in Clean PC mode. Strange.
In Paranoid Mode everything works fine.
My config: XP SP2 32bit, CIS + Avira + BOClean + TF.
Maybe it isn't exactly a bug but simply a different behavior of D+ in CIS compared to CPF, however, I decided to post it here.
(Will post screenshots ASAP).
Kind Regards.
Logged
--
"Non quia difficilia sunt non audemus, sed quia non audemus, difficilia sunt."
Security setup: CIS + GesWall + SRWare Iron + Prevx + Avira...
HW setup: E4500 2.2[at]3.01 GHz rock solid w. Noctua NH-U12, Asus P5K, A-Data Extreme 1066, WD Raptor
weaker
Usability Study Member
Comodo's Hero
Offline
Posts: 505
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #1 on:
October 31, 2008, 03:32:26 PM »
Perhaps it depends if you installed the "Recommended" configuration or the "Max security" config. I use the "Max security" one and get as much pop-ups as I got with v3.0.x.
Logged
3xist
Guest
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #2 on:
October 31, 2008, 06:22:06 PM »
The whole idea is to reduce pop ups with the AV Architecture, While still having Prevention as your first line of Defense.
Josh
Logged
weaker
Usability Study Member
Comodo's Hero
Offline
Posts: 505
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #3 on:
November 02, 2008, 08:47:07 AM »
I'm quite sure that between 3xist's and my post there was an additional answer from someone else.
This was not for the first time where I have the feeling that posts just disappear.
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3678
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #4 on:
November 02, 2008, 09:43:39 AM »
Cause the default setting in CIS is meant to rely on severall layers to help protect you.. spread the butter on the toast.
Although my view is the default settings aren't bullet proof like "Proactive security" is.
Logged
Windows 7 x64
AMD FX 8120, 8gb ram, ATI 6870 1gb
fOrTy_7
Comodo's Hero
Offline
Posts: 587
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #5 on:
November 02, 2008, 09:52:16 AM »
[ at ]Swordfish:
I suggest you to read a description of each Defense+ security level setting. The behaviour of Defense+ you described is completely expected when user starts an application which is on Comodo's safe list (white list and ObjectDock is on it. I didn't check the rest.). This way Defense+ reduces the amount of alerts and you're completle safe since these applications were previously examined by Comodo's experts.
Quote
Train with
Safe Mode: While monitoring critical system activity, Defense+ will automatically learn the activity of executables and applications certified as 'Safe' by Comodo. It will also automatically create 'Allow' rules these activities. For non-certified, unknown, applications, you will receive an alert whenever that application attempts to run. Should you choose, you can add that new application to the safe list by choosing 'Treat this application as a Trusted Application' at the alert. This will instruct the Defense+ not to generate an alert the next time it runs. If your machine is not new or known to be free of malware and other threats as in 'Clean PC Mode' then
Train with
Safe Mode' is recommended setting for most users - combining the highest levels of security with an easy-to-manage number of Defense+ alerts.
safe_mode_description.png
(7.97 KB, 511x421 - viewed 13 times.)
«
Last Edit: November 02, 2008, 09:58:57 AM by fOrTy_7
»
Logged
Windows 7 Pro 6.1.7601 x64 Service Pack 1
Comodo Internet Security 5.10.228257.2253
AV: Stateful, FW: Safe, D+: Safe, SB: Enabled
Swordfish
Newbie
Offline
Posts: 14
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #6 on:
November 06, 2008, 06:03:01 PM »
Ok, I get the idea but... is there a possibility that D+ in Safe Mode would behave exactly like it did in CPF? (I mean that it would not add "safe" applications to my Computer Security Policy Rules?).
Asking, because now I use Paranoid Mode and it'a a bit too much.
And - how safe a "safe" application really is? (scanned with one A/V engine or more?, a behavior analysis? or whatever? what a situation when a "safe" executable have been tampered with?)
Regards
Logged
--
"Non quia difficilia sunt non audemus, sed quia non audemus, difficilia sunt."
Security setup: CIS + GesWall + SRWare Iron + Prevx + Avira...
HW setup: E4500 2.2[at]3.01 GHz rock solid w. Noctua NH-U12, Asus P5K, A-Data Extreme 1066, WD Raptor
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3678
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #7 on:
November 06, 2008, 09:47:22 PM »
Quote from: Swordfish on November 06, 2008, 06:03:01 PM
Ok, I get the idea but... is there a possibility that D+ in Safe Mode would behave exactly like it did in CPF? (I mean that it would not add "safe" applications to my Computer Security Policy Rules?).
Asking, because now I use Paranoid Mode and it'a a bit too much.
And - how safe a "safe" application really is? (scanned with one A/V engine or more?, a behavior analysis? or whatever? what a situation when a "safe" executable have been tampered with?)
Regards
It's considered safe by comodo staff. It's safe
Logged
Windows 7 x64
AMD FX 8120, 8gb ram, ATI 6870 1gb
dchernyakov
Comodo's Hero
Offline
Posts: 286
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #8 on:
November 07, 2008, 10:24:33 AM »
Quote from: Swordfish on November 06, 2008, 06:03:01 PM
is there a possibility that D+ in Safe Mode would behave exactly like it did in CPF? (I mean that it would not add "safe" applications to my Computer Security Policy Rules?).
CIS has more safe signatures in safe files database than CFP - that could be the reason why some files has not been assumed safe by CFP are assumed safe by CIS now.
Logged
Swordfish
Newbie
Offline
Posts: 14
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #9 on:
November 12, 2008, 09:34:47 AM »
Quote from: dchernyakov on November 07, 2008, 10:24:33 AM
CIS has more safe signatures in safe files database than CFP - that could be the reason why some files has not been assumed safe by CFP are assumed safe by CIS now.
Thank you, but I will try to ask again:
Is there a possibility to make D+ not insert new rules automatically (for safe applications) in Computer Security Policy rules in Safe Mode? Or do I have to go back to CPF or use Paranoid Mode in CIS?
btw. It's a bit stange - some not everyday apps like SandboxIE are known for CIS (considered thus as safe) and, for example firefox.exe could not be recognized. Please take a look at the attachment.
I was a die-hard CPF user for a long time and I must admit that I'm a little disappointed with that change of D+ behavior, not only because of a large gap between Safe and Paranoid mode now, but more because the very interesting way CIS differentiates known (.i.e. safe) and unknown (i.e. unsafe) applications.
Ok, I understand that this (auto adding "known" to Comp. Sec. Policy in Safe Mode )will make life easier for the 80% of users, but what about the rest 20%? Bo they really have to go Paranoid?
And, for now, CIS in Safe Rules makes automatically rules for uTorrent, which is - but this is of course my opinion - potentially more dangerous, than up-to-date Firefox (with NoScript and etc.).
Just one last question - because it keeps coming back - regarding use of of AV architecture (especially in the light of 3xist and Kyle posts): what do you mean by that? To be precise: if a file is scanned with one A/V engine and then it's considered safe or is it scanned using more sophisticated A/V mechanism like CAVS?
Best regards
ff_and_CIS.JPG
(161.83 KB, 1199x814 - viewed 11 times.)
«
Last Edit: November 12, 2008, 09:49:17 AM by Swordfish
»
Logged
--
"Non quia difficilia sunt non audemus, sed quia non audemus, difficilia sunt."
Security setup: CIS + GesWall + SRWare Iron + Prevx + Avira...
HW setup: E4500 2.2[at]3.01 GHz rock solid w. Noctua NH-U12, Asus P5K, A-Data Extreme 1066, WD Raptor
gibran
Average User
Comodo's Hero
Offline
Posts: 5056
A bad workman always blames his tools
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #10 on:
November 12, 2008, 10:21:26 AM »
Quote from: Swordfish on November 06, 2008, 06:03:01 PM
Ok, I get the idea but... is there a possibility that D+ in Safe Mode would behave exactly like it did in CPF? (I mean that it would not add "safe" applications to my Computer Security Policy Rules?).
There is no change in that regard. D+ Safe Mode added safe apps automatically even before (eg. notepad.exe)
One relevant change different from CFP is that explorer.exe
Treat As
policy is set to
windows system applications
(previously it was trusted app or custom) thus explorer will not trigger an execute alert even for unknown apps.
As for Firefox.exe not in the safelist I guess it could be due to the fact FF is usually updated and it is more likely that it is needed to perform a manual Lookup (eg from pending file dialog) to confirm it was whitelisted (safelisted).
Since FF is a digitally signed app it would be possible to add Mozilla code signing certificates to trusted vendors to have all mozilla apps considered trusted.
To prevent automatically training triggered by safe mode the only way would be to set each ASK permission to block or use D+ paranoid mode.
«
Last Edit: November 12, 2008, 10:54:14 AM by gibran
»
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
Swordfish
Newbie
Offline
Posts: 14
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #11 on:
November 12, 2008, 10:38:23 AM »
Gibran, thank you very much for your answer, really appreciate it
Logged
--
"Non quia difficilia sunt non audemus, sed quia non audemus, difficilia sunt."
Security setup: CIS + GesWall + SRWare Iron + Prevx + Avira...
HW setup: E4500 2.2[at]3.01 GHz rock solid w. Noctua NH-U12, Asus P5K, A-Data Extreme 1066, WD Raptor
gibran
Average User
Comodo's Hero
Offline
Posts: 5056
A bad workman always blames his tools
Re: D+ in Safe Mode acts like if it was in Clean PC Mode.. what's going on?
«
Reply #12 on:
November 12, 2008, 11:45:55 AM »
Quote from: Swordfish on November 12, 2008, 10:38:23 AM
Gibran, thank you very much for your answer, really appreciate it
TBH I'm searching for something in between safe and paranoid mode too.
The only way to get alerts for ASK access rights is to use paranoind mode (To my understanding every policy-less app can be regarded as having an all Ask policy)
IIRC Safe mode will basically learn many behaviours that have not been explicitly set to allow or block (setting those rights to block has proven to be unsatisfactory for me and I had to revert them to ask for troubleshooting purposes).
It is entirely possible that a custom policy has some Ask enties and AFAIK non paranoid modes can add new entries for these access rights.
To my current understanding a whitelisted app has less privileges than a trusted app.
In fact even if notepad.exe is whitelisted it still triggers an alert if I attempt to create a bogus executable (eg test.exe) in D+ safe mode.
I didn't make the necessary tests to confirm other restrictions imposed on safelisted apps but I would appreciate a way to disable the safe behaviour for specific safelisted apps and known if they are safelisted after an CIS/CFP update (only possible using manual lookup).
This will provide me a way to watch over specifc safelisted apps and get an alert when they attempt something new and at the same time have other safe apps automatically learned.
Even if D+ is designed to be a malware prevention app I'm inclined to explore its uses as a system gatekeeper and have it enforce app specific policies and watch over specific entities in the same way a firewall can be used to restrict even legit connections (eg update requests).
IMHO there are some features that even if they could be considered legitimate by some they could be deemed unnecessary by others.
«
Last Edit: November 12, 2008, 11:52:27 AM by gibran
»
Logged
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."-
Douglas Adams
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.053 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com