Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2013, 06:59:16 PM

Login with username, password and session length

664087 Posts
70636 Topics
145267 Members

Latest Member: SebastianJu

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  Help - CIS
| | | |-+  Defense+ / Sandbox Help - CIS
| | | | |-+  Feedback on Help, FAQs and Guides
« previous next »
Pages: 1 2 [3] Go Down Print
Author Topic: Feedback on Help, FAQs and Guides  (Read 27853 times)
mouse1
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7219


« Reply #30 on: December 01, 2010, 01:53:47 PM »

1- After the reboot everything that is in the sandbox will be automatically terminated and won´t be able to execute (only after manually execution).
No it will run in the sandbox again after the reboot, unless removed from the sandbox in some way, for example by the user making it a trusted file. Because it is sandboxed it is unable to damage your system.

Quote
2- If my first post is right, then that means after the reboot you will not receive pop up´s  from those programs (like com windows hooks, COM interfaces, etc).
You will receive the same pop-ups, if the app is still sandboxed. Most sandboxed files don't generate COM, hook alerts, but some do.

Quote
3- Can an other program (trusted or not) start an application that was terminated in reboot (and of course is in untrusted files).
If an unknown program is started again it is sandboxed and so unable to damage your system.

Quote
4- Manually terminate an application that is in the sandbox will have the same effect than rebooting ( the application won´t be able to automatically start).
If an unknown program is started again, whether automatically or not, it is sandboxed and so unable to damage your system.

Quote
5- what about dropped files
Sandboxed software is not allowed to drop files in protected directories.

Hope this answers your questions. Apologies for the delay.

Mouse
« Last Edit: December 01, 2010, 01:55:38 PM by mouse1 » Logged

mouse1
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7219


« Reply #31 on: December 01, 2010, 02:06:35 PM »

Please add to D+ FAQ:
1. Differences between Comodo Preset Configurations, but not this outdated text. Wink

2. How to enable execution alerts when starting an application from Windows Explorer. Smiley

Good suggestions! Will do my best when I have time. Think differences between CIS and Proactive now small.

If you want to have a go do post here, and I will move to FAQ when ready!

Best wishes

Mike
Logged

Peter5
Comodo's Hero
*****
Offline Offline

Posts: 257



« Reply #32 on: December 15, 2010, 07:28:28 PM »

Thanks for all the answers Mouse.

Logged
mouse1
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7219


« Reply #33 on: December 17, 2010, 04:33:10 PM »

Good suggestions! Will do my best when I have time. Think differences between CIS and Proactive now small.

If you want to have a go do post here, and I will move to FAQ when ready!

Best wishes

Mike

Draft comparison of Proactive and Internet Security Configs added: here.

Please do check if you agree if you have time.
Logged

JoWa
Product Translator
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2935



« Reply #34 on: December 17, 2010, 04:58:39 PM »

Thanks! Smiley Thumb Up
Logged

Ubuntu 13.04, 64-bit | Chrome 27β | Asus P8Z77-M | Intel Core i5 2500K 3,3GHz | 2×4 GB RAM | SSD: OCZ Vertex3 60GB, HDD: 2TB Western Digital Caviar Black | Dell UltraSharp 24" U2410 IPS | Sony MDR-XB1000 | Philips SBC AH1000
MRCS
Comodo Family Member
***
Offline Offline

Posts: 98



« Reply #35 on: January 01, 2011, 03:03:26 PM »

Thanks for the guide; it was a *big* help.

However there was one item that I found a bit confusing,  #5. "ignoring all except AV alerts".  I am well versed in Comodo (though by no means as expert as some), so if I found it confusing, others might too.  Then again, no one else has posted a comment on this so it may only be me.

When you say, "all except AV alerts", surely you don't mean D+ alerts, of which I had quite a few, and the closest thing there to 'ignore' is 'cancel'.  Then of course the program won't run.  I chose the status I wanted for the program.  But of course if you're 'choosing' you're not 'ignoring'.

I may be totally missing something here, so can you please point me in a direction to find an explanation to this confusion.

Logged
mouse1
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7219


« Reply #36 on: January 05, 2011, 05:48:14 AM »

Thanks for the guide; it was a *big* help.

However there was one item that I found a bit confusing,  #5. "ignoring all except AV alerts".  I am well versed in Comodo (though by no means as expert as some), so if I found it confusing, others might too.  Then again, no one else has posted a comment on this so it may only be me.

I mean just literally ignore them they'll time out or not before the next reboot. It does not matter if they don't time out before your reboot. The reason for this policy is to avoid the risk of creating confusing additional rules, which will happen if people answer and tick remember my answer.
Logged

MRCS
Comodo Family Member
***
Offline Offline

Posts: 98



« Reply #37 on: January 05, 2011, 07:53:54 AM »

I mean just literally ignore them they'll time out or not before the next reboot. It does not matter if they don't time out before your reboot. The reason for this policy is to avoid the risk of creating confusing additional rules, which will happen if people answer and tick remember my answer.

Okay.  Thanks for the reply.

Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 492


« Reply #38 on: October 22, 2011, 06:49:10 PM »

From http://forums.comodo.com/defense-sandbox-faq-cis/file-specification-inc-using-wildcards-in-cis-draft-v5-t77245.0.html:
Quote
However there appears to be no simple way to get round this when defining block and allow lists for a specific file or file spec. Block lists under 'customise' in a D+ rule don't over-ride more general allow lists for example, and you cannot define multiple rulesets for the same file or set of files (specified the same way) in D+. However in D+ rules defining the file path once using a string, and the second time an environment variable, does seem to be accepted by D+ and priority ordering may therefore work.

One can get around this by using multiple file groups, with each file group including the same file or file spec.
Logged
mouse1
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 7219


« Reply #39 on: October 23, 2011, 05:19:04 AM »

From http://forums.comodo.com/defense-sandbox-faq-cis/file-specification-inc-using-wildcards-in-cis-draft-v5-t77245.0.html:
One can get around this by using multiple file groups, with each file group including the same file or file spec.

Good thought Smiley. So then priority ordering would potentially work.

Best wishes

Mouse
Logged

Tags:
Pages: 1 2 [3] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.047 seconds with 23 queries.
Powered by SMF 1.1.18 | SMF © 2006, Simple Machines Design by 7dana.com