Welcome, Guest. Please login or register.
March 16, 2010, 05:08:55 AM

Login with username, password and session length

371592 Posts
41141 Topics
93743 Members

Latest Member: parthiban

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products & Services
| |-+  Comodo Internet Security - CIS
| | |-+  News / Announcements / Feedback - CIS
| | | |-+  Wishlist - CIS
| | | | |-+  automated quick scan of critical areas
« previous next »
Pages: [1] Go Down Print
Author Topic: automated quick scan of critical areas  (Read 789 times)
BigMike
Product Translator
Comodo Loves me
*****
Offline Offline

Posts: 181


« on: December 22, 2008, 06:12:41 AM »

Hi, I'd like to suggest a feature, that D+ does from time to time - maybe even at every boot, scan critical areas and alerts the user if something has changed and gives him the possibility to restore the old settings.
I think about something like HijackThis does, but much more userfriendly, advanced and automated Smiley

To be more explicit
- do an automated scan of critical system areas (autostart, services, bhos, host file, network shares...) from time to time
- compare this scan to an older snapshot of the critical areas
- alert the user if something has changed (new, modified or deleted entries) and give him the possibility to set it back to the old state
- alert on obviously misconfigured security settings, which should be changed (for example a network share which is accessible by everyone without a password - or - I'm not a fan of automated updates - but another example would be the automated windows update is disabled or can't work because it's set up wrong in any way)
- alert on potentially security risks (the default settings for WinXP aren't the best in every case - for example by default WinXP saves the LM-Hash of passwords for compatibility reasons with older systems. This is only needed if you want to connect from a machine using Windows ME or earlier (I think it was ME...). Newer systems don't use this Hash anymore for authentication - but if it's saved, your userpassword can be computed in minutes...)
Logged

Latest German translation files for CIS v3 / CIS v4
Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 3369



WWW
« Reply #1 on: December 22, 2008, 07:10:17 AM »

This isn't neccersary as defense+ prevents the whole problem to begin with.

In the future comodo will release "comodo timemachine" that if infected or system instability occurs comodo will revert your system and files back to tip-top shape.
Logged

Windows XP
E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM.  500gb. HDD

Ubuntu
P4 [at] 3ghz, Radeon x300 128mb
1gb DDR2 Ram 80GB HDD
BigMike
Product Translator
Comodo Loves me
*****
Offline Offline

Posts: 181


« Reply #2 on: December 22, 2008, 03:15:29 PM »

I know, that Defense+ will prevent such things - the problem is always the user, who clicks on allow Smiley

For example, I'm playing around with a lot of freeware programs (in my case on a virtual machine and with D+ in paranoid mode). Most applications bring really just the wanted applipaction or ask to install any toolbars, etc...
But there are some, which install also adware, spyware or just more or less useless crap without asking you. And if you execute the installer as "installer/updater" in "installation mode" (and I'm convinced, a lot of people would do so) you wouldn't notice anything during the installation.
Look at Adobe Reader - a useful application from a trusted company. But I simply don't need the quick starter application, which is placed in my autorun (the useless crap from above Wink ). It wastes my resources, any additional running process is also an additional risk (ok, in this case minimal and Defense+ will warn me again, if something is wrong)
But it would be comfortable if CIS would tell me from time to time automatically what has changed on my system. At the moment, either I've to check all the autoruns/bhos... coming to my mind manually from time to time or I may not use any predefined policy, which allows the application to access the registry completely (which is no fun at all with some installers...)
Logged

Latest German translation files for CIS v3 / CIS v4
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.227 seconds with 22 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com