Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 11, 2008, 08:31:42 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199466
Posts
22903
Topics
54972
Members
Latest Member:
rexSmall
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Feedback/Comments/Announcements/News
Defense+ file integrity detection
« previous
next »
Poll
Question:
EDIT by Mod: Changed Topic title to not be a joke
Members can change their own topic titles themselves editing the subject field of their 1st post.
0 (0%)
Please remember to keep this topic polite and avoid personal attacks.
0 (0%)
Please submit suggestions to
Comodo Firewall Wishlist V6
0 (0%)
Total Voters: 0
Pages:
[
1
]
2
3
...
5
Author
Topic: Defense+ file integrity detection (Read 3199 times)
gpnx
Comodo Member
Offline
Posts: 27
Defense+ file integrity detection
«
on:
July 13, 2008, 04:41:04 PM »
I was having really high hopes to replace the Tiny Firewall Pro i am using with Comodo (because of switching to vista) but i guess comodo is not there yet.
What a HIPS is for if it does not do INTEGRITY check on the executables with the original that the policy was applied to? You put some policy on executable and then modify this executable and the comodo does still think its the old executable and applies the same policy w/o even a warning...and thats how most of the malware comes to your pc ... via some trusted system component who got hacked.
I really don't get it why you guys don't have that yet and seems like some of you don't think its necessary...
All the serious HIPS have integrity checks...
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Defense+ file integrity detection
«
Reply #1 on:
July 13, 2008, 04:47:09 PM »
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Defense+ file integrity detection
«
Reply #2 on:
July 13, 2008, 04:54:45 PM »
Well thats odd cause I can prove you wrong. I just downloaded the GRC leak test and ran it and it past. Then I deleted the entries of the leak test in the firewall and D+. Then I renamed the leak test like GRC says to. I renamed it Firefox.exe which is an already trusted program and guess what. D+ gave me an alert. Works fine for me.
Logged
gpnx
Comodo Member
Offline
Posts: 27
Re: Defense+ file integrity detection
«
Reply #3 on:
July 13, 2008, 06:02:03 PM »
Here is what i did:
put a notepad.exe in some folder. run it. allow all the activit (its the notepad..) downloaded some of the leaktests (the one which changes the desktop - breakout2.exe). replaced with it the notepad.exe in that folder... it ran using the notepad security ( it means it changed my desktop etc..)
now, maybe in your case firefox.exe is in the "my protected files"?
i tried puting that notepad.exe in "My safe files", but there is still no integrity check for them either...what a joke again.
don't get me wrong, i like comodo (at least the interface), but this is unaceptable non integrity check version.
I really really would suggest the developers to take a look at the Tiny Firewall Pro 6.5.xxxx . I think thats the best firewa//hips. I really really regretd CA bought them and shelved the tiny - seems like that , cuz their firewall is completely different.
I will be interested which files/group you put you firefox. But anyway, the fact is there is no integrity check. You may protect your files with some non modifying policy , but i can do that with the NTFS too.. Why i need comodo HIPS then?
«
Last Edit: July 13, 2008, 06:03:59 PM by gpnx
»
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Defense+ file integrity detection
«
Reply #4 on:
July 13, 2008, 06:27:48 PM »
I do not use protected files. Everything is at default values from install except I use D+ in safe mode. Which option are you using D+ in I might ask? Do you know what all the different levels of D+ mean?
Paranoid Mode: This is the highest security level setting and means that Defense+ will monitor and control all executable files apart from those that you have deemed safe. The firewall will not attempt to learn the behavior of any applications - even those applications on the Comodo safe list. and will only use your configuration settings to filter critical system activity. Similarly, the firewall will not automatically create 'Allow' rules for any executables - although you still have the option to treat an application as 'Trusted' at the Defense+ alert. Choosing this option will generate the most amount of Defense+ alerts and is recommended for advanced users that require complete awareness of activity on their system.
Safe Mode: While monitoring critical system activity, the firewall will automatically learn the activity of executables and applications certified as 'Safe' by Comodo. It will also automatically create 'Allow' rules these activities. For non-certified, unknown, applications, you will receive an alert whenever that application attempts to run. Should you choose, you can add that new application to the safe list by choosing 'Treat this application as a Trusted Application' at the alert. This will instruct the firewall not to generate an alert the next time it runs. If your machine is not new or known to be free of malware and other threats as in 'Clean PC Mode' then Safe Mode' is recommended setting for most users - combining the highest levels of security with an easy-to-manage number of Defense+ alerts.
Clean PC Mode: From the time you set the slider to 'Clean PC Mode', Defense+ will learn the activities of the applications currently installed on the computer while all new executables introduced to the system are monitored and controlled. This patent-pending mode of operation is the recommended option on a new computer or one that the user knows to be clean of malware and other threats. From this point onwards Defense+ will alert the user whenever a new, unrecognized application is being installed. In this mode, the files in 'My Pending Files' are excluded from being considered as clean and are monitored and controlled.
'Installation Mode: Installer applications and updaters may need to execute other processes in order to run effectively. These are called 'Child Processes'. In 'Paranoid', Safe' and 'Clean PC modes', Defense+ would raise an alert every time these child processes attempted to execute because they have no access rights. Whilst in one of these 3 modes, Comodo Firewall Pro will make it easy to install new applications that you trust by offering you the opportunity to temporarily engage 'Installation Mode' - which will temporarily bestow these child processes with the same access rights as the parent process - so allowing the installation to proceed without the usual alerts
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Defense+ file integrity detection
«
Reply #5 on:
July 13, 2008, 06:32:09 PM »
Tiny Firewall isn't even listed in Matousec. Not even on the bottom so how good can it be.
Logged
gpnx
Comodo Member
Offline
Posts: 27
Re: Defense+ file integrity detection
«
Reply #6 on:
July 13, 2008, 07:04:12 PM »
1) Tiny is not listed because CA bought them like 1-2 years ago.
2) i use even paranoid mode. the same result. just do what i did and will see.
If you search the forums here, there are more post/complains/feedback about this missing feature. Is not just me and i am not trying to bash comodo..i want them to implement this so i can use it.
Some of the comodo developers/moderators are trying to explain that i don't need this (haha, joke) because comodo does some more file protection or w/e their explanation is. Its a joke explanation because the user don't know all the time what happens on the system. For example you run an install on a product and you don't know what it modifies - what if its a malware and modifies a settings for which you have rules ? Here the integrity will help - next time you try to run a modified progy, you will get information.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Defense+ file integrity detection
«
Reply #7 on:
July 13, 2008, 07:12:54 PM »
Well it seems to me like your bashing. BTW I never download and install anything I do not know. I also scan everything before opening it. If I doubt the program I am installing then I Sandbox it.
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 1018
Re: Defense+ file integrity detection
«
Reply #8 on:
July 13, 2008, 08:19:10 PM »
I ran the SSS utility to test your theory, I treated it as a Trusted application so everything it will do will be allowed. I then renamed the SSS utility to ZZZ, I tried to create a registry entry with ZZZ and D+ popped up.
Logged
Current Goals;
* Run 10kms without taking a break, 7kms so far.
* 100 push ups, 50 so far.
* Do my bit for the world by joining the army.
* Learn C++ as a long term goal, Currently learning.
gpnx
Comodo Member
Offline
Posts: 27
Re: Defense+ file integrity detection
«
Reply #9 on:
July 13, 2008, 08:31:57 PM »
Vettetech:
1) Again, if you consider bashing constructive critique, this is your problem
2) If you do all these things (sandbox, etc..) then why you need HIPS at all then? And the usual user don't bother with these things....
Kyle:
Do what i did and lets see... What is the dialog box that poped up? I am testing comodo 3.0.25.378 x64 on vista. maybe there is bug with it. would be happy if thats the case. Maybe i am not doing something right. Would be even happier if thats the case.
Logged
egemen
Administrator
Comodo's Hero
Offline
Posts: 1737
Re: Defense+ file integrity detection
«
Reply #10 on:
July 13, 2008, 09:12:29 PM »
Quote from: gpnx on July 13, 2008, 06:02:03 PM
Here is what i did:
put a notepad.exe in some folder. run it. allow all the activit (its the notepad..) downloaded some of the leaktests (the one which changes the desktop - breakout2.exe). replaced with it the notepad.exe in that folder...
At this point, you are skipping something:
You manually replacing a file and a virus replacing/infecting a file are 2 different things and D+ default policy is aware of this fact. So unless you dont use explorer.exe, D+ will NOT allow any file replacements without any authorization. What makes you think that a virus can infect a file without being catched by D+?
To better understand please search this forum first. I have explained this before.
D+ is a sophisticated piece of security software, and you changing something manually will be known by D+ as a non-malicious act, and because of its intelligence manual modifications like what you did, will be allowed without disturbing you. Try to do that in a way that malware would and see how D+ will pounce on it! Pls give us "some" credit! We have innovated new ways of checking for integrity which is more efficient and doesn't disturb the user as often!
«
Last Edit: July 13, 2008, 09:19:01 PM by Melih
»
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Defense+ file integrity detection
«
Reply #11 on:
July 13, 2008, 09:16:30 PM »
Very true egemen. A virus has to run first and when it tries to run D+ will catch it. You are manually doing this which a virus cannot do invisibly. I Sandbox my browser when needed not my whole pc. If you use Sandboxie you still need and HIPS and AV and Firewall.
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 5686
Re: Defense+ file integrity detection
«
Reply #12 on:
July 13, 2008, 09:20:05 PM »
Quote from: Vettetech on July 13, 2008, 09:16:30 PM
Very true egemen. A virus has to run first and when it tries to run D+ will catch it. You are manually doing this which a virus cannot do invisibly. I Sandbox my browser when needed not my whole pc. If you use Sandboxie you still need and HIPS and AV and Firewall.
You are right. even if you run a sandbox you will still need to run security apps as some malware can jump out of a sandbox right into your OS.
Melih
Logged
Visit Melih's Blog
Vettetech
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 4631
Re: Defense+ file integrity detection
«
Reply #13 on:
July 13, 2008, 09:34:06 PM »
Listen gpnx. Anyone who makes a thread and calls it " D+ what a joke" is clearly bashing. Why didn't you go into the Comodo help area and ask why does D+ fail this. That would have been a better thing to do.
Logged
gpnx
Comodo Member
Offline
Posts: 27
Re: Defense+ file integrity detection
«
Reply #14 on:
July 13, 2008, 10:14:54 PM »
Feel free to move this thread to whatever is the appropriated forum. I didnt consider "what a joke" bashing... but if sounded like this i am sorry. As you see from my msg context i am not bashing, just trying to help improve it.
Logged
Tags:
Pages:
[
1
]
2
3
...
5
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.103 seconds with 21 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com