Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
September 06, 2008, 04:24:53 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
189127
Posts
22037
Topics
52849
Members
Latest Member:
sallu79
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Feedback/Comments/Announcements/News
Rules associated with "OLE Automation" alerts
« previous
next »
Pages:
[
1
]
Author
Topic: Rules associated with "OLE Automation" alerts (Read 2178 times)
NewUser
Newbie
Offline
Posts: 10
Rules associated with "OLE Automation" alerts
«
on:
October 11, 2006, 02:36:24 AM »
When I deny access from an "OLE Automation" pop-up a generic rule is created that will always block the application making the actual connection attempt (svchost.exe, for example). Is there a way to create a rule that will only block the connection when a specific component (WGATray.exe, for example) is the one trying to connect through svchost.exe?
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Rules associated with "OLE Automation" alerts
«
Reply #1 on:
October 17, 2006, 01:35:20 PM »
Quote from: NewUser on October 11, 2006, 02:36:24 AM
When I deny access from an "OLE Automation" pop-up a generic rule is created that will always block the application making the actual connection attempt (svchost.exe, for example). Is there a way to create a rule that will only block the connection when a specific component (WGATray.exe, for example) is the one trying to connect through svchost.exe?
If I understand correctly from the other postings on OLE Automation issues, unless you click to remember the response, CPF only stores that response until the next reboot (which for some users causes their entire internet to be blocked until they reboot).
Keeping that in mind, what I have done is created an Application Rule, adding the app in question (ie, wgatray.exe) and setting it to be blocked from connecting to the internet. Then it should not matter how the app attempts to connect, whether svchost or other means - it should be blocked.
Hopefully one of the resident forum gurus will respond and give a better explanation. In the meantime, hope this helps somewhat.
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Rules associated with "OLE Automation" alerts
«
Reply #2 on:
October 17, 2006, 01:54:01 PM »
Also, here's a couple links to threads dealing with OLE issues, for more info.
http://forums.comodo.com/index.php/topic,3163.0.html
http://forums.comodo.com/index.php/topic,3159.0/topicseen.html
And, if you go to the Firewall homepage, then to Help, then to the search field, and type in "OLE" you'll get a ton of results; many of them dealing with the security aspects of OLE automation, allowing the apps, etc.
I've created a link which should hopefully work; you might need to refresh once you get there, to get the latest results. {edit - the link will open a window prompting for a search topic - that's where you'll put in OLE}
http://forums.comodo.com/index.php?action=search2
«
Last Edit: October 17, 2006, 01:55:33 PM by Little Mac
»
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
NewUser
Newbie
Offline
Posts: 10
Re: Rules associated with "OLE Automation" alerts
«
Reply #3 on:
October 17, 2006, 02:33:35 PM »
Thanks for your suggestion, Little Mac. I'll try manually adding rules to block undesired apps that attempt to connect through svchost or iexplore.
By the way, I have also experienced the issue discussed in the thread you pointed out (
http://forums.comodo.com/index.php/topic,3163.0.html
) where denying an OLE attempt results in internet connectivity being lost until the system is rebooted.
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Rules associated with "OLE Automation" alerts
«
Reply #4 on:
October 17, 2006, 02:40:11 PM »
Quote from: NewUser on October 17, 2006, 02:33:35 PM
By the way, I have also experienced the issue discussed in the thread you pointed out (
http://forums.comodo.com/index.php/topic,3163.0.html
) where denying an OLE attempt results in internet connectivity being lost until the system is rebooted.
Yeah, I did too, when I changed from Internet Explorer to FireFox. Fortunately I had already read about, and experienced similar things w/other security products in the past.
Hope that will help w/UR situation; not a problem at all. I strive to give comfort to others in the manner in which comfort was provided to me.
</humor>
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
NewUser
Newbie
Offline
Posts: 10
Re: Rules associated with "OLE Automation" alerts
«
Reply #5 on:
October 20, 2006, 01:06:24 AM »
It looks like a rule to block an application will only stop it from connecting directly to the Internet, but not from connecting indirectly through another application like svchost or iexplore (I still get the OLE Automation pop-ups).
Logged
comicfan2000
Guest
Re: Rules associated with "OLE Automation" alerts
«
Reply #6 on:
October 20, 2006, 01:09:32 AM »
Quote from: NewUser on October 20, 2006, 01:06:24 AM
It looks like a rule to block an application will only stop it from connecting directly to the Internet, but not from connecting indirectly through another application like svchost or iexplore (I still get the OLE Automation pop-ups).
Hi, if you want fewer alerts do this..
Go to >advanced > application behavior analysis > then uncheck > monitor com\ole automation attempts.
Paul
Logged
NewUser
Newbie
Offline
Posts: 10
Re: Rules associated with "OLE Automation" alerts
«
Reply #7 on:
October 20, 2006, 04:45:55 PM »
Disabling the monitoring of COM/OLE automation attempts probably means that those attempts will then be allowed, which is not what I wanted. I was hoping that rules to block them could be created.
Logged
comicfan2000
Guest
Re: Rules associated with "OLE Automation" alerts
«
Reply #8 on:
October 20, 2006, 05:28:16 PM »
Quote from: NewUser on October 20, 2006, 04:45:55 PM
Disabling the monitoring of COM/OLE automation attempts probably means that those attempts will then be allowed, which is not what I wanted. I was hoping that rules to block them could be created.
I see, perhaps you can copy the attempt and the dll, or exe file (write it down) find and block it in component monitor if listed.
Paul
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Rules associated with "OLE Automation" alerts
«
Reply #9 on:
October 20, 2006, 05:57:27 PM »
I'd kinda like to know the answer to the question myself. Other than when I first started CPF, or switched from IE to FF, or installing a new program, I don't get those types of requests. Just today I denied an application attempting to do an OLE connect; the executing application was denied, but it did not block the connecting application (ie, svchost.exe). So, do I have something set differently?
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
NewUser
Newbie
Offline
Posts: 10
Re: Rules associated with "OLE Automation" alerts
«
Reply #10 on:
October 20, 2006, 08:26:53 PM »
The specific problem I have been experiencing goes something like this:
1) OLE Automation alert for application trying to connect through svchost pops up
2) I deny the attempt without selecting the "remember" option
3) I put the notebook into hybernation
4) I wake the notebook from hybernation
5) Now the notebook cannot acquire an IP address from the router because access is denied to svchost (log entries confirm this)
6) To restore connectivity I have to either disable the firewall temporarily while the wireless connection is being re-established after coming out of hybernation, or reboot.
Logged
comicfan2000
Guest
Re: Rules associated with "OLE Automation" alerts
«
Reply #11 on:
October 20, 2006, 08:58:35 PM »
Quote from: NewUser on October 20, 2006, 08:26:53 PM
The specific problem I have been experiencing goes something like this:
1) OLE Automation alert for application trying to connect through svchost pops up
2) I deny the attempt without selecting the "remember" option
3) I put the notebook into hybernation
4) I wake the notebook from hybernation
5) Now the notebook cannot acquire an IP address from the router because access is denied to svchost (log entries confirm this)
6) To restore connectivity I have to either disable the firewall temporarily while the wireless connection is being re-established after coming out of hybernation, or reboot.
This is an issue and hopefully will be fixed in next version.
Paul
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6011
Re: Rules associated with "OLE Automation" alerts
«
Reply #12 on:
October 23, 2006, 09:14:18 AM »
Hey, NewUser,
I liked your post in the CPF Wishlist
http://forums.comodo.com/index.php/topic,1202.240.html
; very concise, thought-out; great!
It's interesting (confusing?) the way computer issues go; one person has a problem with an app that another does not, even with similarities of system and associated apps. That's why I'd never make it as a programmer, or a tech. What should be logical order is so frequently seemingly illogical chaos! Too many variables, I guess.
Hope your post over there engenders positive results.
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
NewUser
Newbie
Offline
Posts: 10
Re: Rules associated with "OLE Automation" alerts
«
Reply #13 on:
October 24, 2006, 02:28:33 AM »
Thanks for the kind words, LM. It's always nice to get some positive feedback.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.128 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com