Welcome, Guest. Please login or register.
March 19, 2010, 06:44:58 PM

Login with username, password and session length

373014 Posts
41370 Topics
94044 Members

Latest Member: megatrom

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archived Boards
| |-+  Discontinued Products
| | |-+  Comodo Firewall
| | | |-+  Feedback/Comments/Announcements/News
| | | | |-+  URGENT: TRUSTED APPLICATION *EDITABLE* LIST
« previous next »
Pages: [1] Go Down Print
Author Topic: URGENT: TRUSTED APPLICATION *EDITABLE* LIST  (Read 2464 times)
good firewalL
Newbie
*
Offline Offline

Posts: 5



« on: October 13, 2008, 04:21:34 AM »

MAYBE in the the RC2 of CIS 3.5?
It is a massive security flaw to allow manual  trusted application input without being able to review from a list which applications are trusted.

Anyone with access to the windows desktop could add trusted applications & any mistakenly trusted application can't be removed!
 Viva Comodo

« Last Edit: October 13, 2008, 04:24:42 AM by good firewalL » Logged
Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 3369



WWW
« Reply #1 on: October 13, 2008, 04:30:33 AM »

Welcome to the forums  Hug

That's a very good point FirewalL.
So you mean that, Put a password on Comodo and that you can add trusted apps VIA pop-ups?
If you won't want this to happen please look at the screen shot provided.
Logged

Windows XP
E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM.  500gb. HDD

Ubuntu
P4 [at] 3ghz, Radeon x300 128mb
1gb DDR2 Ram 80GB HDD
good firewalL
Newbie
*
Offline Offline

Posts: 5



« Reply #2 on: October 13, 2008, 04:39:52 AM »

while password protecting the application is useful, temporary trusting applications & the level of trust for certain applications is certainly a vital feature to determine what ip's  or ports are trusted for any given software.

Although its cnet.com download (rumoured to perpetuate spyware www.download.com); compare 'online armour free edition':
http://www.tallemu.com/
« Last Edit: October 13, 2008, 04:42:59 AM by good firewalL » Logged
Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 3369



WWW
« Reply #3 on: October 13, 2008, 04:42:27 AM »

Yes however, If the alerts are surpressed - the user won't be alerted and there for can't make any programs trusted.

By the way you have a pretty funny picture lol
Logged

Windows XP
E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM.  500gb. HDD

Ubuntu
P4 [at] 3ghz, Radeon x300 128mb
1gb DDR2 Ram 80GB HDD
gibran
Average User
Comodo's Hero
*****
Offline Offline

Posts: 5063


A bad workman always blames his tools


« Reply #4 on: October 13, 2008, 04:53:53 AM »

while password protecting the application is useful, temporary trusting applications & the level of trust for certain applications is certainly a vital feature to determine what ip's  or ports are trusted for any given software.

Although its cnet.com download (rumoured to perpetuate spyware www.download.com); compare 'online armour free edition':
http://www.tallemu.com/


Parental control is meant to prevent unauthorized editing of configurations.
Besides if an use mark an app to be trusted it would be possible to manually revoke that mistake.

If you are suggesting to add a limited functionality mode that allow only whitelisted apps to be learned this should be already possible enabling the settings suggested by kyle and setting D+ to Safe mode.

In that case whitelisted apps (apps considered safe by Comodo) or added to Safe list will be learned without alerts (it's possible to prevent untrusted users to do this using parental control as above).

This way legitimate users can have full control.
« Last Edit: October 13, 2008, 05:02:06 AM by gibran » Logged

"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams
good firewalL
Newbie
*
Offline Offline

Posts: 5



« Reply #5 on: October 14, 2008, 11:30:17 PM »

Parental control is meant to prevent unauthorized editing of configurations.
Besides if an use mark an app to be trusted it would be possible to manually revoke that mistake.

WAIT I SEE NOW UNDER  "NETWORK SECURITY POLICY"...MAYBE THE SECTION SHOULD BE CHANGED TO "APPLICATION SECURITY POLICY"




READ OR DISREGARD, i wrote this before  I had  FOUND "NETWORK SECURITY POLICY" section:

How is this done?Huh??

I meant a list that defines which applications are trusted and what functionaility is allowed.

For example;
internet explorer port 80 TCP , 8080 TCP , 21 TCP   - would CLEARLY allow the user to know that INTERNET explorer is trusted as web browser and FTP client.
If  a strange port number was mentioned for example UDP port 31337 (back orfice trojan) it is important to be able to remove that single port access functionality so LEGITMATE software is not acting like spyware or to clearly identify spyware.

I have not been able to find the option to LIST the applications i have allowed ANY sort of access for , neither those I've defined as trusted!

THERE is a list of TRUSTED Software VENDORS, but  not useful if i want to trust software and block another software from the same vendor , internet explorer and outlook express for example.

the firewall has excellent ADVANCED FIREWALL FEATURES UNDER THAT TITLED TAB


« Last Edit: October 14, 2008, 11:39:12 PM by good firewalL » Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 8102


substance constant, depth variable


« Reply #6 on: October 15, 2008, 12:36:26 AM »


I meant a list that defines which applications are trusted and what functionaility is allowed.

For example;
internet explorer port 80 TCP , 8080 TCP , 21 TCP   - would CLEARLY allow the user to know that INTERNET explorer is trusted as web browser and FTP client.


If you click FIREWALL -> ADVANCED -> NETWORK SECURITY POLICY -> APPLICATION RULES, you'll see the list of what application have been granted or denied access on your system. The tightness or looseness of the rule (ports, direction, protocol, address etc.) is determined by the alert settings, found in FIREWALL -> ADVANCED -> FIREWALL BEHAVIOUR SETTINGS -> ALERT SETTINGS.

You can define sets of ports (FIREWALL -> COMMON TASKS -> MY PORT SETS) and apply these to applications which would explicitly restrict them to those ports.

Quote

If a strange port number was mentioned for example UDP port 31337 (back orfice trojan) it is important to be able to remove that single port access functionality so LEGITMATE software is not acting like spyware or to clearly identify spyware.


You can create a network rule that explicitly blocks individual known bad ports or you could create a port set of known bad ports and use this port set in a block rule.

Quote

I have not been able to find the option to LIST the applications i have allowed ANY sort of access for , neither those I've defined as trusted!


See FIREWALL -> ADVANCED -> NETWORK SECURITY POLICY -> APPLICATION RULES

Cheers,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.066 seconds with 18 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com