Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 21, 2010, 07:13:56 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
373411
Posts
41421
Topics
94148
Members
Latest Member:
Sebo77
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
CFP- Poor Pop up alerts by compared with other HIPS?
« previous
next »
Pages:
[
1
]
2
3
4
Author
Topic: CFP- Poor Pop up alerts by compared with other HIPS? (Read 7633 times)
aigle
Comodo's Hero
Offline
Posts: 521
CFP- Poor Pop up alerts by compared with other HIPS?
«
on:
August 18, 2009, 02:35:08 PM »
I have made a thread here.I think no need to re-write it here.
http://www.wilderssecurity.com/showthread.php?p=1526872#post1526872
What are your thoughts?
Thanks
«
Last Edit: August 18, 2009, 06:42:45 PM by aigle
»
Logged
forcespawn
Comodo Member
Offline
Posts: 44
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #1 on:
August 18, 2009, 03:25:39 PM »
Quote from: aigle on August 18, 2009, 02:35:08 PM
I have madethe thraed here.I think no need to re-write it here.
http://www.wilderssecurity.com/showthread.php?p=1526872#post1526872
What are your thoughts?
Thanks
Thanks for the tests. I'm concerned that critical driver installation alerts are hidden within registry alerts, to say the least, and I think Defense+ would be greatly improved by alerting users directly to driver installations instead of registry changes. Please post your findings here, because someone has made this suggestion to the wishlist:
https://forums.comodo.com/defense_wishlist/on_driver_install_say_driver_install_not_registry_modification-t43954.0.html
Logged
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #2 on:
August 18, 2009, 06:29:44 PM »
Most people won't understand any of those alerts.. Thats a problem with HIPS..
I don't think saying that a "driver/ service" is installing is necessary better than telling where in the registry changes are taking place.
Those who do understand alerts to some extent would be perfectly fine with all the alerts presented.. By all the programs..
I prefer CIS alerts since thats what Iam used to..
Anyway, testing and uninstalling/installing software takes time.. good job!
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 8105
substance constant, depth variable
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #3 on:
August 18, 2009, 06:43:36 PM »
[at] aigle,
I think you might have posted the wrong CIS screenshot in your post on Wilders. The CIS screenshot clearly shows it alerting about loading a device driver, using those exact words. As such, it is as good as the EQS screenshot.
Wouldn't it be better if the CIS screenshot was one showing where it is alerting about the registry mod?
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #4 on:
August 18, 2009, 07:00:59 PM »
OMG.. Aigle this time don't let it be like the wrongly preformed conflicker test please.. Were users was made believe that CIS in proactive only popped once.. something some users there still thinks..
If what Panic says is correct then please post that on wilders.. Not telling when comodo actually passes, or as in this case, alerts nicley isn't really fair..
I feel your intentions are not to fool anyone.. But as a rumor starter you should end it now..
Prehaps post a link here and tell them that you missed the alert or screwed over when testing and that CIS actually alerts about loading a device driver. Cus thats a fact... Highly doubt Panic would lie..?? If you think he is.. I will test as well..
But I hope I don't have to..
«
Last Edit: August 18, 2009, 07:03:37 PM by Monkey_Boy=)
»
Logged
jp10558
Comodo Loves me
Offline
Posts: 104
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #5 on:
August 18, 2009, 07:17:20 PM »
Well, when I installed Process hacker, what started all this (follow the threads back) it installed a driver, but I never saw ANY pop-up that said a driver was being installed...
Can you post a screenshot of the claimed driver pop-up, because I've never seen one in using CIS for about a year...
Logged
aigle
Comodo's Hero
Offline
Posts: 521
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #6 on:
August 18, 2009, 07:35:23 PM »
[at]panic
[at]Monkey_Boy=)
Post the picture of an alert by CFP saying about a driver/ service install with this software installer. I doubt that you might not even bothered to read my long thread.
«
Last Edit: August 18, 2009, 07:37:43 PM by aigle
»
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 8105
substance constant, depth variable
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #7 on:
August 18, 2009, 11:23:13 PM »
Quote from: aigle on August 18, 2009, 07:35:23 PM
I doubt that you might not even bothered to read my long thread.
Think again. I've been following this thread and its spawns since the beginning. Both you and forcespawn have made good points about the obscurity of some of CIS's alerts and about the fact that a driver install can apparently bypass CIS.
I was only trying to help.
My post referred to your link
http://www.wilderssecurity.com/showpost.php?p=1526881&postcount=19
, where the CIS screenshot clearly shows a driver install alert, which seemed at odds with the rest of the topic.
Your other Wilders topic,
http://www.wilderssecurity.com/showthread.php?p=1526872#post1526872
, is really well done and I really hope the CIS devs are monitoring it.
I hope you bother to read my short post.
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
The Joker
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 532
Let’s put a smile on that face!
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #8 on:
August 18, 2009, 11:43:55 PM »
KIS has very intuitive pop up alerts! CIS should follow it!
Logged
Windows 7 Ultimate x64 l Avira AntiVir Personal 8 l CIS 4.0.664.127486 BETA (Proactive Security) (AV: Stateful l FW: Custom Policy Mode l D+: Safe Mode) l Asus M4A78T-E l AMD Phenom II X3 720 BE l 2 x 2 GB Ram l HD Sata II 7200 RPM 1TB
______________________________
It's all part of the plan!
wj32
Comodo Loves me
Offline
Posts: 124
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #9 on:
August 19, 2009, 01:21:17 AM »
Quote from: jp10558 on August 18, 2009, 07:17:20 PM
Well, when I installed Process hacker, what started all this (follow the threads back) it installed a driver, but I never saw ANY pop-up that said a driver was being installed...
Can you post a screenshot of the claimed driver pop-up, because I've never seen one in using CIS for about a year...
Please read my comment on this in the PH thread:
Quote from: wj32
There are two main ways a program can load a driver. One is by writing to the registry in HKLM\System\CurrentControlSet\Services and then calling NtLoadDriver. The other is by contacting the services controller (services.exe) and telling it to create a service to load the driver. In the first case, D+ correctly reports that a program is attempting to load a driver, and tells you the filename of the driver. The prompt is also in red (I think). In the second case however, D+ only prompts you about registry access (which most people will allow since it comes from services.exe) and then the driver is loaded. This is a HUGE problem with D+ and I hope the developers will fix it.
I will elaborate on this. In the Wilders Security thread, gmer was shown with the correct CIS alert. That's because it uses the first technique I discussed (NtLoadDriver). Process Explorer and Process Monitor also use this method. Most other software uses the second technique, and the alerts are broken. I find it puzzling why we are alerted to registry access by services.exe but we are not alerted to services.exe calling NtLoadDriver...
Attached is a small test program demonstrating the two methods. You will be able to see how CIS responds to the two methods with different alerts...
«
Last Edit: August 19, 2009, 01:56:01 AM by wj32
»
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 3370
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #10 on:
August 19, 2009, 03:04:10 AM »
Yes D+ alerts could be displayed clearer..
Logged
Windows XP
E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM. 500gb. HDD
Ubuntu
P4 [at] 3ghz, Radeon x300 128mb
1gb DDR2 Ram 80GB HDD
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #11 on:
August 19, 2009, 03:27:11 AM »
Quote from: panic on August 18, 2009, 06:43:36 PM
[at] aigle,
I think you might have posted the wrong CIS screenshot in your post on Wilders. The CIS screenshot clearly shows it alerting about loading a device driver, using those exact words. As such, it is as good as the EQS screenshot.
Wouldn't it be better if the CIS screenshot was one showing where it is alerting about the registry mod?
Cheers,
Ewen :-)
hehe.. I understood this as if you had tested this yourself and got alerted "about loading a device driver, using those exact words"..
Hard to tell you was referring to something else..
Therefor I got a little upset with aigle for not showing that popup..
Then my mum pulled the plug to my Internet.. hehe..
Quote from: wj32 on August 19, 2009, 01:21:17 AM
Quote
There are two main ways a program can load a driver. One is by writing to the registry in HKLM\System\CurrentControlSet\Services and then calling NtLoadDriver. The other is by contacting the services controller (services.exe) and telling it to create a service to load the driver. In the first case, D+ correctly reports that a program is attempting to load a driver, and tells you the filename of the driver. The prompt is also in red (I think). In the second case however, D+ only prompts you about registry access (which most people will allow since it comes from services.exe) and then the driver is loaded. This is a HUGE problem with D+ and I hope the developers will fix it. Sad
I will elaborate on this. In the Wilders Security thread, gmer was shown with the correct CIS alert. That's because it uses the first technique I discussed (NtLoadDriver). Process Explorer and Process Monitor also use this method. Most other software uses the second technique, and the alerts are broken. I find it puzzling why we are alerted to registry access by services.exe but we are not alerted to services.exe calling NtLoadDriver...
Attached is a small test program demonstrating the two methods. You will be able to see how CIS responds to the two methods with different alerts...
I hope the Devs reads this.. Everyone loves work so Iam sure they jump right on it..
http://www.youtube.com/watch?v=jqiwEafCJ74
Logged
aigle
Comodo's Hero
Offline
Posts: 521
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #12 on:
August 19, 2009, 04:38:35 AM »
Quote from: panic on August 18, 2009, 11:23:13 PM
My post referred to your link
http://www.wilderssecurity.com/showpost.php?p=1526881&postcount=19
, where the CIS screenshot clearly shows a driver install alert, which seemed at odds with the rest of the topic.
Your other Wilders topic,
http://www.wilderssecurity.com/showthread.php?p=1526872#post1526872
, is really well done and I really hope the CIS devs are monitoring it.
I hope you bother to read my short post.
I did not mention first link as it was a bit irrelevent as no such alert was shown with virtual CD drive software install. This alert was shown by gmer and I did mention in that case that CIS alert was correct.
And Monkey_Boy=) thought I am trying to hide something. He might not even bother to read the threads and supposed that you have tested and found the results contrary to me. It took me all the day to make this thread and some one just supposing that I am hiding some thing and he is asking me to confess. That,s sad and funny.
Any way wj32 has already made it very clear.
Quote from: wj32
There are two main ways a program can load a driver. One is by writing to the registry in HKLM\System\CurrentControlSet\Services and then calling NtLoadDriver. The other is by contacting the services controller (services.exe) and telling it to create a service to load the driver. In the first case, D+ correctly reports that a program is attempting to load a driver, and tells you the filename of the driver. The prompt is also in red (I think).
In the second case however, D+ only prompts you about registry access (which most people will allow since it comes from services.exe) and then the driver is loaded. This is a HUGE problem with D+ and I hope the developers will fix it.
Thanks
wj32
.
«
Last Edit: August 19, 2009, 04:40:25 AM by aigle
»
Logged
commanding the celsius
Product Translator
Comodo's Hero
Offline
Posts: 1401
^^^^
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #13 on:
August 19, 2009, 06:37:30 AM »
Quote from: aigle on August 19, 2009, 04:38:35 AM
And Monkey_Boy=) thought I am trying to hide something. He might not even bother to read the threads and supposed that you have tested and found the results contrary to me. It took me all the day to make this thread and some one just supposing that I am hiding some thing and he is asking me to confess. That,s sad and funny.
Well perhaps I misunderstood panics post..
poo happens..
I did not read and certainly wasn't aware of this thread/post:
http://www.wilderssecurity.com/showpost.php?p=1526881&postcount=19
and that the alert in there was what panic was talking/referring to.. I only read the one link you posted here.. Without clicking any further links at wilders..
Well sorry "mate"..
Logged
3xist
Guest
Re: CFP- Poor Pop up alerts by compared with other HIPS?
«
Reply #14 on:
August 19, 2009, 07:09:09 AM »
Wait till CIS ver 4...
Zero pop ups is the future with max security guys.
Cheers,
Josh
Logged
Tags:
Pages:
[
1
]
2
3
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> AV False Positive/Negative Detection Reporting
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 0.07 seconds with 19 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com