Welcome, Guest. Please login or register.
December 27, 2009, 07:43:49 AM

Login with username, password and session length

345486 Posts
38156 Topics
86643 Members

Latest Member: rubbe

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Feedback/Comments/Announcements/News - CIS
| | | |-+  firewall problem with KAV
« previous next »
Pages: [1] Go Down Print
Author Topic: firewall problem with KAV  (Read 854 times)
cvsa
Comodo Family Member
***
Offline Offline

Posts: 85


« on: January 25, 2009, 05:51:56 AM »

As reported here (http://forums.comodo.com/leak_testingattacksvulnerability_research/v3_doesnt_pass_grc_leaktest_merged_threads-t5795.75.html)  there's a problem of security showed by GRC leaktets for people who use Kaspersky antivirus. Comodo firewall lets GRC acceed to the internet through KAV's  avp.exe process. I think cis should warn us if an application tries to use port 80 to acceed a remote adress. Some firewalls do it : Outpost for example...

Could you (Comodo people) do something about it  ?
Logged
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1283


^^^^


« Reply #1 on: January 25, 2009, 08:50:46 AM »

I think cis should warn us if an application tries to use port 80 to acceed a remote adress. Some firewalls do it : Outpost for example...

CIS warns you too, you are probably using safemode or similar, some safe applications such as a KAV antivirus get automatically allowed then. Set CIS to custom policy and alert settings HIGH.

Check your firewalls network security policy too to see if you have any previous allowed rules for KAV, if so, remove them.

Firewall > Advanced > Network Security Policy.

Now you should get an alert next time KAV tries to connect the Internet.  Bounce Bounce
Logged
cvsa
Comodo Family Member
***
Offline Offline

Posts: 85


« Reply #2 on: January 25, 2009, 09:15:54 AM »

yes, i've got an alert when kav acces internet... but that's not what i want cause KAV always access the internet ! I would like Comodo firewall to tell me (once kav is trusted) when another applicatioin is using port 80 trough kav monitoring (i.e. avp.exe) to acces internet (like grc leaktest) ...
« Last Edit: January 25, 2009, 09:22:14 AM by cvsa » Logged
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1283


^^^^


« Reply #3 on: January 25, 2009, 09:27:03 AM »

I never heard of AVP, but it should show up an alert if this really access the Internet, I have a hard time believing that CIS somehow would miss that.

So you put the firewall to custom policy?

If so check at:
Firewall > Advanced > Network Security Policy. to see if you got any allow rules for avp.exe.

I get a different alert if ex; Internet Explorer and then Firefox tries to access the Internet through port 80.
Also what CIS version are you running?
Logged
cvsa
Comodo Family Member
***
Offline Offline

Posts: 85


« Reply #4 on: January 25, 2009, 02:08:26 PM »

avp is the monitoring process of Kaspersky AV. it scans all the traffic . I Use last stable version of CIS (not the beta).

Kaspersky is creating a breach through CIS firewall and GRC leak test is using that breach : it gets access to the internet via port 80 monitored by avp.exe process (part of KAV) ,  cf; the link in my first post.



Logged
.FaZio93.
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2279


Söz gümüşse sukut altındır.


« Reply #5 on: January 25, 2009, 02:24:14 PM »

So, have you asked on the KAV forums yet?
Logged

Vista Home Prem x32 SP2
CIS 3.13.121240.574
Please remember to follow the Forum Policy.
cvsa
Comodo Family Member
***
Offline Offline

Posts: 85


« Reply #6 on: January 25, 2009, 02:52:37 PM »

yes.. no answer Thinking

they say use kis or outpost.....
Logged
commanding the celsius
Product Translator
Comodo's Hero
*****
Offline Offline

Posts: 1283


^^^^


« Reply #7 on: January 26, 2009, 05:04:31 AM »

First check if you passes http://www.testmypcsecurity.com/securitytests/firewall_test_suite.html
That test (340/340 points), If not then your setup is wrong.

Make sure you uses proactive security mode.
I bet you should get a warning!

Comodo should catch this whenever or not this is a bug in KAVS.

Check your network security policy, do you got any global allow rules there? Also Check your application rules.
Also check firewall behavior settings, under alert settings, make sure every box is clicked.
Logged
cvsa
Comodo Family Member
***
Offline Offline

Posts: 85


« Reply #8 on: January 27, 2009, 11:22:37 AM »

my test is 340 /340. The only allowed pro. is AVP (Kasperky) and grc leaktest still penetrate the FW trough avp.exe process via port 80. Thinking

Could any KAV user on this forum try to reproduce the problem ?
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.038 seconds with 17 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com