Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
March 10, 2010, 03:29:41 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
369173
Posts
40835
Topics
93156
Members
Latest Member:
JulotM
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products & Services
Comodo Internet Security - CIS
Bug Report - CIS
Too Easy Termination of cfp.exe and cmdagent.exe
« previous
next »
Pages:
[
1
]
Author
Topic: Too Easy Termination of cfp.exe and cmdagent.exe (Read 2077 times)
deepcut
Comodo Member
Offline
Posts: 29
Too Easy Termination of cfp.exe and cmdagent.exe
«
on:
June 06, 2009, 04:21:05 PM »
I have Defense+ disabled, Firewall and Antivirus enabled.
I am able to
terminate both cmdagent.exe and cfp.exe from Windows Task Manager
.
To me this seems a
serious flaw
in the security of CIS.
If I had seperate firewall and antivirus applications, I would fully expect them to protect themselves from termination.
Otherwise, any malware that infects the system simply needs to terminate them to render the system completely vulnerable.
I understand that enabling Defense+ causes CIS to be protected in this manner.
But what about anyone who wants to use a seperate HIPS solution, or to use CIS as a standalone firewall or antivirus.
I mentioned this in a
previous post
for one of the release candidates.
I hope this will be taken seriously, and perhaps some of the regulars can reply to confirm/agree or whatever.
«
Last Edit: June 06, 2009, 06:56:17 PM by deepcut
»
Logged
Windows XP Pro x64 SP2. CIS 3.9.95478.509 with AV & FW, no D+.
Guillermo391
Comodo Member
Offline
Posts: 43
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #1 on:
June 06, 2009, 05:21:54 PM »
This is only the GUI you are termiating.
Firewall and AV keep functioning. Firewall blocks all unknown comunnications, and Defense Plus all unknown hooks of programs.
You are still protected.
Just restart in safe mode, and kill whichever malware caused it,.
Logged
John Buchanan
Global Moderator
Comodo's Hero
Offline
Posts: 2713
Behold, there be Dragons here!
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #2 on:
June 06, 2009, 05:28:10 PM »
CFP.exe is just the GUI. If it is terminated, the software still protects as default deny (you just won't see it).
Deepcut, may I ask how is Defense+ supposed to protect itself if it is disabled?
The AV will notify you if any virus it detects tries to run or is about to be accessed.
The firewall will notify you about all incoming and outgoing connections.
If you are using a separate HIPS program, shouldn't it be monitoring your system for unintentional/undesired application shutdowns?
Please note, even with Defense+ enabled, if you the user wishes to shut down this or any software, Defense+ will allow this. If another software tries this same however, you will be notified and asked to confirm or block the attempt.
Just my opinion here, but I don't see this as a flaw in design.
Logged
deepcut
Comodo Member
Offline
Posts: 29
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #3 on:
June 06, 2009, 06:53:44 PM »
It would be nice if you read what I wrote before replying.
Quote from: John Buchanan on June 06, 2009, 05:28:10 PM
CFP.exe is just the GUI. If it is terminated, the software still protects as default deny (you just won't see it).
Quote from: Guillermo391 on June 06, 2009, 05:21:54 PM
This is only the GUI you are termiating.
I know that cfp.exe is the GUI, but cmdagent.exe is the main service that provides the actual protection and I can terminate that just as easily.
And even though cfp.exe is the GUI, the only way I should be able to terminate it is from CIS itself.
Quote from: John Buchanan on June 06, 2009, 05:28:10 PM
The firewall will notify you about all incoming and outgoing connections.
If malware is able to simply terminate the firewall, it cannot notify anything.
Logged
Windows XP Pro x64 SP2. CIS 3.9.95478.509 with AV & FW, no D+.
John Buchanan
Global Moderator
Comodo's Hero
Offline
Posts: 2713
Behold, there be Dragons here!
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #4 on:
June 06, 2009, 06:58:34 PM »
I read yours, you failed to read mine.
Logged
Toggie
Guest
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #5 on:
June 07, 2009, 12:32:50 AM »
deepcut, perhaps you would care to submit details regarding how you 'terminated' the two processes in question.
When ever I try to terminate either of the processes (logged on as Administrator) I get an access denied message...
Logged
BigMike
Product Translator
Comodo Loves me
Offline
Posts: 178
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #6 on:
June 07, 2009, 04:22:25 AM »
Quote from: Toggie on June 07, 2009, 12:32:50 AM
deepcut, perhaps you would care to submit details regarding how you 'terminated' the two processes in question.
When ever I try to terminate either of the processes (logged on as Administrator) I get an access denied message...
He already wrote, that he disabled Defense+ completely. If you do that, you won't get an access denied message, since it's Defense+ that takes care of what happens on your machine and protects important processes like cmdagent.exe and cfp.exe.
But I support John Buchanan's opinion. If you install CIS, just CFP or CAV you'll in any case end up with an enabled Defense+ that will protect the components and itself.
If you decide to change the recommended/predefined settings (or even use another HIPS), you should know what you're doing and what the consequences are - and set up your system according your wishes.
«
Last Edit: June 07, 2009, 04:24:11 AM by BigMike
»
Logged
Latest German translation files for
CIS v3
/
CIS v4
Agent420
Newbie
Offline
Posts: 13
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #7 on:
June 07, 2009, 11:59:10 AM »
I used sysinternals, Autoruns to stop cmdagent. The trouble with doing that is that the Anti-virus will not scan when cmdagent is stopped. BUT, with it stopped, it will no scan the computer. On the flip side, I have my computer back without having to wait for that POS cmdagent to finish whatever it is doing beside wearing out my disks.
Logged
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 5622
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #8 on:
June 07, 2009, 06:08:47 PM »
Quote from: Agent420 on June 07, 2009, 11:59:10 AM
I used sysinternals, Autoruns to stop cmdagent. The trouble with doing that is that the Anti-virus will not scan when cmdagent is stopped. BUT, with it stopped, it will no scan the computer. On the flip side, I have my computer back without having to wait for that POS cmdagent to finish whatever it is doing beside wearing out my disks.
With Autoruns you disable the start up of cmdagent. That is not what is being discussed here.
Logged
Triple boot: XP SP3, Vista Ultimate 32 SP2 and Win7 RTM (default) , AMD Phenom 925 (quad core), 4 GB of RAM on MSI 785G E53.
Always the latest CIS or CIS Beta (too lazy to update my sig)
Opera Browser: always using the latest snapshots; the 10.50 branch as I write this....
John Buchanan
Global Moderator
Comodo's Hero
Offline
Posts: 2713
Behold, there be Dragons here!
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #9 on:
June 07, 2009, 09:49:31 PM »
Again, you are manually terminating the process. CIS can't prevent this. Again, if another program made the attempt (a malicious program), you would be notified before it was permitted to proceed with this action.
(This assumes Defense+ is not disabled).
Logged
kail
Autonomous
Global Moderator
Comodo's Hero
Offline
Posts: 5333
I'm not a complete idiot, some bits are missing.
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #10 on:
June 20, 2009, 11:01:28 AM »
I'd just like to say: Whilst you may well be able to terminate cmdagent.exe (the service), you'd still need to tackle CIS's drivers (the business end) to actually circumvent it in anyway. And even if by some miracle you managed this.. I strongly suspect you would need to reboot to return the TCP stack back to a workable state. In fact, given CIS's hooks you may not have the choice. In any event, it will only end tears.
Logged
Windows 7 Ultimate x32 with CIS 3.14 & Firefox 3.6 & Becky! 2.54
__
A positive and polite attitude may not solve all your problems, but it will annoy enough people to make it worth the effort.
adioz86
Comodo's Hero
Offline
Posts: 278
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #11 on:
June 21, 2009, 11:02:37 AM »
Easy thing.
When you disable Defense+, and do not have another HIPS, it would be easy to terminate both process.
Other Firewall and Antivirus solutions works a little bit like an HIPS, but just for their own applications. I think this is the selfprotection of these FW and AV solutions you mean. They try to prevent everything from terminating their process.
In Comodo this selfprotection is integrated in Defense+. You haven't the choices to not install it. It will always be installed. So this is the selfprotection part of CIS. This selfprotection works, when you have Training Mode or higher level of D+, 'cause then it cares about the rules. In disabled mode every action is applied, and no rule will be triggered.
By disabling this, there wouldn't be a opportunity that CIS can protect its self.
So if you use another HIPS, it should be able to protect Comodo Firewall and AV from being terminated.
Logged
Intel Core 2 Quad Q9550 2.83GHz C1-Stepping [at]3.83GHz (8,5 *451MHz), Scythe Mugen 2 Cooler, Asus Rampage Formula X48, Kingston HyperX 2*2GB 1066Mhz [at]902Mhz, Sapphire HD 4890,PoV GTS 250, Antec Three Hundred, Dual Boot Win7 x64 and WinXP Pro x86 for 16bit programs
fragglerockboy
Newbie
Offline
Posts: 1
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #12 on:
December 17, 2009, 08:34:53 AM »
I am also able to terminate both cfp.exe and cmdagent.exe of CIS from the task manager without any problem whether as a regular user or as an administrator. I have Defense+ set to safe mode, with all options checked under Defense+ monitor settings. I see from the last post that self protection is integrated into Defense+ , however I am curious as to why I'm able to terminate them if they are protected. When someone else may be using my pc under any login, then I don't want them to be able to disable any of it. For years I always used Norton, which was too paranoid/ too many false positives at times, but a feature I truely to this day like: Tamper Protection. With Tamper Protection enable in Norton you were unable to kill/terminate any of the running processes whether intentionally or accidentally even with trying multiple methods to close them. You couldn't terminate them unless you went into the Norton control panel option, unchecked tamper protection, then restarted your pc. Is there any way for CIS to integrate tamper protection like Norton?
Logged
Dennis2
Global Moderator
Comodo's Hero
Online
Posts: 2458
Re: Too Easy Termination of cfp.exe and cmdagent.exe
«
Reply #13 on:
December 17, 2009, 08:51:54 AM »
Welcome to the forum fragglerockboy
Whilst you do not have Defence+ disabled you should not be able to kill cmdagent screenshot.
Possible problems with install leftover drivers etc.
Dennis
«
Last Edit: December 17, 2009, 08:54:19 AM by Dennis2
»
Logged
Moderator:
Aims to keep the forum a friendly place. Any concerns? Please PM me and/or review the
NEW forum policy
.
System:
Windows 7 (UAC)x32, CIS 4,Sandboxie 3.44
Vista Home P. (UAC)x32 SP2, CIS 3.14, W.D.
Tags:
serious
flaw
termination
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> False Positive/Negative reporting - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Report - CIS
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Online Backup - COB
===> Help - CB
=====> FAQ - CB
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
===> Beta Corner - CDE
=> Comodo Secure Email - CSE
===> News / Announcements / Feedback - CSE
===> Help - CSE
=====> FAQ - CSE
===> Bug Reports - CSE
=> Comodo EasyVPN - CEVPN
===> News / Announcements / Feedback - CEVPN
===> Help - CEVPN
=====> FAQ - CEVPN
===> Bug reports - CEVPN
=> Comodo AntiSpam - CAS
=> Comodo TrustConnect - CTC
=> HopSurf - CHS
=> Comodo Instant Malware Analysis Online - CIMA
=> Verification Engine - CVE
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner - CSC
===> News / Announcements / Feedback - CSC
===> Help - CSC
=====> FAQ - CSC
=> Comodo Cloud Scanner - CCS
===> News / Announcements / Feedback - CCS
===> FAQ - CCS
=> Live PC Support
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
===> Comodo BOClean Anti-Malware
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing) (discontinued)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
Page created in 1 seconds with 17 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com