Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 08, 2008, 02:09:54 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
198020
Posts
22790
Topics
54756
Members
Latest Member:
Shoman
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Help for v2
Component Monitor - Learning mode better ?
« previous
next »
Pages:
[
1
]
Author
Topic: Component Monitor - Learning mode better ? (Read 2787 times)
ocky
Comodo Loves me
Offline
Posts: 110
Component Monitor - Learning mode better ?
«
on:
February 08, 2007, 08:02:08 AM »
I have been using Comodo PF for about 2 weeks now, and whilst I have not encountered any problems, I am still confused as to the benefit of switching the component monitor from 'learning' to 'on', especially for average home users.
Let's say I install a new version of 'X' application and some of the .dll files have changed - in learning mode I will be alerted and would select 'allow' because I know what I am installing and from which source. In 'on' mode I would also select 'allow' - the difference being that if I choose I can see the .dll files by clicking 'Libraries' and would then need to allow them, otherwise my updated program will not connect.
Am I missing something vital to my security - or can I leave the component monitor in 'learning' mode ?
Also I don't understand the PC Flank Leak test. There is a dripping tap, but when pasting the url into my browser the result definitely does not reflect what I typed before ?
Thanks in advance for any help/advice.
Logged
ocky
Comodo Loves me
Offline
Posts: 110
Re: Component Monitor - Learning mode better ?
«
Reply #1 on:
February 09, 2007, 06:51:43 AM »
Sorry to 'bump' this - I did come across a thread, or was it a poll ? where some of the members mentioned their preferences or methods regarding the Component Monitor modes. Alas, I can't find this thread anymore.
Some guidance will be welcome. Apologies for being impatient !
Logged
Graham1
Comodo's Hero
Offline
Posts: 612
Re: Component Monitor - Learning mode better ?
«
Reply #2 on:
February 09, 2007, 08:08:00 AM »
Quote from: ocky on February 09, 2007, 06:51:43 AM
Sorry to 'bump' this - I did come across a thread, or was it a poll ?
The link below may help.
http://forums.comodo.com/index.php/topic,2546.0.html
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7366
Re: Component Monitor - Learning mode better ?
«
Reply #3 on:
February 09, 2007, 08:13:19 AM »
Learning mode is best during the initial few weeks of CFP's installation to avoid unnecessary alerts about known programs/components. It's been weeks, but I still keep my on Learn because of another problem (causes high cmdagent.exe cpu usage when web browsing).
Logged
ocky
Comodo Loves me
Offline
Posts: 110
Re: Component Monitor - Learning mode better ?
«
Reply #4 on:
February 09, 2007, 09:24:51 AM »
Quote from: Graham1 on February 09, 2007, 08:08:00 AM
The link below may help.
Many thanks for the link. That's what I was searching for. However please advise if there are any benefits of turning the Component Monitor on ...... unless it is only a matter of being curious as to what components are shown in Libraries. See my initial post.
Anyone on my PC Flank leak test query ?
Sorry, but noobs do need some pampering to become at least
mini heros
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7366
Re: Component Monitor - Learning mode better ?
«
Reply #5 on:
February 09, 2007, 09:31:13 AM »
The supposed advantage of ON mode is that any time new components are loaded (after the first weeks of it being on LEARN), you will be alerted. Learn mode automatically defaults all components to accept as you can see from the huge list. ON mode will default to deny unless you explicity allow the components to load.
I'll state this up front: there is no honour to being a hero other than self-reward of helping others.
«
Last Edit: February 09, 2007, 09:34:04 AM by ♥ soyabeaner ♪
»
Logged
ocky
Comodo Loves me
Offline
Posts: 110
Re: Component Monitor - Learning mode better ?
«
Reply #6 on:
February 09, 2007, 10:57:26 AM »
Thanks
♥ soyabeaner ♪ !
At this stage I think I will leave the Comp. Monitor in 'Learning' mode, in line with several
"Comodo Hero"
folks, as gleaned from the link kindly supplied by
Graham1
.
I assume that, when say downloading an application update where .dll, ActiveX etc. have changed, I will be asked to allow/deny. As I know the source to be safe (touch wood), I will choose allow, thereby also allowing the associated components. Is this right ?
I also assume that when Comodo was first installed and I initiated, "scan for known applications" this is what is to be seen in the Comp. Monitor. If there are any changes, I will be alerted as mentioned above; so I really don't see the need for "On" mode although I will certainly give it a try.
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7366
Re: Component Monitor - Learning mode better ?
«
Reply #7 on:
February 09, 2007, 11:05:00 AM »
I may be a "hero", but it doesn't mean I know much
.
Quote from: ocky on February 09, 2007, 10:57:26 AM
At this stage I think I will leave the Comp. Monitor in 'Learning' mode, in line with several
"Comodo Hero"
folks, as gleaned from the link kindly supplied by
Graham1
.
I assume that, when say downloading an application update where .dll, ActiveX etc. have changed, I will be asked to allow/deny. As I know the source to be safe (touch wood), I will choose allow, thereby also allowing the associated components. Is this right ?
I think you're right. At least it seems logical
.
Quote from: ocky on February 09, 2007, 10:57:26 AM
I also assume that when Comodo was first installed and I initiated, "scan for known applications" this is what is to be seen in the Comp. Monitor.
No. Scan for known apps does not do anything to the component monitor - it only adds allowed AppMon rules. Everytime I reinstall CFP the CompMon list is empty as expected, even after scanning known apps.
Quote from: ocky on February 09, 2007, 10:57:26 AM
If there are any changes, I will be alerted as mentioned above; so I really don't see the need for "On" mode although I will certainly give it a try.
Yes. Go ahead and try. The worst it can do is blow up your computer. Joking.
Logged
ocky
Comodo Loves me
Offline
Posts: 110
Re: Component Monitor - Learning mode better ?
«
Reply #8 on:
February 09, 2007, 12:32:53 PM »
Quote from: ♥ soyabeaner ♪ on February 09, 2007, 11:05:00 AM
No. Scan for known apps does not do anything to the component monitor - it only adds allowed AppMon rules. Everytime I reinstall CFP the CompMon list is empty as expected, even after scanning known apps.
Hi again, and thanks for your time ! One more question. How do the CompMon items get listed ?
Surely they are the components of the various applications and should be tied to the process of scanning for known apps. so that CPF can validate them before giving the OK to access the internet ? Tricky stuff for a noob ....
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7366
Re: Component Monitor - Learning mode better ?
«
Reply #9 on:
February 09, 2007, 12:48:37 PM »
I don't know the exact technical details, but you are on the right track. It depends.
If you're in Learn mode, all programs that are allowed to connect (I think the AppMon rules and the certified apps if you enabled that option) are automatically allowed for all their related components (dll's, drivers, libraries, etc.) and appear in that big CompMon list. Although, I
believe
there is a something deeper or hidden because I've noticed dlls are were never used by programs I haven't even loaded yet. It's almost as if CFP learns your entire computer components in time.
In On mode, if you deny the components, they will appear in the big Component Monitor list as denied (or in different combinations if you selectively deny/allow when clicking on the Show Libraries button on a pop-up).
There may be more unexplainble factors involved. For example, even though I don't click Remember when I deny a given group of components, even after rebooting I never get asked the same dll's anymore.
«
Last Edit: February 09, 2007, 12:50:36 PM by ♥ soyabeaner ♪
»
Logged
ocky
Comodo Loves me
Offline
Posts: 110
Re: Component Monitor - Learning mode better ?
«
Reply #10 on:
February 09, 2007, 01:51:51 PM »
Quote from: ♥ soyabeaner ♪ on February 09, 2007, 12:48:37 PM
Although, I
believe
there is a something deeper or hidden because I've noticed dlls are were never used by programs I haven't even loaded yet. It's almost as if CFP learns your entire computer components in time.
I have also noticed this .... interesting. Anyway I have a lot to learn and will monitor more closely what goes on when I next do an uninstall/reinstall. Great firewall. (Miss the detailed logs in my olde Sygate with Whois lookup et al).
Logged
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 7366
Re: Component Monitor - Learning mode better ?
«
Reply #11 on:
February 09, 2007, 01:57:27 PM »
I'm sure the logging will improve as time progresses. There's another thread on voting polls about which
plugins
users would like to see in future versions (if Comodo decided to implement them), and Whois lookup currently seems to be the most popular
.
«
Last Edit: February 09, 2007, 01:59:01 PM by ♥ soyabeaner ♪
»
Logged
Little Mac
Global Moderator
Comodo's Hero
Offline
Posts: 6017
Re: Component Monitor - Learning mode better ?
«
Reply #12 on:
February 09, 2007, 03:06:42 PM »
Regarding the connections and logs, I know that we shall soon have our beloved "Closed" button back, so that we can terminate any given connection. We shall also have the "Listening" connections shown again.
It has been requested in the WishList that IP resolution (ie, Whois) be added; I would anticipate that will be in there soon as well...
LM
Logged
date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 bs=32768 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.188 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com