Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 11, 2009, 10:01:08 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
334000
Posts
36900
Topics
83697
Members
Latest Member:
gerald6g
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archive Boards
Comodo Firewall
Help for v3
Can you knowledgeable folks please help us with NOD32 v3!
« previous
next »
Pages:
1
[
2
]
3
Author
Topic: Can you knowledgeable folks please help us with NOD32 v3! (Read 7670 times)
ggf31416
Comodo Loves me
Offline
Posts: 108
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #15 on:
December 28, 2007, 08:25:12 AM »
Quote from: Stanr on December 27, 2007, 06:00:05 PM
Based on the above I have it in my mind as follows:
Opera->CFP->NOD->Internet
Based on other posts I have read seem to indicate as follows:
Opera->NOD->Internet
There is not tunnel, it's just a problem of incorrect configuration and rules.
I will see if I can install a trial of NOD32 and test it.
Logged
ggf31416
Comodo Loves me
Offline
Posts: 108
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #16 on:
December 28, 2007, 10:02:49 AM »
OK, good news and bad news.
Good News: Configuring comodo to control the "tunnel" is a PoC (Not a Proof of Concept but a Piece of Cake
)
First you have to enable
Firewall -> Advanced -> Firewall Behaviour Settings -> Alert Settings -> Enable Alerts for loopback requests
I not sure if the port is the same on all computers, if you do the following please check that the communication is not allowed without prompt.
Now remove the rules for your browser (or another application that connects to Internet, e.g. an updater or leaktest) and try to access a HTTP web page with that program(HTTPS doesn't use the proxy in the default configuration), you should receive a prompt similar to the first and second screenshot. Make sure that your Firewall Security Level is set to Custom.
Please provide feedback.
Bad News: I think I found a bug in Comodo while testing NOD32, the exclude checkbox in the destination port is not working!
«
Last Edit: December 30, 2007, 07:08:42 PM by ggf31416
»
Logged
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 712
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #17 on:
December 28, 2007, 04:40:40 PM »
Nice job! Note that people should NOT choose "Treat this application as.." and any of the Web Browser or Email Client options on the pop-up. Just clicking Allow would be fine.
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
ratchet
Comodo Family Member
Offline
Posts: 99
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #18 on:
December 28, 2007, 08:36:02 PM »
ggf31416, thank you for all this work! Hopefully you've nailed it and I've entered your policies and rules correctly. Have a great new year!
p.s. I assume Comodo Firewall Security Level now needs to be set to "Custom Policy Mode".
«
Last Edit: December 28, 2007, 08:41:24 PM by ratchet
»
Logged
ggf31416
Comodo Loves me
Offline
Posts: 108
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #19 on:
December 28, 2007, 10:30:58 PM »
Quote from: ratchet on December 28, 2007, 08:36:02 PM
ggf31416, thank you for all this work! Hopefully you've nailed it and I've entered your policies and rules correctly. Have a great new year!
Did that worked? Can you download this program
http://www.grc.com/lt/leaktest.htm
, it's a very basic leaktest but it's enough to know if the instructions work in your computer. Allow the defense+ warnings and select "test for leaks". When you receive a prompt from the firewall select Block. Please post the results.
Quote from: ratchet on December 28, 2007, 08:36:02 PM
p.s. I assume Comodo Firewall Security Level now needs to be set to "Custom Policy Mode".
It's not needed. You can use Train with Safe Mode if you want but (with or without the NOD32 Proxy) you won't get prompts for programs in the comodo safelist and they can connect without your authorization.
«
Last Edit: December 28, 2007, 11:15:56 PM by ggf31416
»
Logged
Burillo
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 324
Bunghole
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #20 on:
December 29, 2007, 04:11:13 AM »
traffic goes as follows: APP -> CFP -> NOD32 -> Internet
the reason why CFP can't control outbound traffic with NOD32 proxy turned on is the fact that every app is connecting to localhost (127.0.0.1), not the real destination address. If malware tries to call home - you will be alerted only with localhost connection attempt, and the only way to get some idea about destination address is to log ekrn.exe. That means given the fact NOD scans http traffic - you can't ban Windows Media player from phoning home without banning the whole M$ IP range for ALL apps that use NOD proxy. Simple but oh so painful...
Logged
Some people are dumb... (c) Butt-head
Remember! CIA is watching you!
ratchet
Comodo Family Member
Offline
Posts: 99
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #21 on:
December 29, 2007, 08:33:39 AM »
Quote from: ggf31416 on December 28, 2007, 10:30:58 PM
Did that worked? Can you download this program
http://www.grc.com/lt/leaktest.htm
, it's a very basic leaktest but it's enough to know if the instructions work in your computer. Allow the defense+ warnings and select "test for leaks". When you receive a prompt from the firewall select Block. Please post the results.
It's not needed. You can use Train with Safe Mode if you want but (with or without the NOD32 Proxy) you won't get prompts for programs in the comodo safelist and they can connect without your authorization.
Well first of all, let me state I'm an idiot as you'll shortly discover! Per your initial instructions (Reply #16), my browsers loaded undetected. Not good I presume. Then early this morning (like 4:00am) I mistakenly (idiot me!) gave the leak test file permission to doenload. Comodo did warn me. The file did damage Sandboxie, preventing it from opening Firefox. Each attempt from the shortcut would list two Sb files that could not be accessed. Everything is back to normal now after a system restore. Thank You, ratchet
Logged
Stanr
Comodo Member
Offline
Posts: 48
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #22 on:
December 29, 2007, 09:36:34 AM »
ggf31416
Thanks for looking in to this and your hard work.
I have created the rules as you suggested and removed all preset rules for Opera and got the alerts as you describe.
I then removed the newly created rules and just tried to connect with Opera, just the app I'm using for this test, and still received the same alert as shown in proxy1.png. It seems as long as a permit rule has not been saved, for opera in this case, that you will get the popup as previously described. This leads me to believe that no matter what the program is if it has not been granted permission and the rule saved then an alert will be given if it tries to connect even if the NOD proxy is running. But, I'm not sure as my testing/knowledge is limited.
I tried the leak test from GRC as well as many as I could from PCFlank and none got to the Internet, sans the rules you described. Some of the leak tests on PCFlank were stopped on download by NOD and some requiring install were stopped by NOD or Comodo at the time of install. I have Comodo firewall is set to "Custom policy Mode" and D+ set to "Train with safe mode" .
I'm sure I'm missing something here but it seems that Comodo/D+ is stopping these from getting through with the NOD proxy operating and with the Protocol filtering set to "Ports and applications marked as Internet browsers and email clients".
Does the above indicate that if a unknown malware tries to connect and has not been previously granted permission in Comodo/D+ an alert will pop up?
Also, if a malware attempts to alter a previously permitted app to connect would Comodo/D+ alert me to the attempt even if NOD is filtering as I previously described? I would like to test this if such a test exists.
I stress that I'm a real novice at all this so I'm not sure what this means other then the leak tests failed and I got the alerts. For all I know my computer butt may be hanging out with a welcome sign for the world to kick.
Thanks again for your interest and efforts to help us less informed, it is greatly appreciated.
Stan
Logged
XP-Home-sp2 ~ Nod32 v3.0.667.0 ~ CFP v3.5.54375.427
ggf31416
Comodo Loves me
Offline
Posts: 108
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #23 on:
December 29, 2007, 11:08:26 AM »
Quote from: ratchet on December 29, 2007, 08:33:39 AM
Well first of all, let me state I'm an idiot as you'll shortly discover! Per your initial instructions (Reply #16), my browsers loaded undetected. Not good I presume. Then early this morning (like 4:00am) I mistakenly (idiot me!) gave the leak test file permission to doenload. Comodo did warn me. The file did damage Sandboxie, preventing it from opening Firefox. Each attempt from the shortcut would list two Sb files that could not be accessed. Everything is back to normal now after a system restore. Thank You, ratchet
Sorry for your problems with the leaktest but I really don't understand how that could happen. The only thing that leaktest.exe do is create an outbound connection, so it's impossible that it damaged sandboxie. Maybe it was some rare conflict or you mistankenly blocked something needed for sandboxie.
With respect to the browsers not being detected, can you enable again the "Enable Alerts for loopback requests" option, set firewall security level to Custom, remove the rules for internet explorer, run internet explorer, access the google page (or any other safe HTTP page), and post a screenshot of the firewall alert (or write the port number)?
«
Last Edit: December 29, 2007, 11:18:46 AM by ggf31416
»
Logged
ratchet
Comodo Family Member
Offline
Posts: 99
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #24 on:
December 29, 2007, 02:47:32 PM »
ggf31416, between setting up my wife's webcam and Skype (so we can view our new granddaughter between 600mi visits), my wife's iPod, and my Canon S5 IS Camera (the kids got me that for xmas), I'm kind of fiddled out. I'm even considering reverting back to v2.7 of NOD and trying the Online-Armor free firewall since it isn't quite as feature rich as Comodo. Of course that would require more fiddling, so for the time being I may just stay the course since I know I'm not going to get into any malware anyway. ratchet
Logged
Bizarre™
Comodo Member
Offline
Posts: 47
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #25 on:
December 29, 2007, 03:37:41 PM »
Here.
http://www.wilderssecurity.com/showpost.php?p=1124960&postcount=17
Problem Solved.
Logged
Imagination is more important than knowledge...
- Albert Einstein
perigee
Newbie
Offline
Posts: 20
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #26 on:
December 30, 2007, 11:46:35 AM »
Correct me if I am wrong, but as I see it there are two options:
option 1: If you don't want to use or be bothered with NOD v3's proxy then the link that
Bizarre just gave is the way to go.
option 2: If you want to filter internet data transfers for virus and malware
before
it gets on your computer (where it is then up to your resident av/malware programs
to detect) then ggf31416's post #16 seems to be the way to go.
I am using option 2 for the extra protection I get using NOD v3's internet data filtering
capabilities and CFP's program access capabilities. This seems to be the best of both worlds
for these two applications at the moment. I may be wrong but it won't be the first or
the last time.
thanks for all the helpful posts.........................
«
Last Edit: December 30, 2007, 11:54:02 AM by perigee
»
Logged
ggf31416
Comodo Loves me
Offline
Posts: 108
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #27 on:
December 30, 2007, 02:06:24 PM »
I edited my post as I not sure if NOD32 uses the same port on all computers.
Enabling the "Enable Alerts for loopback requests" option should guarantee that connections passing through the NOD32 proxy are intercepted, if there are no rules allowing those connections.
Logged
ratchet
Comodo Family Member
Offline
Posts: 99
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #28 on:
December 30, 2007, 04:59:55 PM »
ggf31416, I did pass the test last night with the "default" settings, although "Alerts for Loopback Requests" was already enabled. I put your policies and rules back in place today. Also, there is already a Global Rule "Block And Log IP IN Any To IP Any Where Protocol Is Any". Not sure that is by default or I put it there upon some other recommendation. How does it effect, if at all, your rules?
Logged
ratchet
Comodo Family Member
Offline
Posts: 99
Re: Can you knowledgeable folks please help us with NOD32 v3!
«
Reply #29 on:
December 30, 2007, 06:32:42 PM »
I totally failed the leak test! I download the file, open it and Comodo asks, I say block. Then the leak test box opens, I hit test and I fail. I delete the file, go through the whole thing one more time, only this time the file opens without even a whimper from Comodo. I hit test and I failed. Now what?
Logged
Tags:
Pages:
1
[
2
]
3
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - Program Lineup
===> Comodo.TV - News and Announcements
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.049 seconds with 17 queries.
Powered by SMF 1.1.10
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com