Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
January 08, 2010, 02:17:01 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
349131
Posts
38590
Topics
87751
Members
Latest Member:
abrolrahul6
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Archived Boards
Comodo Firewall
Help for v3
Mars Attacks! and apparently everyone else does too.
« previous
next »
Pages:
[
1
]
Author
Topic: Mars Attacks! and apparently everyone else does too. (Read 1769 times)
Irish_Sean
Newbie
Offline
Posts: 14
Mars Attacks! and apparently everyone else does too.
«
on:
December 02, 2008, 03:02:01 PM »
CFP / Latest version, using Proactive Security config, FW Safe, D+ Safe, Stealth ports to everyone.
WIN XP PRO SP3.
Dial up, no router.
After initial install I started to define some rules for common windows components and all hell has broke loose. I have set Lsass, Svchost, System, and Explorer to outgoing only using CFP's predefined rule. CFP is now logging 100/1000's of intrusion attempts on my computer I dont know what is going on.
I have included a screen, showing examples....HELP How can I be attacked when all my ports are stealthed?
Logged
grue155
Global Moderator
Comodo's Hero
Offline
Posts: 1172
Re: Mars Attacks! and apparently everyone else does too.
«
Reply #1 on:
December 03, 2008, 08:26:17 PM »
Quote
How can I be attacked when all my ports are stealthed?
Believe it or not, this the normal amount of junk on the Internet these days. These are simply zombie probes being sent to any and all, to see if anything replies. You're stealthed, so they don't know that you're there. But it makes the logs look like a windscreen travelling down a motorway in locust season. It's unnerving, but harmless because CFP is keeping all the junk away from your machine.
To cut back on the amount of stuff being recorded in the logs, you can uncheck the box that says "log this" on the respective blocking rules.
Logged
Irish_Sean
Newbie
Offline
Posts: 14
Re: Mars Attacks! and apparently everyone else does too.
«
Reply #2 on:
December 04, 2008, 07:41:21 AM »
Good to know grue155, I felt a little naked in the wind there. I thought I had miss-configured the Firewall in some way.
I still have a problem though, while playing Warrock an on-line FPS that is using P2P technology to connect players, my logs fill up with failled UDP attempts. When I firstt ran Warrock I set FW/D+ into training mode so Im pretty sure that I allowed CFP to accept inbound UDP for Warrock. Is the fact I set most Windows components to outgoing only superceeding this?
Logged
grue155
Global Moderator
Comodo's Hero
Offline
Posts: 1172
Re: Mars Attacks! and apparently everyone else does too.
«
Reply #3 on:
December 04, 2008, 11:55:35 AM »
Maybe. The answer in probably in the way that firewall rules are evaluated. When packets are sent and received, the packets are processed in this sequence of rules:
Internet ---- Global Rules ------ Application Rules ------- application
Setting CFP for a training mode, lets CFP learn about the application and what rules need to be set for that application. Setting rules to be outgoing only doesn't allow packets to come in from the Internet if those packets are not in some kind of answer to something sent from the application.
P2P, on the other hand, has users out on the Internet who will query your machine. They just send packets to you, and those packets aren't answers, but are queries. So, those packets coming in, first encounter CFP global rules, and then the application rules. (And, if there is no specific application, the CFP "Windows Operating System" rules get used)
If those incoming packets are all coming to a single UDP port, then you'll need to set an application rule to allow those unsolicated packets to reach the application. And you'll likely need to add a global rule to allow that packet to get thru, also.
Logged
Irish_Sean
Newbie
Offline
Posts: 14
Re: Mars Attacks! and apparently everyone else does too.
«
Reply #4 on:
December 05, 2008, 04:09:27 PM »
Quote from: grue155 on December 04, 2008, 11:55:35 AM
If those incoming packets are all coming to a single UDP port, then you'll need to set an application rule to allow those unsolicated packets to reach the application. And you'll likely need to add a global rule to allow that packet to get thru, also.
Thanks for taking the time to explain that grue155, very nice of you. I didn't want to report back without trying to create these rules myself, but as you can in the logs I have made things worse. Could someone in the know check them out and determine what adjustments I need to make, or better yet if someone else plays Warrock without lag could you post your rules.
Thanks Sean.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to Help Comodo?
-----------------------------
=> Help Spread the Word - Banners and Logos
=> How Can I Help Comodo? (Please We Need You!)
===> Help Spread the Word! (Please Read and Help)
===> Report Comodo Forum / Web Site Issues
=> Please Tell Us Your Views and Vote Here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Help - CIS
=====> AntiVirus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> AntiVirus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> AntiVirus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> AntiVirus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> Graphical User Interface (GUI) Wishlist
===> Bug Report - CIS
=====> AntiVirus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> GUI / Miscellaneous / Other Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
===> Help - CTM
===> Feedback/Comments/Announcements/News - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless World!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to You)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Comodo Cloud Scanner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Other Security Products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archived Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
=> Other Firewalls
=> Host Intrusion Prevention Systems (HIPS)
=> AntiPhishing Solutions
Page created in 0.034 seconds with 20 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com