Welcome, Guest. Please login or register.
December 01, 2009, 04:20:56 PM

Login with username, password and session length

339141 Posts
37538 Topics
85172 Members

Latest Member: corporal92

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Archive Boards
| |-+  Comodo Firewall
| | |-+  Help for v3
| | | |-+  Leak Protection doubt...
« previous next »
Pages: 1 [2] Go Down Print
Author Topic: Leak Protection doubt...  (Read 3927 times)
Vettetech
Guest
« Reply #15 on: July 03, 2008, 08:18:19 PM »

I have 2 Seagate hard drives and it comes with a bootbale cd to write zero's to the drive. What kind of hard drives do you have? Is this the program? The dwmapi.

http://www.dll-files.com/dllindex/dll-files.shtml?dwmapi
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 410


« Reply #16 on: July 03, 2008, 08:40:12 PM »

Leak Protection is a subset of all that Defense+ can do, tuned towards preventing leaking of information.

ThreatFire and Comodo Firewall 3 both work on the concept of behaviors.  Comodo lets you decide what individual behaviors to allow or block.  ThreatFire, on the default settings, looks at combinations of individual behaviors and prompts you when it appears that malicious activity is occuring.

Logged
Sir Joe
Comodo Family Member
***
Offline Offline

Posts: 86


Ops...


« Reply #17 on: July 03, 2008, 08:49:06 PM »

Nope, I have a notebook, Dell XPS M1530, one HD, seagate 160G 7200rpm.
Configured in ATA, because this is what Dell suggested, even if now a frien told me that AHCI give better performances (even if I have no turbo memory...).

Who is that guy, Cuba G. Junior after a diet?
Anyway, I see you not prepared about the theme  Nerd
If you have the time and courage to scroll the 4 pages of dwmapi topic, you will understand, if not, I will do a brief sintesis here, just a bit: Comodo (apparently onlythe last release) alerts of some programs (IE, WMP, FIrefox, and some things more) tring to install hook dwmapi.dl (DL, not DLL!!!) in system32. Both if we say allow or deny, no dwmapi.dl is never ever found in the system anywhere.
The other guy, Therealjobe, says that he has got the dwmapi.dll (the good one) always there.
I think to remember, 85% sure, that when I installed Comodo as the first program after a clean install, and it alerted about this, and I said deny, well, I had no dwmapi in s32, nor DL or DLL.
While when I said allow, the DLL appeared in s32.
My theory is that is an error, transcription error, in the database of names which Comodo uses. It should say DLL but for some error it says DL.
But they have lately found some suspicious events in a netstat log from Therealjobe computer.
For this reason I am worrying again.
But, as I have no more time to devote to this, I can't allow myself to worry anymore.

 Kewl
Logged
Sir Joe
Comodo Family Member
***
Offline Offline

Posts: 86


Ops...


« Reply #18 on: July 03, 2008, 09:13:36 PM »

Hi MrBrian, you have my attention.
Can you explain a bit more about how ThreadFire proceed, and what is the pro and contra with D+?
Thanks... Smiley
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 410


« Reply #19 on: July 03, 2008, 09:31:30 PM »

Hi MrBrian, you have my attention.
Can you explain a bit more about how ThreadFire proceed, and what is the pro and contra with D+?
Thanks... Smiley

See review on ThreatFire at http://www.pcmag.com/article2/0,2817,2301045,00.asp for more info about how it works.

I personally use Comodo Firewall 3 on my own machine, because I think i can do a better job than the analysis system of ThreatFire.  For another person in my family who is less experienced, I installed Comodo Firewall 2 (not v3) and ThreatFire.  See post #5 at http://www.pctools.com/forum/showthread.php?t=50673 for advantages of ThreatFire.  Comodo Firewall 3 has advantages over ThreatFire, but I never made a list because nobody asked for one.
« Last Edit: July 03, 2008, 10:17:51 PM by MrBrian » Logged
Sir Joe
Comodo Family Member
***
Offline Offline

Posts: 86


Ops...


« Reply #20 on: July 03, 2008, 09:46:34 PM »

I ask for one, I ask for one!  Bounce
 Angel
« Last Edit: July 03, 2008, 10:21:53 PM by Sir Joe » Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 410


« Reply #21 on: July 03, 2008, 10:17:06 PM »

I ask for one, I ask for one!  Bounce
 Angel

I'll have to write one sometime soon....  In the meantime, here are a few reasons I use CFP instead of ThreatFire on my machine:
a) CFP has full firewall.
b) With CFP, I get to make the decisions on what behaviors to allow or block.
c) CFP can block individual behaviors while still allowing a program to continue running.  ThreatFire, in older versions, cannot block an individual behavior, except by terminating the entire program.  Newer versions of ThreatFire may have changed in this respect, with regard to ThreatFire custom rules.
d) CFP doesn't have whatever overhead is necessary for the behavioral analysis that ThreatFire performs.
e) CFP detects some things that ThreatFire does not.  For example, CFP detects all 7 keylogging methods of AKLT keylogging tester, while ThreatFire detects, if I recall correctly, 2.

Logged
Sir Joe
Comodo Family Member
***
Offline Offline

Posts: 86


Ops...


« Reply #22 on: July 03, 2008, 10:28:24 PM »

Ok,
I will wait!
Anyway, as this topic was about something else, I am going to open a new topic specifically about a comparison between Defense+ and ThreatFire (as if I understood well the real similitude is with D+, not with the Firewall).
I wait for you there...
I have read that review, and your post in the other forum, and I understand that I can use both at same time with no problems. But, to the other topic! (it is to be read as "to the batmobile!")
 Kewl
Logged
MrBrian
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 410


« Reply #23 on: July 04, 2008, 12:05:35 AM »

 Tongue
and I understand that I can use both at same time with no problems.

I did find at a later time an issue with prior versions of both installed - see http://forums.comodo.com/bug_reports/some_keylogging_methods_are_not_detected_with_threatfire_v3014_21_x32-t20301.0.html;msg139414.
Logged
Tags:
Pages: 1 [2] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.049 seconds with 20 queries.
Powered by SMF 1.1.10 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com