Welcome, Guest. Please login or register.
August 28, 2008, 12:29:09 AM

Login with username, password and session length

186746 Posts
21599 Topics
52402 Members

Latest Member: bonexfriendster

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Help for v3
| | | |-+  Questions about Submit/Lookup [Merged Threads]
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: Questions about Submit/Lookup [Merged Threads]  (Read 1295 times)
Ganda
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2681


what!? never see an actor join up a forum?!


« on: November 27, 2007, 08:55:28 PM »

hi all, Wave
just wanna know, if we submit something via CFP3 submit files option, and it turns out that the submitted file is a malware,and......... what's next? we know that CFP uses white list/safelist, isn't it great IF CFP defense+ has a black list as well?


Ganda
Logged

Chuck Norris once kicked a horse in the chin. Its decendants are known today as Giraffes.
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6963


Deleted Posts: 495,204


« Reply #1 on: November 27, 2007, 08:57:32 PM »

isn't it great IF CFP defense+ has a black list as well?

That's what CAVS and BOClean are for.
Logged
Ganda
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2681


what!? never see an actor join up a forum?!


« Reply #2 on: November 27, 2007, 09:03:21 PM »

That's what CAVS and BOClean are for.
OK then Grin
you mean malware sample submitted to CFP will be added to CAVS/CBO signature? nice Clapping
Logged

Chuck Norris once kicked a horse in the chin. Its decendants are known today as Giraffes.
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6963


Deleted Posts: 495,204


« Reply #3 on: November 27, 2007, 09:08:54 PM »

I don't know, but you probably just gave Comodo an idea (or maybe they already knew) Laugh
Logged
Ganda
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2681


what!? never see an actor join up a forum?!


« Reply #4 on: November 27, 2007, 09:17:38 PM »

I don't know, but you probably just gave Comodo an idea (or maybe they already knew) Laugh
Cheesy , and i never submit anything.i always delete my pending files.  Tongue
Logged

Chuck Norris once kicked a horse in the chin. Its decendants are known today as Giraffes.
Rednose
Comodo's Hero
*****
Offline Offline

Posts: 1267


Ganda's sleepy ( in his wildest dreams )


« Reply #5 on: November 27, 2007, 09:26:46 PM »

Cheesy , and i never submit anything.i always delete my pending files.  Tongue

Now you can forget a bonus payment from Comodo for this great idea Grin

Greetz, Red.
Logged

XP 32x SP3  CFP 2.4  SSM 2.0 Free  Avast! 4.8 Home  CBOClean 4.27  CMF 2.0  SAS 4.15 Free  MBAM 1.24
Ganda
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 2681


what!? never see an actor join up a forum?!


« Reply #6 on: November 28, 2007, 04:27:11 AM »

Now you can forget a bonus payment from Comodo for this great idea Grin

Greetz, Red.
LOL  Cheesy
Logged

Chuck Norris once kicked a horse in the chin. Its decendants are known today as Giraffes.
marcos.zy
Computer Security Testing Group
Comodo Loves me
*****
Offline Offline

Posts: 132



WWW
« Reply #7 on: December 04, 2007, 02:21:26 PM »

Hello!  Smiley

I would like to know if someone can help me in a doubt regarding CFP 3.

I am running it for about 1 week, and it is working very fine on all my machines. I have noted only one strange behavior while it is running: frequently on bottom right of my desktop, while I am working on my computer, the "submitting the file(s) for analysis" dialog box opens automatically and "apparently" sends some file(s) to Comodo, without any interaction from my part (this happens just for a few seconds).

I would like to say that I frequently execute the "purge", "lookup" and "submit" options to the files that appears on "my pending list" option, but the above mentioned sending is occurring frequently, without any interaction from my part, even if there is not any file on "my pending list".

Someone has any idea of what could be the cause of it?

Best Regards.  Cheers
Logged

Blas
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 361


« Reply #8 on: December 04, 2007, 02:47:07 PM »

The default option is that pending files not on the safelist will be sent automatically to comodo. Even after you clear the pending list these unknown files will enter a queue in the files to submit list. If it fails to send some it will try it again later.
Logged
marcos.zy
Computer Security Testing Group
Comodo Loves me
*****
Offline Offline

Posts: 132



WWW
« Reply #9 on: December 04, 2007, 02:54:11 PM »

Hello Blas!

Thank you for your reply.  Smiley

Do you know where can I see this queue that contains the unknown files that does not appears on "my pending files" list, and if is there some way to configure these options?

Regards.
Logged

Blas
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 361


« Reply #10 on: December 04, 2007, 03:57:49 PM »

Hi,

The queue can be found under Miscellaneous/Submit suspicious files.
These files should appear first on your pending list. It have just came to my mind that after doing whatever action with the pending files it poped up a message asking if I wanted to send the files to comodo. I checked the box "don't ask again" so in my case this is why the submission is automatic.
Quote
Files which are not in the Comodo safelist and are also unknown to the user can be submitted directly to Comodo for analysis and possible addition to the safelist.

File Submission Process

Files can be transferred into this module by clicking the 'Move to..' button in the 'My Pending Files' and 'My Own Safe Files' areas. The interface also allows you to manually add files that you would like to submit. Click 'Add' to manually add suspicious files to the 'List of Files'. Similarly, to remove a file from the submission process, click the 'Remove' button.

This was from the help file...not much of a help though...
From what I see it shouldn't send files without your consent unless you clicked "remember" your option when asked for submission. I had some problems with few bigger files btw. It wanted to send skypesetup.exe and it always failed with a network error Huh regardless of its failure to send it it tried it periodically thus the submission icon appeared often but it was sending the same file all the time. If you duble click on the icon you can see what is sent or being tried to send.
Logged
marcos.zy
Computer Security Testing Group
Comodo Loves me
*****
Offline Offline

Posts: 132



WWW
« Reply #11 on: December 04, 2007, 04:43:16 PM »

Hello Blas,

Thank you for your reply.

Quote
The queue can be found under Miscellaneous/Submit suspicious files.
These files should appear first on your pending list. It have just came to my mind that after doing whatever action with the pending files it poped up a message asking if I wanted to send the files to comodo. I checked the box "don't ask again" so in my case this is why the submission is automatic.

I have found the queue, thanks.  Smiley But it is empty.

I always purge, execute a "lookup" and submit the unknown files already existent on "my pending files" list to Comodo, manually, and I never had used any "remember" option here. So, due to this I'm not understanding the so frequent dialog boxes regarding sending files.

Now, for example, I can see that my "my pending files" list is empty, but since I have started this post, the dialog box has already appeared a few times.

And I have already experienced the same bug you experienced with the skype file, with some "bigger" files. It seems that there is some type of bug when submitting bigger files, because always occurs the error you have mentioned.

Someone knows what can cause this?

Regards.  Smiley
« Last Edit: December 04, 2007, 04:47:03 PM by marcos.zy » Logged

Geko
Comodo Member
**
Offline Offline

Posts: 44


« Reply #12 on: December 14, 2007, 09:31:01 PM »

Can someone tell me how can I copy a temporary file.

Programs such as Process Explorer, a-squared, CounterSpy, etc... creates temporary files. These temporary files disappear very fast.

So is there a program that can capture them or a way to do it.

I ask this because I want to submit them to Comodo, so they can add them to their safety database for Defense+.

By the way, I think this topic should be sticked, so everyone can help, with the safety database.
Logged
AnotherOne
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 665


« Reply #13 on: December 15, 2007, 12:55:09 AM »

There are a few other consideration here.
1.  A user reported that asp.net would not work because of temp files.  He identified .dll's, but I suspect that there were other files that needed permission - either as a temp executable or as an exe trying to run a temp file.  It is very hard to give permissions to do either without resorting to wildcards and possibly creating other problems.

2.  It is a characteristic of rootkits that its files are hidden from most ways of viewing them.  If such a hidden file was identified when it was seeking permissions, it might not show up again when being checked in the Pending Files list or by any other way of searching for those files except for a few anti-rootkit tools. 

3. A game player reported that one of his games created temp files that needed internet access.  This was successfully resolved by the creative use of wildcards, but it is a task beyond the average user's talents.

Given the above, and the question of vanishing files possibly being related to rootkits, some form of inspection of those files (possibly in memory) should be built into CFP.  If it becomes necessary to give such files permissions, it is difficult in the ordinary way.  If a record of the inspected file could be used to grant permissions to it, that would deal with some of the problems. 
Logged

What do you mean, my shoes are on the wrong feet???  These are the only feet I've got!
jim28277
Newbie
*
Offline Offline

Posts: 19


« Reply #14 on: December 17, 2007, 10:36:20 PM »

I have a few questions about pending files. I have submitted a file in my "files for review" list and am waiting for COMODO's response. How long should we expect to wait for the submitted files to be researched and added to the safe files database. Is there a definitive answer to submitted files or do we just assume they are unsafe if they are not added to the safe files database after a certain period of time. What do we do with the pending files that are not added to the safe files database (should we search for these files on our hard drive and manually delete them?). Thanks in advance.....Jim
Logged
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.185 seconds with 19 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com