Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
September 07, 2008, 07:29:09 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
189565
Posts
22065
Topics
52905
Members
Latest Member:
hell
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Help for v3
some newbie questions
« previous
next »
Pages:
[
1
]
2
Author
Topic: some newbie questions (Read 909 times)
new_user_2008
Newbie
Offline
Posts: 23
some newbie questions
«
on:
July 12, 2008, 04:17:34 PM »
Hello,
nice to find this forum.
I am using the Comodo Firewall since a few days and I got a few "newbie questions" about its functions and proper configuration.
First of all, I installed it and I didn't change anything in the settings with one exception, namely in "Stealth Ports Wizard", I decided to switch to the 3rd option - "Stealth my Ports to Everyone" (although whenever I click again on the "Stealth Ports Wizard", I see the first option checked, but I guess that's just the confusing part, because I clicked for sure to activate the third option.....can someone confirm BTW?)
anyway, I wonder if there are any other recommended changes to do in the settings, to ensure a proper protection? I'm using WIN XP HOME with SP3, it's a home computer, not on a shared network (i'm from Europe BTW).
Should I change something in the configuration? If yes, where and why? Or maybe in the "my ports set" (I see many default ports there) or "my network zones" (I only see a loopback zone there). But as you can deduct from my message, I am pretty much clueless when it comes to such things. (right now my settings are for firewall as "safe mode" and for defense as "clean PC mode" (the default settings).
For example, I came acoss this thread on this very forum
http://forums.comodo.com/leak_testingattacksvulnerability_research/cant_stealth_the_port_139_with_comodo_i_did_not_pass_shieldup_file_sharring-t21236.0.html
where someone says that under the default Comodo settings, his firewall did not pass some kind of security test.
can you please point to me what exactly do I need to change and where, to increase the security level in that regard?
Also, under "Firewall events", I can see hundreds of events with application: Windows Operating System, action: blocked, protocol: TCP, UDP, sometimes ICMP and different IP's & ports.
I reckon that although these are listed as "intrusions", these are in fact harmless operations which are/should normally run in my system (?). Can someone confirm this and explain to me what blocking them means or causes?
Under "defense events" yesterday I saw only mshta.exe responsible for "Direct Monitor Access" so far but from my currect research it looks like I needed to enable that, because these were standard processes required to enter and manage the "User Accounts" in my XP's Control Panel..
But today I see in "pending review" files QTFont.for and temp0.exe? I guess these files are connected with some natural processes and I can enable them (or add to my "safe files"?)
Also, I wonder, if someone will try to attack my system (some hacker trying to get into my PC), then I will see the information about it in "defense Events" and not "Firewall Events", right?
But how it will get listed most likely?
anyway, just some basic questions, I would appreciate some help to a total newbie
oh and final question, I am using some messangers, such as ICQ. However, the Comodo Firewall has never asked me so far if it should allow ICQ to connect from my computer to the Internet.
I was expecting that it will ask me about this. Is it normal,. or is this showing that my Firewall is not configured properly?
I hope some of you will find the patience and time to answer my questions. I will make sure NOT to ask such simple questions in future and I will recommend this Firewall to my friends
And sorry for the bad English!
PS I just re-read what I wrote and I have one more question. Now that I have the Comodo Firewall, should I disable the XP built-in firewall, or not?
kindest regards,
Logged
Goose18
Comodo's Hero
Online
Posts: 1129
Re: some newbie questions
«
Reply #1 on:
July 12, 2008, 04:20:54 PM »
Quote from: new_user_2008 on July 12, 2008, 04:17:34 PM
PS I just re-read what I wrote and I have one more question. Now that I have the Comodo Firewall, should I disable the XP built-in firewall, or not?
kindest regards,
Sorry but this is all I can answer. Yes you should disable Windows built in firewall. They don't have any known conflicts running together but you should never run two firewalls at the time time to prevent possible conflicts. Same goes for Anti Viruses.
Logged
Avast! 4.8, BOClean, CFP3 and did i mention Avast! 4.8
OH guess what!!! Avast! 4.8
System Specs: Pentium 4 with HT 3.06 Ghz, 1.5GB RAM, 160 GB WDC HD, Nvidia Geforce 7600GT 256MB
sded
Global Moderator
Comodo's Hero
Offline
Posts: 1835
Re: some newbie questions
«
Reply #2 on:
July 12, 2008, 04:35:25 PM »
A few more answers
:
Stealth port wizard blocks inbound connections by adding a rule at the end of your global rules to not allow incoming connections. The wizard doesn't show the status; it just has the first option checked by default.
You should not need to change to default settings arbitrarily; in safe mode you will get popups for applications that let you select how CFP should treat them and CFP will make rules for you accordingly. To make more selective rules, I prefer to set alert settings to high.
To test how well your settings block intrusions, you can go go
http://www.grc.com/intro.htm
and run Shields Up and let it probe your ports.
An intrusion in CFP is an incoming connection attempt that is blocked and logged. Most of them have to do with normal networking for things like file sharing, or network status checking by your router. They are blocked as normally unnecessary to your network functions. To make the logging go away, make rules that block the same messages you see, but don't select logging. This will also stop them from showing up in the intrusion counter.
Logged
CFP 3.0.24/368, Vista Ultimate 32x + SP1, Avast! 4.8, Windows Defender. SAS offline. Acronis True Image just in case.
new_user_2008
Newbie
Offline
Posts: 23
Re: some newbie questions
«
Reply #3 on:
July 13, 2008, 04:58:01 PM »
thansk for the answers guys, I saw them immediately but decided to wait with replying, as I was hoping for more replies that would eventually answer all my questions
I have done the "file sharing", "common ports" and "all services ports" tests and passed them perfectly.
No idea why the user in the link quoted above had problems with the "file sharing" test
However, some specific question here:
On this site (i havent used the test there yet) I have read that:
http://www.auditmypc.com/firewall-test.asp
Note that some high-end hardware firewalls (cisco PIX, etc) and software firewalls may permanently block an IP address if it detects a security audit. You'll want to temporarily disable this autoblock feature (not the firewall) or you'll receive incorrect results (if you are an average user, this probably won't concern you).
Here's why: If we start to test your firewall for ports 1 to 1024 and your firewall blocks our IP address after a only few ports, then the remaining ports will appear closed to us when in fact they may actually be open
can someone tell me if that can be also a concern with the Comodo Firewall and the GRC test?
I mean, did that test really test all ports, or did the Comodo Firewall block their IP adress after a few times trying already, as described above, which coulnd constitue a false result.
some expert opinion appreciated
(maybe someone from Comodo?)
also,
sded
, you said
Quote
An intrusion in CFP is an incoming connection attempt that is blocked and logged. Most of them have to do with normal networking for things like file sharing, or network status checking by your router. They are blocked as normally unnecessary to your network functions. To make the logging go away, make rules that block the same messages you see, but don't select logging. This will also stop them from showing up in the intrusion counter.
personally, Im not doing any file sharing, I am just surfing the web normally, but I still get LOTS of blocked connections, that I am not sure where they are coming.(what do they mean) I don't think i am attacked all the time, so I realise, they can be harmless. But I wonder if you guys, are seeing the same?
thanks and regards
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Online
Posts: 4565
Re: some newbie questions
«
Reply #4 on:
July 13, 2008, 05:01:48 PM »
First of all are you behind a hardware firewall? What do your Comodo logs say is being blocked?
Logged
new_user_2008
Newbie
Offline
Posts: 23
Re: some newbie questions
«
Reply #5 on:
July 13, 2008, 05:17:54 PM »
Quote from: Vettetech on July 13, 2008, 05:01:48 PM
First of all are you behind a hardware firewall? What do your Comodo logs say is being blocked?
Im in Europe now, it's just after midnight and for some reason the firewall is showing logs only recorded from "today", but I see two firewall events already.
I see protocol UDP and two connections, the source IP are as following:
125.211.198.23 and 190.80.198.142 (not sure if I should reveal the source and destination ports as well?)
hmm I just googled the first IP and it seemd to belonging to an attaker indeed?
http://www.mittineague.com/dev/dids.php
(its on that list)
hm, so if i didn't have the Comodo Firewall, then what would have happened? would someone get into my PC? or is that just automatic scanning for open ports?
I'm really a tech-newbie
thanks for any comments !
EDIT: no, not behind a hardware firewall. Only Comodo and the Windowxs Xp firewall (didnt disable it YET)
«
Last Edit: July 13, 2008, 05:20:15 PM by new_user_2008
»
Logged
sded
Global Moderator
Comodo's Hero
Offline
Posts: 1835
Re: some newbie questions
«
Reply #6 on:
July 13, 2008, 05:29:19 PM »
If you are not using a router, what you are seeing then is normally called "internet noise". There are computers on the internet constantly scanning potentially vulnerable ports to enroll careless users in the "zombie army". Most users have routers that get rid of all this crap before it hits the software firewall. Get rid of the log in the "block and log" rule created by CFP so you won't see it anymore. And yes, without a firewall you are likely to become infected, although even the included Windows firewall will protect against these attacks.
Logged
CFP 3.0.24/368, Vista Ultimate 32x + SP1, Avast! 4.8, Windows Defender. SAS offline. Acronis True Image just in case.
new_user_2008
Newbie
Offline
Posts: 23
Re: some newbie questions
«
Reply #7 on:
July 14, 2008, 09:50:47 AM »
Quote from: sded on July 13, 2008, 05:29:19 PM
If you are not using a router, what you are seeing then is normally called "internet noise". There are computers on the internet constantly scanning potentially vulnerable ports to enroll careless users in the "zombie army". Most users have routers that get rid of all this crap before it hits the software firewall. Get rid of the log in the "block and log" rule created by CFP so you won't see it anymore. And yes, without a firewall you are likely to become infected, although even the included Windows firewall will protect against these attacks.
thank you
Quote from: new_user_2008 on July 13, 2008, 04:58:01 PM
On this site (i havent used the test there yet) I have read that:
http://www.auditmypc.com/firewall-test.asp
Note that some high-end hardware firewalls (cisco PIX, etc) and software firewalls may permanently block an IP address if it detects a security audit. You'll want to temporarily disable this autoblock feature (not the firewall) or you'll receive incorrect results (if you are an average user, this probably won't concern you).
Here's why: If we start to test your firewall for ports 1 to 1024 and your firewall blocks our IP address after a only few ports, then the remaining ports will appear closed to us when in fact they may actually be open
can someone tell me if that can be also a concern with the Comodo Firewall and the GRC test?
I mean, did that test really test all ports, or did the Comodo Firewall block their IP adress after a few times trying already, as described above, which coulnd constitue a false result.
some expert opinion appreciated
(maybe someone from Comodo?)
can anyone answer this?
also, in Firewall -> Advanced -> Attack Detection Settings, I see a rule that says that the suspicious host attempting a port scan will be blocked for 5 mins... so isn't this connected with what I quoted above, therefore can't it theoretically falsify the GRC test results?
BTW after done the "file sharing" or "common ports" tests, only a few times these IP's are logged in "firewall events", but I see them (4.79.142.192 etc) showing more often as "active connections" while doing the tests, is that normal? (I mean WHILE doing the common ports test, I see these IP's showing like 10 times as "Active connections" but they are recorded in "firewall events" only 4 times here)
finally, did anyone do the leakTest from GRC? (leaktest.exe)
I read in an ancient article about it, but on that website the info about the LeakTest seems a few years old.
anyone did it?
http://www.grc.com/lt/leaktest.htm
regards,
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Online
Posts: 4565
Re: some newbie questions
«
Reply #8 on:
July 14, 2008, 10:04:17 AM »
Of course Comodo passes this test. Any firewall can actually pass this test. You first need to let D+ allow the test to run.
Logged
sded
Global Moderator
Comodo's Hero
Offline
Posts: 1835
Re: some newbie questions
«
Reply #9 on:
July 14, 2008, 10:15:27 AM »
GRC doesn't scan your ports fast enough or long enough to trigger the attack detection settings. The "active connections" you should see are the outbound connections from your browser to the GRC site to run the test. TCP connections have some persistence and websites use multiple http connections-do you see something else? CFP does selective logging, so you won't generally see all the scans in the log.
Logged
CFP 3.0.24/368, Vista Ultimate 32x + SP1, Avast! 4.8, Windows Defender. SAS offline. Acronis True Image just in case.
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 1945
Re: some newbie questions
«
Reply #10 on:
July 14, 2008, 10:18:44 AM »
Oh yeah by the way if you have a Hardware Firewall, GRC Will scan that first and not the Software Firewall.
Logged
Vettetech
Computer Security Testing Group
Comodo's Hero
Online
Posts: 4565
Re: some newbie questions
«
Reply #11 on:
July 14, 2008, 10:32:38 AM »
He was talking about the GRC leak test not the Shields Up test.
Logged
new_user_2008
Newbie
Offline
Posts: 23
Re: some newbie questions
«
Reply #12 on:
July 14, 2008, 10:36:24 AM »
To clarify, I have done the 3 shields up tests and asked more specifically about them (their accuracy and how they are logged etc)
LeakTest I only asked if it's worth doing it, becuse I saw it mentioned in an old article yesterday.
Logged
3xist
Global Moderator
Comodo's Hero
Offline
Posts: 1945
Re: some newbie questions
«
Reply #13 on:
July 14, 2008, 10:38:03 AM »
Quote from: Vettetech on July 14, 2008, 10:32:38 AM
He was talking about the GRC leak test not the Shields Up test.
Thx. Just realized that
Logged
new_user_2008
Newbie
Offline
Posts: 23
Re: some newbie questions
«
Reply #14 on:
July 15, 2008, 02:59:11 PM »
Ok so I guess overall I'm pretty much safe.
Final question, the GRC site mentions some vulnerabilities with the MSN messanger.
i am not using it but I use ICQ.
Does it also have any vulnerabilities, eg someone can detect my IP based on my ICQ number (or so) and then somehow hack my PC?
I hope its not the case, just making sure.
Logged
Tags:
please kindly answer
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.304 seconds with 19 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com