Welcome, Guest. Please login or register.
August 21, 2008, 06:05:46 AM

Login with username, password and session length

184858 Posts
21464 Topics
52056 Members

Latest Member: bibmo

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Firewall
| | |-+  Leak Testing/Attacks/Vulnerability Research
| | | |-+  What about inboud??
« previous next »
Pages: [1] Go Down Print
Author Topic: What about inboud??  (Read 1708 times)
MasterTB
Comodo Family Member
***
Offline Offline

Posts: 78



« on: August 13, 2007, 06:19:43 AM »

Hi:

I see'ya all concerned and worried about leaktest, but.. have you ever considered about inbound attacks?? The reason I post this is because besides the TCP, UDP or ICMP flood analisis on Comodo to prevent DoS attacks, I don't see that the firewall enables a true Network Intrusion Prevention System (with signatures and all) like the ones you can find in firewalls like Kerio -to name one of the best in the job-.
I used Kerio, before they sell it and I tell you, nothig ever got in, so, why worry about leak tests if you can stop them before getting in??
That said, besides the "Block all" rule in the Network Globall Rules, what does comodo to prevent inbound attacks, like os fingerprinting, scans, network scans, nmap, trojans with particular signatures and drivers to generate TCP traffic...

BTW V3 beta... R O C K S !!!
Logged

AMD Athlon64 X2 3800+
2 GB Ram
MSI Nvidia NX 7600GT VIVO Edition
2x Samsung SP250-4C SAta II 250GB
Samsung SyncMaster 750B TFT_LCD 17"
Running on XP SP2 fully patched
NOD32 V3 and of course C.O.M.O.D.O firewall V3
MasterTB
Comodo Family Member
***
Offline Offline

Posts: 78



« Reply #1 on: August 15, 2007, 06:38:11 AM »

Ohhhhhhhhhhhhh come on!!!!!!!

It's a fair question since not much firewalls in the market actualy implement an IDS/IPS system I would love Comodo to be able to detect attacks on the network in this way and prevent them (like the old Kerio firewall did).

Snort has some fabulous rules and today actualy the only firewall that is able to implement them is the Sunbelt/kerio firewall.
Logged

AMD Athlon64 X2 3800+
2 GB Ram
MSI Nvidia NX 7600GT VIVO Edition
2x Samsung SP250-4C SAta II 250GB
Samsung SyncMaster 750B TFT_LCD 17"
Running on XP SP2 fully patched
NOD32 V3 and of course C.O.M.O.D.O firewall V3
Pho3NiX
Newbie
*
Offline Offline

Posts: 12


« Reply #2 on: August 15, 2007, 07:38:10 AM »

Yes it is a fair question.

However the number of ppl that can answer question on internal working of the firewall are quite limited and probably are comodo dev wich job are not to answer forum topic (altougth they probably can in their free time). I just want to point out that the limited answer is probably because you have a very narow question scope.

This being said .. why dont you just install snort on your computer ?
http://www.snort.org/dl/binaries/win32/
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5312


... and I say to myself, "What a wonderful world"


« Reply #3 on: August 15, 2007, 08:06:40 AM »

[at] MasterTB,

I've PM one of the dev guys your topic details. They are all pretty much flat out with the refinement of CFP V3, so they may not be able to respond immediately.

Cheers,
Ewen :-)
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
egemen
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 1721



« Reply #4 on: August 15, 2007, 09:40:56 AM »

Hi:

I see'ya all concerned and worried about leaktest, but.. have you ever considered about inbound attacks?? The reason I post this is because besides the TCP, UDP or ICMP flood analisis on Comodo to prevent DoS attacks, I don't see that the firewall enables a true Network Intrusion Prevention System (with signatures and all) like the ones you can find in firewalls like Kerio -to name one of the best in the job-.
I used Kerio, before they sell it and I tell you, nothig ever got in, so, why worry about leak tests if you can stop them before getting in??
That said, besides the "Block all" rule in the Network Globall Rules, what does comodo to prevent inbound attacks, like os fingerprinting, scans, network scans, nmap, trojans with particular signatures and drivers to generate TCP traffic...

BTW V3 beta... R O C K S !!!

Hi MasterTB,

A signature based network intrusion detection system, is normally not a vital component of a personal security system because the attacks such a system can detect are usually in the domain of a server computer. Snort, for example, is hardly suitable for a PC. However, this does not mean, an IDS does not mitigate some sorts of risks even for a PC.

An IDS suitable for personal computers/users is in our wish list and will be implemented in the future.  But till that time, your firewall should be quite enough to make sure you have a robust inbound network defense.

Good luck,
Egemen
Logged
MasterTB
Comodo Family Member
***
Offline Offline

Posts: 78



« Reply #5 on: August 15, 2007, 05:13:39 PM »

OK, first of all sory for my impatience.
I understand how heavy down in work you are with V3 so again sory for that impatient comment.
Now back to the topic I agree that a personal computer normally wouldn't need an IDS/IPS protection, but if you take the time to install an IDS -say the free version of Sunbelt PErsonal Firewall- on a computer directly conneted to the net by an ADSL modem you would be surprised by how much a properly configured IDS detect on an every day basis, just a thought....
Logged

AMD Athlon64 X2 3800+
2 GB Ram
MSI Nvidia NX 7600GT VIVO Edition
2x Samsung SP250-4C SAta II 250GB
Samsung SyncMaster 750B TFT_LCD 17"
Running on XP SP2 fully patched
NOD32 V3 and of course C.O.M.O.D.O firewall V3
Soyabeaner
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6861


Akagi


« Reply #6 on: August 15, 2007, 05:29:32 PM »

a personal computer normally wouldn't need an IDS/IPS protection, but if you take the time to install an IDS -say the free version of Sunbelt PErsonal Firewall- on a computer directly conneted to the net by an ADSL modem you would be surprised by how much a properly configured IDS detect on an every day basis, just a thought....

I've fulfilled all 3 conditions: had Kerio firewall (not much different from Sunbelt now since development is slow from what I understood), have ADSL modem, and noticed lots of things IDS detected.  However, I'm not concerned about it, especially since Egemen stated it will be included in a future version of CFP.
Logged
MasterTB
Comodo Family Member
***
Offline Offline

Posts: 78



« Reply #7 on: August 15, 2007, 07:20:25 PM »

I've fulfilled all 3 conditions: had Kerio firewall (not much different from Sunbelt now since development is slow from what I understood), have ADSL modem, and noticed lots of things IDS detected.  However, I'm not concerned about it, especially since Egemen stated it will be included in a future version of CFP.


OK, but you have to agree that if you have an IDS/IPS system on your machine, that corrupted traffick never get's to the application it is intended for, because what IDS does is filter the traffic incoming to your machine, and it's most important function is to filter trafic that you have alowed to recieve, say when you are browsing online, all the traffic that incomes is first scanned to check for inconsistances by the IDS/IPS, something comodo doesn't do actually, and by many people's standards this is a security risk; thus my question related to wether we will see this kind of improvements in the firewall and how great it would be !!
Logged

AMD Athlon64 X2 3800+
2 GB Ram
MSI Nvidia NX 7600GT VIVO Edition
2x Samsung SP250-4C SAta II 250GB
Samsung SyncMaster 750B TFT_LCD 17"
Running on XP SP2 fully patched
NOD32 V3 and of course C.O.M.O.D.O firewall V3
adric
"Start every day with a smile and get it over with."
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 553


"I am not young enough to know everything. "


« Reply #8 on: August 16, 2007, 02:35:52 AM »

Wow, Egemen is back on the forums, Looks like he has some time on his hands.  Grin
Sorry for the OT, but I just had to join the Comodo fan-boy crowd with some OT stuff  Grin.   

Al (test with 120 DPI) Adric
« Last Edit: August 17, 2007, 01:05:17 AM by adric » Logged
war59312
Newbie
*
Offline Offline

Posts: 19


WWW
« Reply #9 on: August 17, 2007, 03:37:38 PM »

I too would love to see this happen...
Logged

God Bless America
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.497 seconds with 20 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com