Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
July 25, 2008, 05:13:08 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
176897
Posts
20916
Topics
50724
Members
Latest Member:
Loos
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Leak Testing/Attacks/Vulnerability Research
What about inboud??
« previous
next »
Pages:
[
1
]
Author
Topic: What about inboud?? (Read 1674 times)
MasterTB
Comodo Family Member
Offline
Posts: 78
What about inboud??
«
on:
August 13, 2007, 06:19:43 AM »
Hi:
I see'ya all concerned and worried about leaktest, but.. have you ever considered about inbound attacks?? The reason I post this is because besides the TCP, UDP or ICMP flood analisis on Comodo to prevent DoS attacks, I don't see that the firewall enables a true Network Intrusion Prevention System (with signatures and all) like the ones you can find in firewalls like Kerio -to name one of the best in the job-.
I used Kerio, before they sell it and I tell you, nothig ever got in, so, why worry about leak tests if you can stop them before getting in??
That said, besides the "Block all" rule in the Network Globall Rules, what does comodo to prevent inbound attacks, like os fingerprinting, scans, network scans, nmap, trojans with particular signatures and drivers to generate TCP traffic...
BTW V3 beta... R O C K S !!!
Logged
AMD Athlon64 X2 3800+
2 GB Ram
MSI Nvidia NX 7600GT VIVO Edition
2x Samsung SP250-4C SAta II 250GB
Samsung SyncMaster 750B TFT_LCD 17"
Running on XP SP2 fully patched
NOD32 V3 and of course C.O.M.O.D.O firewall V3
MasterTB
Comodo Family Member
Offline
Posts: 78
Re: What about inboud??
«
Reply #1 on:
August 15, 2007, 06:38:11 AM »
Ohhhhhhhhhhhhh come on!!!!!!!
It's a fair question since not much firewalls in the market actualy implement an IDS/IPS system I would love Comodo to be able to detect attacks on the network in this way and prevent them (like the old Kerio firewall did).
Snort has some fabulous rules and today actualy the only firewall that is able to implement them is the Sunbelt/kerio firewall.
Logged
AMD Athlon64 X2 3800+
2 GB Ram
MSI Nvidia NX 7600GT VIVO Edition
2x Samsung SP250-4C SAta II 250GB
Samsung SyncMaster 750B TFT_LCD 17"
Running on XP SP2 fully patched
NOD32 V3 and of course C.O.M.O.D.O firewall V3
Pho3NiX
Newbie
Offline
Posts: 12
Re: What about inboud??
«
Reply #2 on:
August 15, 2007, 07:38:10 AM »
Yes it is a fair question.
However the number of ppl that can answer question on internal working of the firewall are quite limited and probably are comodo dev wich job are not to answer forum topic (altougth they probably can in their free time). I just want to point out that the limited answer is probably because you have a very narow question scope.
This being said .. why dont you just install snort on your computer ?
http://www.snort.org/dl/binaries/win32/
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 5162
... and I say to myself, "What a wonderful world"
Re: What about inboud??
«
Reply #3 on:
August 15, 2007, 08:06:40 AM »
[at] MasterTB,
I've PM one of the dev guys your topic details. They are all pretty much flat out with the refinement of CFP V3, so they may not be able to respond immediately.
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
egemen
Administrator
Comodo's Hero
Offline
Posts: 1712
Re: What about inboud??
«
Reply #4 on:
August 15, 2007, 09:40:56 AM »
Quote from: MasterTB on August 13, 2007, 06:19:43 AM
Hi:
I see'ya all concerned and worried about leaktest, but.. have you ever considered about inbound attacks?? The reason I post this is because besides the TCP, UDP or ICMP flood analisis on Comodo to prevent DoS attacks, I don't see that the firewall enables a true Network Intrusion Prevention System (with signatures and all) like the ones you can find in firewalls like Kerio -to name one of the best in the job-.
I used Kerio, before they sell it and I tell you, nothig ever got in, so, why worry about leak tests if you can stop them before getting in??
That said, besides the "Block all" rule in the Network Globall Rules, what does comodo to prevent inbound attacks, like os fingerprinting, scans, network scans, nmap, trojans with particular signatures and drivers to generate TCP traffic...
BTW V3 beta... R O C K S !!!
Hi MasterTB,
A signature based network intrusion detection system, is normally not a vital component of a personal security system because the attacks such a system can detect are usually in the domain of a server computer. Snort, for example, is hardly suitable for a PC. However, this does not mean, an IDS does not mitigate some sorts of risks even for a PC.
An IDS suitable for personal computers/users is in our wish list and will be implemented in the future. But till that time, your firewall should be quite enough to make sure you have a robust inbound network defense.
Good luck,
Egemen
Logged
MasterTB
Comodo Family Member
Offline
Posts: 78
Re: What about inboud??
«
Reply #5 on:
August 15, 2007, 05:13:39 PM »
OK, first of all sory for my impatience.
I understand how heavy down in work you are with V3 so again sory for that impatient comment.
Now back to the topic I agree that a personal computer normally wouldn't need an IDS/IPS protection, but if you take the time to install an IDS -say the free version of Sunbelt PErsonal Firewall- on a computer directly conneted to the net by an ADSL modem you would be surprised by how much a properly configured IDS detect on an every day basis, just a thought....
Logged
AMD Athlon64 X2 3800+
2 GB Ram
MSI Nvidia NX 7600GT VIVO Edition
2x Samsung SP250-4C SAta II 250GB
Samsung SyncMaster 750B TFT_LCD 17"
Running on XP SP2 fully patched
NOD32 V3 and of course C.O.M.O.D.O firewall V3
Soyabeaner
Global Moderator
Comodo's Hero
Offline
Posts: 6621
Akagi
Re: What about inboud??
«
Reply #6 on:
August 15, 2007, 05:29:32 PM »
Quote from: MasterTB on August 15, 2007, 05:13:39 PM
a personal computer normally wouldn't need an IDS/IPS protection, but if you take the time to install an IDS -say the free version of Sunbelt PErsonal Firewall- on a computer directly conneted to the net by an ADSL modem you would be surprised by how much a properly configured IDS detect on an every day basis, just a thought....
I've fulfilled all 3 conditions: had Kerio firewall (not much different from Sunbelt now since development is slow from what I understood), have ADSL modem, and noticed lots of things IDS detected. However, I'm not concerned about it, especially since Egemen stated it will be included in a future version of CFP.
Logged
MasterTB
Comodo Family Member
Offline
Posts: 78
Re: What about inboud??
«
Reply #7 on:
August 15, 2007, 07:20:25 PM »
Quote from: Soya Lv. 2 on August 15, 2007, 05:29:32 PM
I've fulfilled all 3 conditions: had Kerio firewall (not much different from Sunbelt now since development is slow from what I understood), have ADSL modem, and noticed lots of things IDS detected. However, I'm not concerned about it, especially since Egemen stated it will be included in a future version of CFP.
OK, but you have to agree that if you have an IDS/IPS system on your machine, that corrupted traffick never get's to the application it is intended for, because what IDS does is filter the traffic incoming to your machine, and it's most important function is to filter trafic that you have alowed to recieve, say when you are browsing online, all the traffic that incomes is first scanned to check for inconsistances by the IDS/IPS, something comodo doesn't do actually, and by many people's standards this is a security risk; thus my question related to wether we will see this kind of improvements in the firewall and how great it would be !!
Logged
AMD Athlon64 X2 3800+
2 GB Ram
MSI Nvidia NX 7600GT VIVO Edition
2x Samsung SP250-4C SAta II 250GB
Samsung SyncMaster 750B TFT_LCD 17"
Running on XP SP2 fully patched
NOD32 V3 and of course C.O.M.O.D.O firewall V3
adric
"Start every day with a smile and get it over with."
Global Moderator
Comodo's Hero
Offline
Posts: 546
"I am not young enough to know everything. "
Re: What about inboud??
«
Reply #8 on:
August 16, 2007, 02:35:52 AM »
Wow, Egemen is back on the forums, Looks like he has some time on his hands.
Sorry for the OT, but I just had to join the Comodo fan-boy crowd with some OT stuff
.
Al (test with 120 DPI) Adric
«
Last Edit: August 17, 2007, 01:05:17 AM by adric
»
Logged
war59312
Newbie
Offline
Posts: 19
Re: What about inboud??
«
Reply #9 on:
August 17, 2007, 03:37:38 PM »
I too would love to see this happen...
Logged
God Bless America
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> CSE Beta Corner
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.274 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com