Welcome, Guest. Please login or register.
October 06, 2008, 11:32:53 AM

Login with username, password and session length

197618 Posts
22751 Topics
54676 Members

Latest Member: si-14

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Melih's Corner - CEO Talk/Discussions/Blog
| | |-+  Comodo Firewall: Loads too late to provide boot-time protection
« previous next »
Pages: [1] Go Down Print
Author Topic: Comodo Firewall: Loads too late to provide boot-time protection  (Read 660 times)
VanguardLH
Comodo Family Member
***
Offline Offline

Posts: 72


« on: March 12, 2008, 04:55:49 PM »

Please see my existing discussion at:

http://forums.comodo.com/empty-t20715.0.html

From looking at some nasty pests and when they load, it appears they start before Comodo's firewall is even considered to start during Windows startup.  That is, and as examples, programs listed in the BootExecute and WinLogon event registry keys are loaded before CFP is started.  That means there is a window of opportunity in malware (or even with goodware but which you want to restrict network connects or access rights) to run before CFP could block it.  The firewall can't block the connect because the firewall hasn't even started loading yet (although I mention a possible technique in the other thread to kill networking until the firewall has fully loaded).  The HIPS function cannot restrict access rights to the program because CFP hasn't been loaded yet.

I've used other firewalls that had an option to disable networking until the firewall program got loaded; i.e., they provided boot-time protection.  CFP doesn't seem that have that level of protection or it is not documented.  For HIPS, CFP cannot restrict access rights to anything until it loads, and since CFP loads as an NT service then it loads too late to control boot-time programs.
Logged
panic
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 5451


... and I say to myself, "What a wonderful world"


« Reply #1 on: March 12, 2008, 05:27:28 PM »

inspect.sys and cmdguard.sys are loaded as kernel level drivers to provide boot time protection.
Logged

As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the  Comodo Forum Policy.
If you don't like it, don't use the forum.
VanguardLH
Comodo Family Member
***
Offline Offline

Posts: 72


« Reply #2 on: March 12, 2008, 05:51:37 PM »

Thanks for that information.  Nice to know that CFP is protecting starting from boot-time (when the drivers load at the start of Windows load).  Thanks again.
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.131 seconds with 18 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com