CPF Wishlist Rev 3

Apoligies if this has already been mentioned (too much information to read) :). Within the launch pad, it would nice for all the components (i.e firewall, antivirus, etc) to have a standard layout. Say exit and help at the bottom and open component at the top. Not a major problem (only visual) but nicer all the same.

:slight_smile:

yep!

Melih

Hello and thanks for the software.
Iā€™ve run into a few issues configuring access for the Thunderbird email client. My request is not specific to that program, but I will use it as an example here.
Naturally i want to allow Thunderbird to have internet access, but not unlimited access in/out. When the program is started and no rule is in place, Comodo asks if I want to allow traffic. Clicking ā€œAllowā€ seems to allow all TCP/UDP traffic. Now the application is running and I open a message sent via ReadNotify (see http://readnotify.com) and the this triggers a TCP/port 80 connection to ReadNotify. Comodo doesnā€™t mention this though. I only knew this email message used ReadNotify because I was testing their system. I had to discover its method with Comodo by closing and restarting Thunderbird and creating rule restrictions one after another for each new popup notification message traffic type until i finally found the ReadNotify port 80 attempt.
Perhaps there could be an advanced mode notification popup that would provide some or all of the granularity control in the application rule editor? Or maybe just a ā€œstrictā€ check box that would only allow the particular direction (in/out), type (tcp/udp), and port for the popup rules.

hibachirat

Regarding advanced rules, see wishlist 20 on page 1. Should be added in a future release.

:slight_smile:

How about when an application uses IE to access the internet, if you deny it, it blocks internet access altogether, how about something implemented in the firewall that will shut that app down when clicking deny instead of having to restart IE?

Thanks,

Paul

Hi Paul,

When we provide an Advanced button for the popup, this will be very possible.

Egemen

Thanks for the reply Egemen, appreciated as always and canā€™t wait! :wink:

Cheers,

Paul

This slowdown on shutdown occurs because CPF makes several additional security checks (on the system and on itself) as it is shutting down. The thinking was that it was better to lose time when the user was finished, rather than make them lose time waiting for the system to startup.

Like all the changes I see in beta 2.3.3.33, but would like to have the option of skipping the security checks on system shut down which takes so long. Could this be added as an option to the Advanced Attack Detection and Prevention/Miscellaneous section like the ā€œBlock all outgoing connections while bootingā€ choice?

Iā€™d really like to see all this condensed again like on the first page with what has been done, what will be/timeline, responses.

Here is a request, I donā€™t know if it is great or if it is not great, but Iā€™d like a tarpit maybe, like this other firewall (have not tried it). see:
http://www.8signs.com/firewall/features.cfm

Your system accepts TCP connections but never replies and ignores disconnect requests. This can leave ports scanners and hackers stuck for hours, even days.

The thread will be condensed with the next version, and for each version after that.

About your request, it seems interesting, but I think some may feel it bloats the product. This will make a great discussion though, nice find ;).

Mike

CPF blocks port scan attackers temporarily, for 5 mintes by default. But tarpit approach reveals you and you do not remain stealth anymore. And SYN scanning should work very well against it. So it did not sound a good idea to me.

About the tray icon.

PLEASE and urgentlyā€¦ GET A NEW TRAY ICON made for CPF.

Letting Windows scale down the normal resolution icon is NOT the answer.

It currently looks like the type of icon a Dialer would use.

Edward

[attachment deleted by admin]

@TheFireKnight
The icon is not even icon thats scalled down but bitmap image at resolution 12x12 (while tray is using 16x16!). Thats why it looks so ā– ā– ā– ā– ā– ā– . In these days, usage of 16x16 alpha blended icons (those for XP specifically) is a logical choice. They look smooth on edges and far more detailed).

And my other idea:
Would be cool if there was some status page with these info stats:

  • Total data transfered in both directions
  • Total inbound data
  • Total outbound data
  • Total data transfered in both directions for current session
  • Total inbound data for current session
  • Total outbound data for current session
  • Current number of active connections
  • Number of port scans total
  • Number of port scans for current session
  • possibly some others (like total data transfered for this month, this week and this day). Of course when this bandwidth problem is fully solved. I always liked statistics and these are no exception. Plus it would be great for those that have bandwidth limited DSL connections.

Ability to specifiy several parent applications to a child application would also be a logical feature.
For example, you can now have just 1 parent attached to child. But we all know that there is also a chance for different parents launching the same child. Lets say Windows Messenger Live launching IEXPLORE.exe or EXPLORER.exe launching IEXPLORE.exe, Child is the same but parents arenā€™t. It would be more flexibly plus it would avoid constant popups when parents change.

On v2.3.3.33 I currently have Outlook.exe set like that. Theres two rules under Application Monitoring were Outlook.exe is the child on each. The 1st rule has explorer.exe as the parent and the 2nd rule has mailwasher.exe as the parent. I didnā€™t manually create these. I think the first rules was made when ā€œscan for known applicationsā€ was ran, the second I accepted and remember from a popup (tested with firefox as child with both firefox and opera as parents, then with utorrent as child and both utorrent and launcher.exe as parents).

And after just testing with a couple more apps by manually add 2 rules for 1 child app using 2 different parent apps worked fine without inducing a popup using either parent.

I also tried another way. With no rule for Maxthon.exe web browser I ran Maxthon from the start menu. I remember and accepted the popup which added Maxthon as child and explorer.exe as parent and a rule was created for that. Then I ran Maxthon from Launcher and chose to remember and accepted the popup and a second rules was added for maxthn for that.

Well either way if parents would be listed under just one child instead having several child entries on programs list.

Ahhh, I thnk I understand what your saying. Have one rule per app with the ability to add more than one parent to tha apps one rule.

Exactly! It would be much easier to manage and control.

Thanks for responding. I wrote to them, asked more about it.

I think some may feel it bloats the product.

some would think anything other than barebones is bloat.
unfortunately, certain big names out there have gone to such horrid and flawed excesses that now adding features or bundling software gets the fallout from their mistakes and causes alarm. It doesnā€™t have to be that way, and not everyone has to use everything feature.
Add a giant Comodo Security Center with Comodo Radio and Shockwave games, and man, then we have bloat! (:AGL)

Importing/exporting Network Monitor rules list would certanly be a very useful feature, so you can have several profiles (rules lists) that can be imported or exported anytime user wants.