Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 18, 2013, 12:59:23 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
662813
Posts
70563
Topics
145132
Members
Latest Member:
karben
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
Wishlist - CIS
Reverse DNS lookup and whois for IP in alert windows
« previous
next »
Poll
Question:
When you get a firewall alert, do you wish you knew who was behind that IP?
Yes
164 (98.2%)
No
3 (1.8%)
Total Voters: 166
Pages:
[
1
]
2
3
...
6
Author
Topic: Reverse DNS lookup and whois for IP in alert windows (Read 25735 times)
dandv
Newbie
Offline
Posts: 23
Reverse DNS lookup and whois for IP in alert windows
«
on:
February 10, 2011, 02:49:24 AM »
I just installed Comodo today, and got the first alerts of applications trying to connect to various IPs. Of course, I wanted to know what domains resolve to those IPs, so I launched nslookup, then whois. Then after a bunch of alerts, I thought, this is a basic feature, Comodo
must
have it, maybe it's just disabled by default. But nope.
Today we celebrate
3 years
since this basic feature request was posted: reverse IP lookup, and whois lookup. It was also proposed in a
Plugins thread
and again in this
Wishlist
thread.
Is it really complicated to do a reverse DNS lookup? How do Comodo devs who eat their own dogfood deal with this usability issue?
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 11173
Linux is free only if your time is worthless.;-)
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #1 on:
February 10, 2011, 03:35:04 AM »
I agree with you and have voted accordingly, but I do hope that other members who are not familiar with the concept of dogfooding don't think you were being derogatory.
Eating ones own dogfood is a term indicating a company that internally uses the software it produces.
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you can't conform, don't use the forum.
dandv
Newbie
Offline
Posts: 23
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #2 on:
June 09, 2011, 05:28:00 PM »
Why is there NOTHING being done about this issue?
Besides the obvious usability problem,
not doing a reverse DNS lookup for the IP is a security risk
.
While a process may be deemed safe to connect to the Internet (say, svchost.exe, since it's often used by Windows to get Windows updates), the remote IP is crucial - if you live in the USA and see svchost.exe trying to connect to an IP in Bulgaria, it's probably NOT Windows Updates.
I've attached a screenshot but I feel like shouting in the wind here. Who do I need to poke to have this issue finally addressed?
Also, displaying just "svchost.exe" in the Firewall Alert window is not very helpful. It would be muh more helpful if the name of the actual DLL of the service that tries to connect were displayed. Here is a 2006 post that suggests this was possible at one time in Comodo:
http://www.wilderssecurity.com/showthread.php?t=145810
. Why was this capability removed?
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 11173
Linux is free only if your time is worthless.;-)
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #3 on:
June 09, 2011, 05:57:26 PM »
Quote from: dandv on June 09, 2011, 05:28:00 PM
Here is a 2006 post that suggests this was possible at one time in Comodo:
http://www.wilderssecurity.com/showthread.php?t=145810
. Why was this capability removed?
As far as I can remember, Comodo's firewall's (V2, V3, V4 and now V5) has not displayed the DLL that invoked SVCHOST.EXE. AFAIK, it hasn't been removed because it was never there.
I still agree with you about the reverse DNS though, just not as stridently.
Cheers,
Ewen :-)
«
Last Edit: June 09, 2011, 06:33:14 PM by panic
»
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you can't conform, don't use the forum.
Radaghast
Star Group
Comodo's Hero
Offline
Posts: 4052
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #4 on:
June 09, 2011, 06:25:14 PM »
Having the ability to enable reverse look-ups would be a great idea, but it must be optional, as there can be significant network overhead and packet delay when performing these tasks.
I vote yes with that provision.
Logged
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.”
Jebtrix
Newbie
Offline
Posts: 5
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #5 on:
June 20, 2011, 06:17:51 PM »
The lack of this feature has been driving me nutz for years!! I always laugh when an alert comes up blah blah trying to connect to xxx.xxx.xxx.xxx, yeah like I frikkin know with the info provided.
Logged
dandv
Newbie
Offline
Posts: 23
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #6 on:
June 21, 2011, 09:51:40 PM »
Quote from: Jebtrix on June 20, 2011, 06:17:51 PM
The lack of this feature has been driving me nutz for years!! I always laugh when an alert comes up blah blah trying to connect to xxx.xxx.xxx.xxx, yeah like I frikkin know with the info provided.
Exactly. WTF. One wonders if Comodo developers actually ever use Comodo themselves.
But besides that, there's a serious security problem with displaying just the IP - see here:
http://forums.comodo.com/format-verified-issue-reports-cis/security-risk-remote-ip-is-opaque-to-user-issue-report-t73414.0.html
Logged
pabrate
Comodo Loves me
Offline
Posts: 110
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #7 on:
July 17, 2011, 08:27:28 PM »
It will never happen and I'm sick of it
This is so simple to implement and almost every firewall has it.
Finally realized what this company really is , a BIG joke !
Logged
wasgij6
Global Moderator
Comodo's Hero
Offline
Posts: 3062
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #8 on:
July 17, 2011, 09:31:16 PM »
Quote from: pabrate on July 17, 2011, 08:27:28 PM
It will never happen and I'm sick of it
This is so simple to implement and almost every firewall has it.
Finally realized what this company really is , a BIG joke !
its obviously not a big joke if this many people support it and are on this forum discussing it including yourself. if it was a big joke as you stated it wouldnt survive and development would have stopped. idk if you have seen the reviews of cis and all of the recognitions it gets.
Logged
| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
wasgij6
Global Moderator
Comodo's Hero
Offline
Posts: 3062
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #9 on:
July 17, 2011, 09:35:24 PM »
i agree that this feature needs to be added but it doesnt make comodo firewall a joke just cause it doesnt have it. im sure they will implement eventually. im hoping with v6
Logged
| Win 7 Ultimate (x32) SP1; Admin | UAC Disabled | CIS 6.1.276867.2813 | CD 26.2 | CID 20.0.1 | VMWare Workstation; XP (x32), 7 (x64) |
pabrate
Comodo Loves me
Offline
Posts: 110
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #10 on:
July 17, 2011, 10:37:10 PM »
Quote from: wasgij6 on July 17, 2011, 09:35:24 PM
i agree that this feature needs to be added but it doesnt make comodo firewall a joke just cause it doesnt have it. im sure they will implement eventually. im hoping with v6
Well, I asked here almost 2 years ago about the same feature :
https://forums.comodo.com/wishlist-cis/resolve-ip-to-hostname-t54597.0.html
Not a single response from Comodo, absolutely nothing, and from that thread I learned that people actually asked that before me, so who knows for how long this feature has been asked for.
Why is Comodo a joke ?
Because it's a free product and I realized they don't give a "***" about it / their users.
You know, like 20 admins, 30 developers, I mean whatever, there's a huge number of their staff visiting this forum and they just can't say anything about that ? And I mean
anything
?
That's a joke buddy ....
Mod Edit: Removed Explicit word.
«
Last Edit: July 18, 2011, 12:48:52 AM by captainsticks
»
Logged
captainsticks
Global Moderator
Comodo's Hero
Offline
Posts: 6025
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #11 on:
July 18, 2011, 01:08:01 AM »
Hi Pabrate. I do agree that not much has been said about, but I think to call Comodo a joke is a bit harsh.
All jokes a side how often would a general user use this function, and if it is deemed totally necessary there are alternative ways to check. IMHO Comodo does have it users best interest at heart, and with that security, reliabilty, and stability come first. Some might call what is asked for a requirement, and others will say it is just another bell or whistle. My FW is to be used as a FW nothing more and nothing less and I myself am quite happy to use alternative measures for lookups etc. I am not against anyones wish, but IMO it is not a priority and would have to be optional or the ability to disable.
Just my thoughts and kind regards.
«
Last Edit: July 18, 2011, 01:17:32 AM by captainsticks
»
Logged
A good read guaranteed.
Forum Policy - Updated on January 3, 2013
dandv
Newbie
Offline
Posts: 23
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #12 on:
July 19, 2011, 05:41:35 AM »
Quote from: captainsticks on July 18, 2011, 01:08:01 AM
Hi Pabrate. I do agree that not much has been said about, but I think to call Comodo a joke is a bit harsh.
There's a lot of ridiculous praise for Comodo,
serious security risks
(
this being one of them
) are being ignored, so I'm not surprised it's being perceived as a joke.
Quote from: wasgij6 on July 17, 2011, 09:31:16 PM
if it was a big joke as you stated it wouldnt survive and development would have stopped. idk if you have seen the reviews of cis and all of the recognitions it gets.
I've been seeing LOADS of such recognition here in the forum and on the Facebook page, and it comes from, excuse me, uneducated idiots who can't write to save their lives. All they can utter is "omg comodo is da best phirewall evaaaa!!!11". Seriously. Go have a look at the
Comodo Facebook page
. These were actual gems of Comodo praise you could see on the Facebook page within the last 24 hours:
*
BB in DA HOWSE and COMODO iz Keeping my Doorz SECURE WOOT!!!
*
i'm installing comodo is beautifool.
*
REALLY LOVIN IT!!!! NO MORE HEADACHES, AND WANTING TO THROW MY COMPUTER IN THE DUMPSTER!!!!!! LMBO!!!!
Quote from: captainsticks on July 18, 2011, 01:08:01 AM
All jokes a side how often would a general user use this function
ALL. THE. TIME. How can you not understand this painfully obvious point?
Let me try to illustrate it again:
You get two alerts from svchost.exe that your computer wants to connect to:
a) 109.237.208.23
b) 207.46.197.32
Which one do you allow, and which one do you block? How do you approach this problem?
«
Last Edit: July 19, 2011, 05:45:38 AM by dandv
»
Logged
pabrate
Comodo Loves me
Offline
Posts: 110
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #13 on:
July 19, 2011, 08:21:50 AM »
Quote from: captainsticks on July 18, 2011, 01:08:01 AM
Hi Pabrate. I do agree that not much has been said about, but I think to call Comodo a joke is a bit harsh.
Okay, it was harsh, I might overreacted a bit.
But I've been using Comodo for a long time and didn't even think about changing the firewall.
Like I said, I need that feature, it helps a lot and I don't care what you think about that feature.
I asked nicely two years ago for it, at least someone from Comodo could replied and said something , like you did it now for example.
But then out of curiosity I tried several firewalls in VM looking for a replacement, and to my surprise every one had that feature. So, I finally ditched Comodo yesterday, yeah ... just because of that, got sick and tired of waiting, and to be honest, it's the attitude of Comodo that finally made me uninstall it. Not to say a thing about it, that's not cool. That feature is one line of code, to reverse IP to domain name, then just add that string to the alert window and that's it. If that was too much, well ... good luck
Logged
captainsticks
Global Moderator
Comodo's Hero
Offline
Posts: 6025
Re: Reverse DNS lookup and whois for IP in alert windows
«
Reply #14 on:
July 19, 2011, 08:58:17 AM »
To Dandv. I would use alternative bookmarked tools when required.
Quote from: dandv on July 19, 2011, 05:41:35 AM
I've been seeing LOADS of such recognition here in the forum and on the Facebook page, and it comes from, excuse me, uneducated idiots who can't write to save their lives.
Uneducated does not equal idiot, please choose worded expressions carefully.
Whether someone uses good grammer/spelling or not, and is educated/uneducated, does not take away the right for them to have an opinion.
I have had my opinion, and I didn't degrade anyone in doing so.
Kind regards.
Logged
A good read guaranteed.
Forum Policy - Updated on January 3, 2013
Tags:
DNS
ip
lookup
whois
Pages:
[
1
]
2
3
...
6
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.053 seconds with 23 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com