Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 25, 2013, 10:12:45 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
664047
Posts
70630
Topics
145258
Members
Latest Member:
marvin-tpa
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
Wishlist - CIS
Sandbox should accommodate constantly changing applications/files
« previous
next »
Pages:
[
1
]
2
Author
Topic: Sandbox should accommodate constantly changing applications/files (Read 3840 times)
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6573
Sandbox should accommodate constantly changing applications/files
«
on:
September 28, 2010, 07:51:41 PM »
The sandbox needs some sort of functionality to deal with files or applications that are frequently changed.
For example, I have a Java application (in the form of a .jar file) that I compile sometimes several times a day. The sandbox wants to grab each new compilation and send it Comodo.
Now granted, it's great from a security standpoint that CIS is so vigilant about a changed application as this could be the work of something malicious. However, this application is safe and all that ends up happening is that I'm wasting my and Comodos bandwidth, along with the time of whoever gets the
privilege
chore of trying to figure out if these countless files submitted by me with the same name are safe or not...
There is a kludgey workaround to accomplish this. Add the file to the trusted files list, and apply the Installer/Updater security profile. However, that is less than intuitive (it is neither an installer, nor updater) and takes a bit of experimentation (and frustration) to achieve the desired results.
I think another option is necessary on the initial sandbox dialog to accommodate files that are expected to frequently change. If that is deemed too much of a security risk for the unwashed masses to accidentally click, perhaps a new security policy can be instituted that has a much more appropriate name? I don't know, something like
Trusted/Changing
or perhaps
Path Based
?
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16722
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #1 on:
September 28, 2010, 08:29:23 PM »
+1
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
Tech
Usability Study Member
Comodo's Hero
Offline
Posts: 3024
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #2 on:
October 02, 2010, 04:43:33 PM »
Isn't it a security hole?
Shouldn't the files/folders excluded that way be checked with MD5?
Logged
avast! team member
Save freeware snapshot technology of Comodo Time Machine.
Vote!
EricJH
Global Moderator
Comodo's Hero
Offline
Posts: 16722
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #3 on:
October 02, 2010, 04:54:55 PM »
Very strictly speaking it is. But this request is about giving the user a choice in case a file changes often; for example when developing a file.
Logged
Please read:
Introduction to the 5.x Sandbox
With CIS v4 my p2p client (uTorrent, e Mule...) is not working properly anymore
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6573
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #4 on:
October 02, 2010, 05:38:32 PM »
Quote from: Tech on October 02, 2010, 04:43:33 PM
Isn't it a security hole?
Shouldn't the files/folders excluded that way be checked with MD5?
As I replied to your other post, yes exclusions are always a risk, but sometimes that's the only workable option.
As it is a custom application, I don't feel it's a hot target for malware authors.
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
mattpd
Newbie
Offline
Posts: 2
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #5 on:
October 26, 2010, 11:38:32 PM »
+1
Or is it supported already?
I basically have to disable the sandbox feature entirely on my development box, otherwise it's unusable :-/
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6573
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #6 on:
October 27, 2010, 12:29:09 PM »
No it isn't supported already. Hopefully the next release will have a solution.
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
kinemitor
Comodo's Hero
Offline
Posts: 308
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #7 on:
October 30, 2010, 05:28:45 PM »
you ony need to add a exclution folder
D+ setting>execution control>exclutions and add the folder were yyou develop softwares
if not enought then in trusted files add the whole folder XD
«
Last Edit: October 30, 2010, 05:31:15 PM by kinemitor
»
Logged
Win7 x64
CIS x64
OpenDNS
TrueCrypt, Sandboxie
mattpd
Newbie
Offline
Posts: 2
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #8 on:
October 30, 2010, 05:51:17 PM »
HeffeD,
That's unfortunate... seems disabling it is the only workaround for now.
kinemitor,
Are you referring to "Defense+ Settings > Execution Control Settings > 'Exclusions' button" ?
Figures:
http://help.comodo.com/topic-72-1-155-1142-Image-Execution-Control-Settings.html
http://help.comodo.com/uploads/Comodo%20Internet%20Security/ff043a0a3e5bb77e6eca4aae081522d2/5eac818f1e1c4adc19d335055b06586b/03d4320891d353fbd913d8d2a9a216c8/p1.png
The exclusions enabled using the 'Exclusions' button serve exclusively to "exclude some of the file types from being monitored under Detect Shellcode injections."
I believe both HeffeD and I are talking about Sandbox, not shellcode injections detections.
Unfortunately, there is no 'Exclusions' option under "Defense+ Settings > Sandbox Settings":
http://help.comodo.com/topic-72-1-155-1138-Sandbox-Settings.html
Naturally, Trusted files won't work either, because Sandbox keeps switching them to untrusted whenever contents' change.
That makes the Sandbox in current revision of Comodo a bug, not a feature.
A (hopefully temporary) workaround is to disable the Sandbox entirely.
Hopefully it'll get fixed in the update...
Logged
spasserfan
Comodo Family Member
Offline
Posts: 89
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #9 on:
November 24, 2010, 01:31:34 PM »
+1
Logged
Mainframe!
Newbie
Offline
Posts: 4
Defense+ Option NOT To Check EXE File Changes
«
Reply #10 on:
January 06, 2011, 09:56:57 AM »
First, I have tried Comodo Firewall before and was very disappointed.
I have been using PC Tools Firewall Plus v6.0.0.88 for a long time now and was pretty happy until I saw the latest testing at "Matousec".
I was willing to try v5.3.174622.1216 of CIS and WOW I am very impressed!
There is virtually no slowdown to Windows 7 (64 bit) and it seems to catch a lot of things that PC Firewall Plus would miss.
MY WISH (PLEASE, PLEASE) : I am a software developer and compile a new EXE of our product very often, sometimes 10 times an hour. Every time a new EXE is created and run, Defense+ pops up and sandboxes that occurrence of the EXE to whatever setting in the Defense+ Settings (i.e. "Partially Limited").
OK, so I click "Don't isolate it again". A new entry is added to the "Trusted Files" list. I need to exit the EXE and restart it to allow it to run unrestricted.
If I do a new re-compile, a new EXE is created (with a different check sum, MD5, whatever) and when I run it a new pop up is displayed to which I must again answer "Don't isolate it again". Again ANOTHER new entry is created, I need to exit the EXE again and re-run it to allow it to run unrestricted.
So by the end of the day I could have up to 50 new entries in the "Trusted Files" list which all look identical, but behind the scenes they will all have a different (checksum, MD5, whatever).
Please, please add an option to ignore changes to specific EXE files.
Most other HIPS software has this kind of setting, but I really miss that in CIS!!
Logged
deadman
Comodo's Hero
Offline
Posts: 267
I love COMODO.
Re: Defense+ Option NOT To Check EXE File Changes
«
Reply #11 on:
January 06, 2011, 10:29:53 AM »
You can go to Defense+ -> Computer Security Policy -> Defence+ Rules. Then Add and apply the predefined 'Installer/Updater' Policy to that EXE.
Logged
http://twitter.com/ideadman
Mainframe!
Newbie
Offline
Posts: 4
Re: Defense+ Option NOT To Check EXE File Changes
«
Reply #12 on:
January 06, 2011, 10:46:43 AM »
Quote from: deadman on January 06, 2011, 10:29:53 AM
You can go to Defense+ -> Computer Security Policy -> Defence+ Rules. Then Add and apply the predefined 'Installer/Updater' Policy to that EXE.
Wow, you answered that quickly!!
Thank you, thank you. I never thought of doing that. Obviously the "Installer/Updater" rule totally ignores any changes to the EXE itself.
I have deleted all the related entries from the "Trusted Files" list and added the single entry to the "Computer Security Policy -> Defence+ Rules" and it works perfectly now.
I looked everywhere to find a solution, but unless you know the inner workings of the CIS software (like you do), I was at my wits end to know what to set.
Thank you very much indeed!
Comodo Internet Security is a really good product and I would not hesitate to pay for it. I use a different virus scanner right now (Avira Premium) and just the Firewall component from CIS, but I will consider trying the rest of the CIS product at a later date.
Well done on a great product and great support!
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6573
Re: Defense+ Option NOT To Check EXE File Changes
«
Reply #13 on:
January 06, 2011, 04:24:00 PM »
I made a wishlist post about this several months ago.
Sandbox should accommodate constantly changing applications/files
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
Mainframe!
Newbie
Offline
Posts: 4
Re: Sandbox should accommodate constantly changing applications/files
«
Reply #14 on:
January 07, 2011, 04:39:54 AM »
Hi "HeffeD" (thanks for the re-direct to your post) :
I tried to find a wish list topic about this problem, but had no luck. I instead created my own new topic, sorry about that.
This is really a problem for developers and you are very right about the "kludgey workaround" comment. I tried many, many ways to try to deal with this problem and never thought of calling the EXE an "Installer/Updater" at all.
I know that for general usage, you wouldn't want an option like this on the pop up itself, but it would be great to have a way to specifically exclude an EXE with a more specifically named option like "Changing EXE" or "Developer EXE" or something like that.
A warning could also be issued about the danger of enabling such an option on general EXE's.
Anyway: +1 to add this functionality.
Logged
Tags:
Pages:
[
1
]
2
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.14 seconds with 22 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com