Author Topic: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released![Locked]  (Read 112576 times)

Offline Star Shadow

  • Computer Security Testing Group
  • Comodo's Hero
  • *****
  • Posts: 373
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #45 on: March 24, 2008, 05:33:36 AM »
This is one issue I noticed. I opened Photoshop and there were a bunch of popups associated with it. Some of them dealt with modifying the registry keys, and on these popups TC said that it was encountered 42 or some times before and it was like over 80% of those times people said no. However, I noticed that for some programs I get the same warning every time I open the program, so it is likely that one person denied the registry thing multiple times opening up Photoshop several times over the course of days. This kinda skews the data. And users that don't know anything about Photoshop will see that it was encountered nearly 50 times before and most people said no, which is the incorrect choice.

So, can TC be made such that it only records one selection per person? Sometimes the same popup is given over the course of using the program or after opening and closing because the program really wants to access that whatever it is that CFP is denying it.

So, can someone erase all the negative responses to Photoshop so new users are not confused? Photoshop really does need to do those actions and some dummy said no multiple times skewing the results. Seriously. It does need to do all those actions. It is a trusted program by Adobe, I don't think adobe will make a program that corrupts system files. ;) So, can adobe software be added to a trusted list as will by default?

Thanks.
Married to a loving wife. :)

Offline egemen

  • Comodo Staff
  • Comodo's Hero
  • *****
  • Posts: 3380
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #46 on: March 24, 2008, 12:59:25 PM »
PLEASE implement command line viewing into CFP before taking the Threatcast project any further!

It is one thing that 2000 people allowed rundll32.exe which was trying to run shell32.dll and a completly different thing if they allowed "rundll32.exe virus.dll ,s". Threatcast SHOULD ALLOW users to discriminate not only between the applications that are being run, but also their command lines.

CFP does make difference between them. You dont need commandline processing for rundll32.exe. Commandline processing will be introduced but it is not vital for your example. TC should be showing for the proper DLL not for rundll.32.exe alone.

Egemen

Offline wolfmei

  • Computer Security Testing Group
  • Newbie
  • *****
  • Posts: 21
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #47 on: March 26, 2008, 12:35:01 PM »
sorry, this beta can't remember some rules, not all but some programs.
when restart computer ,my IE rules (firewall rule )always GONE, i think this is a BUG..is it anybody got the same Situation? :THNK

Offline Blas

  • Computer Security Testing Group
  • Comodo's Hero
  • *****
  • Posts: 373
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #48 on: March 26, 2008, 12:53:53 PM »
It happened to me in the beginning too, but it disappeared with a few reboots.

Offline Dennis2

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 9663
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #49 on: March 26, 2008, 02:02:29 PM »
sorry, this beta can't remember some rules, not all but some programs.
when restart computer ,my IE rules (firewall rule )always GONE, i think this is a BUG..is it anybody got the same Situation? :THNK
If you go to network/defence security when you have a new rule open then click apply before rebooting this seems to cure it for me with some rules that will not stay.
Dennis
Moderator: Aims Forum a friendly place. Any concerns? Please PM me and/or review the Forum Policy 2012Updated.
System: Centos 7.9 x64, APF, HTTPS Everywhere, ABP, NoScript
 Fedora 33 x64, APF, HTTPS Everywhere, ABP

Offline Searinox

  • Comodo's Hero
  • *****
  • Posts: 545
  • Do you like fire? I'm full of it.
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #50 on: March 26, 2008, 06:24:35 PM »
CFP does make difference between them. You dont need commandline processing for rundll32.exe. Commandline processing will be introduced but it is not vital for your example. TC should be showing for the proper DLL not for rundll.32.exe alone.

Egemen
That's just one out of many. Really command line should be there.

Offline gibran

  • Average User
  • Comodo's Hero
  • *****
  • Posts: 5056
  • A bad workman always blames his tools
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #51 on: March 27, 2008, 01:29:49 PM »
That's a good news that commandline processing will be added. If possible please add some regex support too. :a0

BTW I had a crash during installation (dump attached).
This is the same type of crashes I still get with the updater and I got with file submit (I guess that file submit still crashes but I've not tested it again)

I have few other glitches to report:
File submission don't support .scr files.
Manage My configurations Import or Import As  fails to import cfp.xml
Manage My configurations Export doesn't enable *.xml extension fin the file save dialog
Threatcast settings have no GUI dialog
cfpupdat.exe have no trustInfo embedded Manifest (I may be wrong but I guess this is of utmost importance)


[attachment deleted by admin]
« Last Edit: March 29, 2008, 11:19:36 AM by gibran »
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams

Leopard19

  • Guest
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #52 on: March 28, 2008, 07:03:09 AM »
first contact ever with TC: reporting that 12 users out of 14 prevented (blocked) Internet Explorer from accessing www.google.com... (:WAV) the underworld has stricken again  ;D

just editing this post to mention that the pic I attached is only one among 4 or 5 alerts of the same type popping up in a row, all with approximatively  the same TC rating, and all with google IPs.

[attachment deleted by admin]
« Last Edit: March 28, 2008, 09:29:50 AM by Leopard19 »

Offline gibran

  • Average User
  • Comodo's Hero
  • *****
  • Posts: 5056
  • A bad workman always blames his tools
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #53 on: March 28, 2008, 08:20:00 AM »
geez http://216.239.59.104/ is google indeed anyway reversedns is not able to resolve the name.
I guess some DNS-roundrobin was used to map google.com to that ip. Maybe the ip are to be checked using IP-whois info to get the entire assigned ip range.
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams

Offline Dennis2

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 9663
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #54 on: March 28, 2008, 04:28:57 PM »
I have uninstall CPF3 Beta with Threatcast since there have been no posts reguarding saving rules in limited account in XP and I do not want to run XP in admin account so that I can save rules will try again with next release.
Works fine in the latest CPF3.0.21.329 rules are saved in limited account.
Dennis
Moderator: Aims Forum a friendly place. Any concerns? Please PM me and/or review the Forum Policy 2012Updated.
System: Centos 7.9 x64, APF, HTTPS Everywhere, ABP, NoScript
 Fedora 33 x64, APF, HTTPS Everywhere, ABP

Offline gibran

  • Average User
  • Comodo's Hero
  • *****
  • Posts: 5056
  • A bad workman always blames his tools
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #55 on: March 29, 2008, 06:38:52 AM »
first contact ever with TC: reporting that 12 users out of 14 prevented (blocked) Internet Explorer from accessing www.google.com... (:WAV) the underworld has stricken again  ;D

just editing this post to mention that the pic I attached is only one among 4 or 5 alerts of the same type popping up in a row, all with approximatively  the same TC rating, and all with google IPs.
geez http://216.239.59.104/ is google indeed anyway reversedns is not able to resolve the name.
I guess some DNS-roundrobin was used to map google.com to that ip. Maybe the ip are to be checked using IP-whois info to get the entire assigned ip range.

I guess I found out the real reason.
Info is added to TC public DB even if the user press cancel
« Last Edit: March 29, 2008, 07:50:14 AM by gibran »
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams

Leopard19

  • Guest
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #56 on: March 29, 2008, 10:18:45 AM »
I guess I found out the real reason.
Info is added to TC public DB even if the user press cancel

you're right Gibran; I didn't say it and I probably should have: I pressed cancel after each alert. Another Google IP was launched after each cancellation with a worse TC rating, one more blocking vote each time: mine. Which also means that the TC rating was being applied not just to one IP but to the range.
« Last Edit: March 29, 2008, 10:20:49 AM by Leopard19 »

Offline gibran

  • Average User
  • Comodo's Hero
  • *****
  • Posts: 5056
  • A bad workman always blames his tools
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #57 on: March 29, 2008, 11:25:41 AM »
I wonder if we have to open a separate bugreport topic for the beta.

BTW about file submission the unsupported extension was .SCR (screensaver applications)
These issues apply to 3.022 as well
Image Exec. Control doesn't check if digital signature is invalid (3.0.21 x32) this one is a critical issue.
Impossible to add Apps to Pending Or Trusted lists (3.0.21 X32)
« Last Edit: March 30, 2008, 01:34:08 PM by gibran »
"In the beginning the Universe was created. This has made a lot of people very angry and has been widely regarded as a bad move."- Douglas Adams

Offline Eric Cryptid

  • Global Moderator
  • Comodo's Hero
  • *****
  • Posts: 2840
  • Security Saskquatch
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #58 on: March 30, 2008, 09:19:47 AM »
Would it be possible with Threatcast for example the alert in Leopards message the alert automatically selected "Block" instead of "Allow" so that if you just click ok then it will go with what the majority have chosen? My wife just clicks OK all the time.

Eric

Moderator: Any concerns? PM me and/or review the Forum Policy
System: 64 bit Win 10
Realtime Protection:CIS 12

Offline Melih

  • CEO - Comodo
  • Administrator
  • Comodo's Hero
  • *****
  • Posts: 14690
    • Video Blog
Re: COMODO Firewall Pro 3.0.22.327 BETA with Threatcast Released!
« Reply #59 on: March 30, 2008, 12:02:44 PM »
Would it be possible with Threatcast for example the alert in Leopards message the alert automatically selected "Block" instead of "Allow" so that if you just click ok then it will go with what the majority have chosen? My wife just clicks OK all the time.

Eric

I guess there could be a config option to go with the majority and don't ask the user.

Melih

 

Free Endpoint Protection
Seo4Smf 2.0 © SmfMod.Com Smf Destek