COMODO Internet Security 3.5.61373.458 BETA Q&A's, Feedback [CLOSED]

I had some “Q’s” for which I was hoping you could provide “A’s”

Q #1
Previously, Comodo Memory Firewall blocked the following types of attacks:

  • Detection of Buffer Overflows which occur in the STACK memory
  • Detection of Buffer Overflows which occur in the HEAP memory
  • Detection of ret2libc attacks

Is this same protection incorporated into CIS, or were there any additions/changes to the protection?

Q #2
Why is it called “Image Execution Control” when the execution control applies to much more than images. The help file does not provide the answer. If this protection applies to any executable in the “files to check” list, then it may be more clear to name this window “File Execution Control.” That seems more intuitive to me. This would also make it clear why the “buffer overflow” protection is placed in this window (since it applies to the execution of files, not just images). Maybe there is a good explanation for the current format, if so, maybe someone can explain it to me (because it ain’t obvious).

Q #3
Which of the following does the buffer overflow protection apply to?
1)All executables not on the exclusion list?
2)Only executables not on the exclusion list and present on the “files to check” list? (see 1st pic)

Having an “exclusion” list and a “files to check” list in the same window may be very confusing because they seem to be mutually exclusive (i.e. check these but don’t check these!). Perhaps these should be seperated to avoid confusion (See 2nd pic for a way of doing this).

Whoop

[attachment deleted by admin]

I dropped the processing priority for the initial system scanner (cfpconfg.exe) to Below Normal, and system responsiveness seems to be significantly improved while scanning with little apparent impact on scanning. Please consider making this change. Also for the regular on-demand scanner.
Thanks for listening and for CIS,
John

Please make creation of a desktop shortcut optional in the installer.
Thank you for listening and for CIS,
John

I removed the release version of CIS before installing the beta.
Install went smoothly, and the initial scan found only one false positive (no true positives).
A desktop shortcut was created without asking. This should be optional.
After reboot two additional false positives were immediately reported.
I then manually scanned the directory with the first false positive.
It was found again, and I Ignored it.
However, that false positive did not appear in Anti-Virus Events, a bug.
(Separate bug report posted.)

Maybe I’m blind but where can I find the memory firewall and the heuristics?

Memory firewall is in Defense + under Image Execution Control Settings (buffer overflow is at the bottom of the General Tab).

Heuristics are in CAV under Scanner Settings (top of the list for every tab).

this might have been answered, but is boclean integrated now? Also, im seeing a better boot speed & logon speed ompared with previous versions.

logon time is down 1 second, boot time down about 6 or 7. My sound like tiny numbers, but considering how fast my pc is, its always good to be faster!

Q1: It will protect everything you mentioned and like the full Comodo Memory Firewall.

Q2: Help File is not updated in a beta. As for Image Execution, IMO it’s just better integration work and “Execution” of a BO attack is the key here.

Q3: Exclusions on Memory Firewall will not monitor for, As I said it will prevent a BOAttack in every way… If you’re worried about the protection you can try the BOTester in the Memory Firewall board.

Just FYI… A few months ago, Memory Firewall wasn’t ready for integration - It’s a very sophisticated piece of code and unless Comodo was 110% sure to integrate it, then left it in devlopment beta for a while (Memory Firewall) so there are improvements in this one.

Cheers,
Josh

It will be incorporated after this beta (Eg after final release).

Cheers,
Josh

One other thing that is new… Settings are expanded (Eg now there is ThreatCast on/off button and Proxy Config).

Cheers,
Josh

[attachment deleted by admin]

Josh, thanks for the info regarding my previous post. I have some follow up comments/questions.

Okay, the help file will be updated. But, I am not sure if your response competely addresses my question or the issues that were raised. Can you expand on this: Why is it called “Image Execution Control” when the execution control applies to much more than images? Wouldn’t it be more clear to name this window “File Execution Control.”
Maybe I am missing something?

I am not worried about the protection, I just think the interface is confusing: “exclusions” and “files to check” could apply to either/both BO protection and control level. It is like posting a “left turn only” and a “no left turn” sign next to eachother. Most users will be able to correctly guess that the “files to check” refers to the control level and that the “exclusions” refer to BO protection, but users should not have to guess…the GUI should not be ambiguous.

Thanks in advance,
Whoop

P.S. For you wise guys, “BO protection” does not stand for “body odor protection” and does not refer to deodorant! :slight_smile:

I see. Thanks.
Will have a look later

Really impressed no slow first boot, no false positive all set to high. :BNC
First sig update from 1 to 301 did not take long no reboot required. (:CLP)
Thank you to the team.
D.

Still no comment why SafeSurf is included with the installer, despite that CMF is integrated in the Image Execution Settings? Those of you who installed SS, did you get it in the tray like expected?

Thanks

First update was really slow. Now it is doing great

Image Execution & Memory Firewall being in it I have no idea. :-[ Maybe a Developer can confirm, or Melih.

Cheers,
Josh

Yeah true!

But it’s only a test DB…

Cheers,
Josh

What do you mean by that? a test database? No real signatures?

why my copy of cis the db says 301 under win7 and under winxp is 933??? is the new beta BTW

It’s 301 under Vista as well. ???

Well this is weird!!!

Melih!!! Pls can you answer this?? Is this a test DB?? I thought you said something like that. Detection rate dropped A LOT!!!
Heuristics module is detecting LOTS of samples!! This is good!!