CPF 3.0.10.238 BETA 32-Bit Bug Reports

Running the Diagnosis tool, it tries to install the driver again. Boot. No way.

[attachment deleted by admin]

  1. P4 HT [ at ] 3,7 Ghz 1 GB RAM
  2. WinXP Pro SP2 + online updates
  3. Avira Antivir PE
    4. Rules added to ‘Predefined Security Policies’ are not added to ‘Threat this application as’ drop down menu in Defense+ Alert popup.
  4. N/A
  1. P4 HT [ at ] 3,7 Ghz 1 GB RAM
  2. WinXP Pro SP2 + online updates
  3. Avira Antivir PE
    4. Adding new policies to ‘Predefined Firewall Policies’ work not quite correctly.
    If you copy from/add some rules first instead of naming the policy then in many cases you can’t type a name for the policy later.
  4. N/A

I believe that the issue could be that XP isn’t drive C, try changing the installation path in the installer.

tried to change it to

  • f:.…\firewallpro (instead f:.…\firewall)
  • c:\temp\firewall

same result; rollback instead of finished installation

updated:

  • killing the setup on the last screen (email-notification setup) and fixing with the “automatic check / repair” after reboot helped. cfp runs now.

the traffic indicator doesn’t seem to update properly and in real time.
the file submission option is very confusing and mostly doesn’t make sense. the status is very confusing. what does it all mean? it takes patience to do it and in the end you ask yourself “what am i supposed to do now”. anyway, imo, these things should get attention

i like the intrusion attempts feature. it needs to be more consistent. doesn’t seem to update or keep a tab because when you reboot it resets to zero. also, can seem to find a log of blocked intrusions. would be very handy.

CFP will cause 80070643 for Vista 32 bit and you will never be able to get your Windows Updates unless you uninstall CFP.

This is without having any office 2007 Products installed, having Office 2007 products installed and having ose started or not started. Once CFP is uninstalled updates work as normal.

CFP always tells me that a new network is detected when OS is started , but the network is already exsits in the firewall .
OS: windows XP sp2

Greetings,
I’m not sure if it’s the same problem as with 2.4, but try these links below.

Windows Updates Doesn’t Update
https://forums.comodo.com/index.php/topic,1632.0.html
https://forums.comodo.com/index.php/topic,1702.0.html
https://forums.comodo.com/index.php/topic,1955.0.html
https://forums.comodo.com/index.php/topic,6518.0.html
https://forums.comodo.com/index.php/topic,6579.0.html
https://forums.comodo.com/index.php/topic,6836.0.html
https://forums.comodo.com/index.php/topic,7866.0.html

Also, all bug reports should be posted here.

Cheers,
Ragwing

This can,t be be a bug indeed, more of a feature request. I noticed that CFP doesn,t difrentite between global hooks and hook into a specific process. Say a process XYZ, installs a global hook, CFP gives popup of a global hook. Now say a process A injects a dll into another process B. The pop up alert from CFP is the same( global hooking alert). It doesn,t tell that Process A is trying to inject a dll specifically into Process B.

Many other HIPS like NeoavaGuard clearly diffrentiate between two types of hooks( while some HIPS including CFP doesn,t).

I wish that you can incorporate this feature in some build of CFP.

Here is how u can get these alerts.

1- Global hooking alert- it,s very common. U can use any keylogger that hooks keyboard, Firehole leaktest, any legit application with hotkeys will hook the keyboard also via a global hook. I posted example from a legit application, Locate32- a desktop search tool from here:

2- Hook into a specific process- not too common

Elitebar adware uses this type of hooking, you can get thsi type of hooking from two legit applications as well.

  • Install Roboform, let its taryy icon to run. Open IE and disable all IE add-on by Robofrom. Restart IE and u will get an alert about roboform tray icon hooking into IE

  • Download System info( SIW) from here.

Run siw.exe ( doesn,t need an install, it does loads a driver though). In its top menue go to Tools> Eureka. A small windows will appear. From here drag magnifying glass to ur browser or anyother process and u will get a specific hooking alert9 into the browser etc).

I will like to see the opinion of other users and also I will like to see if you are using anyother HIPS, does it differentiate between the two types of hooking or not?

PS: I am not an expert about hooking/ dll injection etc, it,s just my crude observation from various HIPS. I may be wrong at any place.

[attachment deleted by admin]

I have installed the new beta and I have the usual problem with screen resolution. With the resolution set to 120 DPI, I cannot see the Firewall setting button nor the Miscellaneous button. I suppose that I could mess up all my desktop layout to test the firewall, but it does not appeal to me because it would rearrange my icon layout and since there are more icons than the 96 DPI resolution would hold, I really don’t want to do that.

I was using CPF 3.0.10.238 BETA and found that the firefox(2.0.0.9) process wasn’t being released from memory, i did a little more investigation into this and found that neither firefox 2.0.0.8 nor 2.0.0.9 were being released. I uninstalled CPF 3.0.10.238 and reverted back to CPF 2.4.18.184, tested firefox again(both versions) and no problems.

Widows XP Pro with SP2 and all updates.

it seems firefox gets left out with a lot of programs. it was causing problems with me sine 2.0.0.7 too bad because that has become the dominant browser

I didn’t know that, i thought it was a bug with CPF, because with CPF 2.4.18.184 even with the latest firefox 2.0.0.9 there aren’t any problems with the process staying in memory. Thanks for the info.

I also use the latest Firefox browser on WinXP SP2 + online updates and I haven’t noticed any problems with firefox process staying in memory after closing the application. It might be caused by your specific system configuration. If I were you, I would start with disabling all firefox extensions.

I have noticed this same behavior on Vista Premium 32 bit. CPF seems to interfere with the termination of this browser (as well as Netscape Navigator 9). Zone Alarm does not exhibit this behavior.

Interestingly, the latest beta of CPF on a XP SP2 64-bit system does not have this problem with Firefox 2.0.0.9 (or the latest Navigator for that matter). In fact CPF works great in XP 64.

I attempted to classify Firefox as a trusted application in CPF in the Vista system, but that didn’t do anything.

3.0.10 Beta on a Toshiba P205 with Vista Ultimate, Avast!. Read some earlier postings saying more than the basic ICMP rules Echo Request/Echo Response needed for these. So went to Network Security Policy/Global Rules and allowed echo request, echo reply, time exceeded, and host unreachable in and out. Ping and Tracert worked fine. Added a final rule to block other ICMPs in and out, nothing works then. Don’t understand, since experience with KPF and reading the specs for Ping/Tracert seems nothing else is required. What is happening here? Don’t know whether this is a bug or ?

Did you put that rule after the other ones? ‘Allow’-rules must always be put over the ‘Deny’-rule, as CFP reads the rules from top to bottom.

Cheers,
Ragwing

Yes; put the block rule at the end, just like with KPF. Also tried logging the allow rules triggered with and without the block rule, and nothing appears in the log without the block rule, only the block rule when added.