If Download Program Not In Lst Of Download Programs App Run Unrestricted [M1223]

1. The full product and its version:
COMODO Internet Security 8.0.332922.4281 BETA
2. Your Operating System (32 or 64 bit) and ServicePack revision. and if using a virtual machine, which one:
windows 7 sp1 X64 in real system

3. List all the configuration changes you did. Are you using Default configuration? If no, whats the difference?:
Default configuration
4. Did you install over a previous version without uninstalling first, or import a previous configuration file?:
Clean install
5. Other Security, Sandboxing or Utility Software Installed:
No
6. Step by step description to reproduce the issue. Or if you cannot reproduce it, what you actually did before it happened, step by step:
1: Install a download management program which is not listed in the list of “File Downloaders”. The one I tested the program Xtreme Download Manager
2: Files downloaded through these programs will not be restricted through the Auto-Sandbox. They will be run with full rights.

7. What actually happened when you carried out these steps:
If the Download Manager used does not exist in File group apps downloaded through it will be run unrestricted, with full access to the computer.

8. What you expected to see or happen when you carried out these steps, and why (if not obvious):
If CIS is going to rely on a list of download programs in order to decide whether to restrict files or not, this list should be much more comprehensive, not just the famous and popular ones. Alternatively, the rules governing this should be much more stringent and strict.

Are you saying that files downloaded through a trusted downloading program are automatically excluded from restriction?

if the Download Managers Does not exist in this list such that xdm , are automatically excluded from restriction

http://im85.gulfup.com/D3mocs.png

On one condition, that the program Download Managers is not puts downloaded files in a folder downloads

This issue also applies to browsers

Thank you. Please edit your first post so that it is directed towards the danger which all download managers not in that list play in this vulnerability. I had originally thought that perhaps this just applied to downloader programs. I don’t want anyone else to make the same mistake.

Thanks.

Modified topic

Thank you. I made some more edits to the first post, and altered the title. However, I do not understand what you meant by step 3 of your steps for reproduction. Can you please clarify that step?

Thanks.

Thank you to modify the topic :-TU

If the default mode for download management program to save the applications in the download folder, they are automatically put in the Sandbox

http://im73.gulfup.com/JJdPe7.png

But xmd program saves the files on the default mode in the desktop

http://im73.gulfup.com/7QEdjP.png

I believe the devs would be aware of the details of how it works. Thus, to keep it clear, my thinking is that perhaps it would be best to just leave it with steps 1 and 2 for reproduction.

What do you think?

Thanks.

As you like :slight_smile:

Thank you very much for your report in standard format, with all information supplied. The care you have taken is much appreciated by Comodo, and will increase the likelihood that this bug can be fixed.

Developers may or may not communicate with you in the forum or by PM/IM, depending on time availability and need. Because you have supplied complete information they may be able to replicate and fix the bug without doing so.

Many thanks again.

The issue has not been resolved

Thank you for checking this. I have updated the tracker.

The devs have not marked this as Fixed in the tracker. However, sometimes bugs are fixed by the release of new versions, but not marked as Fixed in the tracker.

If you are able please check with the newest version (CIS version 8.0.0.4337) and let me know if this is fixed on your computer with that version.

Thank you.

This issue has not been resolved

Thank you for checking this. I’ve updated the tracker.

Hello,

The devs have not marked this as Fixed in the tracker. However, sometimes bugs are fixed by the release of new versions, but not marked as Fixed in the tracker.

If you are able please check with the newest version (CIS version 8.1.0.4426) and let me know if this is fixed on your computer with that version.

Thank you.

This should be fixed with Comodo Internet Security V10.0.0.6071 Beta if you are still experiencing this issue please make a reply thanks.