v3 fails CPIL tests [Merged Threads]

BFarmer, I apologize. You’re correct. It was late last night and I wasn’t thinking properly.

Once again, my apologies.

Dave

I just installed Comodo Firewall Pro. Rebooted system, and decided to run the Comodo Leaktests.

It has failed all 3 tests. That doesn’t make sense to me!

SZRetired

???

CFP3 has passed every leak test I’ve tried - what settings are you using for Firewall and D+? (Training, train with safe mode, clean PC, custom etc…)
Did you get any alerts? If so how did you answer them?

Train with Safe Mode setting.

XP SP2

NOD32 V3

The only alert I got was that it sent the file and failed the leak test.

First time on this forum…and after looking more, I see a lot of people have the same problem. The good news is that it did pass the GRC Leaktest.

I did not activate the Defense+, as I only wanted the FW function of Comodo. I trust NOD32 3 to protect me.

CFP3 should be able to block it’s own leak test with or without D+ IMO, however, I just re-tried the test and found that the only alerts I got were from D+! This doesn’t seem right especially as V2.4 could pass the test - and it didn’t have the D+ feature.

I did not activate the Defense+, as I only wanted the FW function of Comodo. I trust NOD32 3 to protect me.
I also use NOD32 and think it's a very good AV however - I still have D+ enabled anyway - have you tried it? It works very well along side NOD32 and gives an extra layer of protection that a dedicated AV can't. It's very easy to set up and use (especially in "Clean PC mode" - if your sure your PC is malware free, or "Train with safe mode" - if your not so sure). No AV is perfect - they have to rely on signatures or heuristics for unknown malware, D+ allows you to monitor and selectively allow or deny [b]all[/b] application actions and interactions - and the safe list makes it all very easy, give it a shot!

Hi,

CFP needs Defense+ for top protection, in the new 3 version the network firewall has handed over away the behaviour analysis and parent check included in v2 to the HIPS component. Please note that CFP 3 with Defense+ will likely generate less popups, if left at the default settings and used correctly, than v2 which doesn’t offer a HIPS’ kind of protection. However if you’re not interested in Defense+, and you feel that the protection offered by v3’s network firewall alone is not enough, you could stick to v2 which is a great impregnable firewall and will continue to get support from here.

I tested the CFP with CPIL and failed tests 1 and 2
I installed basic, so what settings do I need to change
to get full protection? Thanks

(J)

I installed v3.0.14.276 after uninstalling v2.

So far I’ve failed all 3 tests. Firefox and/or IE opens with my entered text on it’s page. I had only one popup requesting access to IE - which I allowed - but since then (and numerous reboots later), all 3 tests went to the web-pages with no prompts.

Am I doing something wrong ??

The firewall is up and running on ‘Train with Safe Mode’ and Defense+ set to ‘Clean PC mode’ and generally seems to tun with no problems.

Windows XP SP2
Avira Antivir PE Classic
COMODO BOClean 4.25
Spyware Terminator

did you have this CPIL leak test apps on your comp before installing CFP3 ?

a)yes b)no

if your answer is :
a) with Defense+ set to clean PC mode, CFP think that your PC is clean, everything inside
your PC is considered as “safe”, so CFP3 won’t stop it.
have you tried setting the defense+ to “train with safe mode” or remove the CPIL
leaktest currently on your comp, and try to run a new one?

b) we need some expert help :o ;D

Ganda

Hi Ganda.

The answer is b)…however…I set Defense+ to ‘Train with Safe Mode’ and Test 3 passed - but only the one time - subsequently it fails and I DIDN’T tick the checkbox ‘Remember this answer’ Tests 1 & 2 still fail.

I deleted the CPIL Suite and unzipped and ran it again and all 3 tests fail. It’s all very strange really.

I tried to use the Comodo’s LeakTest software “CPIL Test Suit” with Comodo FireWall 3.0.15, and…
The CFP 3.o Fails?!!!

In the first test I had Defense+ activated…(?)
I did repeat again with Defense+ disabled and the CPIL Suite made CFP 3.0 to fail again?!..

See the attached file…

Why?

Later…
I tried the LeakTest from GRC and it works well.

Answers please… :slight_smile:

Bets regards,
PedroH

[attachment deleted by admin]

(:WAV) hi pedromh
maybe it’s safelisted?
you might wanna read this:
https://forums.comodo.com/leak_testingattacksvulnerability_research/a_new_leak_test_application_from_comodo-t3178.60.html

*did you have Defense+ set to “Clean PC Mode” ?
*did you have the CPIL leaktest app on your comp before installing CFP3?
some ppl have this leak test Safelisted.
on clean PC mode, everything on your PC is considered as safe, CFP won’t ask anything except for a new application.

have you tried to set the Defese + to “train with safe mode” ? or remove your current CPIL leak test, and run a new one.
:■■■■
Ganda

I changed form Clean PC Mode to Train with Safe Mode and just left it there. PC Magazine had a very good article about CFP v3 and suggested to have it set that way for everyday use. That also fixed part of my leaktest problem. Ganda and I spent a few days working on that, before we finally got it working. The explanation from Little Mac really helped us get it figured out. :wink:

yeah, i think we should use “train with safe mode”, i use paranoid mode now ;D. we can’t guarantee that our system is 100% clean (except for a brand new comp).

Just because a file is signed, doesn’t mean it is safe…

Comodo signs all it files, including the leak test, that is why it passes through… "D

What do you mean by “signed”? With Little Mac’s explanation and help from Ganda, the leaktest didn’t get through the firewall for me.

nah, he was joking, or being sarcastic (:TNG)

Digitally signed Boofo. Defense+ uses that to decide whether to allow or not, in one of the modes, I can’t remember which.

Oh, ok, that Digitally signed. :wink:

I do wish there was an easier way to be able to re-block a program in case you accidentally let it through once, though.

huh ??? i thought you’ve figured it out?
*use Defense+ set up higher than “Clean PC mode” : “train with safe mode” or “Paranoid mode”
*don’t tick remember
*in case we accidentally tick remember, remove the remembered app from
Defense+/advanced/computer security policy

just few clicks, i’ve done it so many times, i often accidentally “block” (:TNG)