Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other firewalls
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old November 24th, 2008, 11:23 PM
Juha L Juha L is offline
Infrequent Poster
 
Join Date: Dec 2007
Posts: 46
Default Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by Subgud
In comodo firewall behavior settings i found a slider to reduce alerts. It worked for me. For the test i had paranoid modus and custom policy, but comodo seems to remember the settings you had for this test, so after the first run you can turn it back to clean pc mode and you will have very few pop ups!


Aha, and what does Comodo score when first run in "very low" alert mode? Sounds like this remembering of the leak test results after first running it in paranoid mode is kinda artificial and not close to the real life situation?
__________________
System: Vista SP2 Home Premium
Protection: Sandboxie - Avira Free AntiVirus
Other: Windows Firewall Control - Secunia PSI - MBAM - Hitman Pro - Firefox + AdblockPlus+KeyScrambler

Last edited by Juha L : November 24th, 2008 at 11:57 PM.
  #27  
Old November 25th, 2008, 11:25 AM
alex_s alex_s is offline
Very Frequent Poster
 
Join Date: Aug 2007
Posts: 1,251
Default Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by firzen771
i run the actual firewall part of PC tools firewall and disable the enhanced Security Verification (HIPS). with purely the firewall part i get 60/340.

i believe a firewall should be exactly as it names says, a "Firewall".

and with JUST Mamutu in paranoid mode i get 10/340. but then again Mamutu is meant to block bad behavior not leak tests.

Firewall should be only firewall, behavior blocker should be only behavior blocker. But what then should stop the leaks ? Special leaks blocker ?
  #28  
Old November 25th, 2008, 03:57 PM
firzen771's Avatar
firzen771 firzen771 is offline
Massive Poster
 
Join Date: Oct 2007
Location: Ontario, Canada
Posts: 4,802
Default Re: Comodo Leak Tested Suite Updated!

HIPS... thats what stops the leaks as well as many other things that it protects, when u use a firewall like comodo or online armor, its not the firewall component blocking most of the leaks, its the HIPS part of it.
__________________
Windows 7 x64 - Windows Defender: Disabled - UAC: Disabled

Real-Time: Avast Free / Zemana Free / WinPatrol
On-Demand: HitmanPro / MBAM
  #29  
Old November 25th, 2008, 06:25 PM
3xist
 
Posts: n/a
Default Re: Comodo Leak Tested Suite Updated!

Hi Guys.

Thanks for testing your products. You can also add your product name and results here So we can add results & products to the list. If a product or result is wrong - Please let us know. Remember this is test the full power of your application.
  #30  
Old November 26th, 2008, 09:22 PM
tsec tsec is offline
Regular Poster
 
Join Date: Nov 2008
Posts: 181
Default Re: Comodo Leak Tested Suite Updated!

Results posted 3xist.

Now I am off to slash my wrists...
  #31  
Old November 26th, 2008, 09:25 PM
3xist
 
Posts: n/a
Default Re: Comodo Leak Tested Suite Updated!

Thanks mate!
  #32  
Old November 27th, 2008, 05:57 AM
alex_s alex_s is offline
Very Frequent Poster
 
Join Date: Aug 2007
Posts: 1,251
Default Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by firzen771
HIPS... thats what stops the leaks as well as many other things that it protects, when u use a firewall like comodo or online armor, its not the firewall component blocking most of the leaks, its the HIPS part of it.

Yep, HIPS stops most, but HIPS itself knows nothing about outbound protection, and leak-tests aim to break outbound. This is why neither only firewall, nor only HIPS can be effective against leaks, but only combined product.
  #33  
Old November 27th, 2008, 07:35 AM
firzen771's Avatar
firzen771 firzen771 is offline
Massive Poster
 
Join Date: Oct 2007
Location: Ontario, Canada
Posts: 4,802
Default Re: Comodo Leak Tested Suite Updated!

unless the HIPS has outbound protection as well... how else would ProSecurity (which is a HIPS) be able to get such a high rank at matousec?
__________________
Windows 7 x64 - Windows Defender: Disabled - UAC: Disabled

Real-Time: Avast Free / Zemana Free / WinPatrol
On-Demand: HitmanPro / MBAM
  #34  
Old November 27th, 2008, 09:33 AM
bonedriven's Avatar
bonedriven bonedriven is offline
Frequent Poster
 
Join Date: Jan 2007
Posts: 549
Default Re: Comodo Leak Tested Suite Updated!

I'm using Avira personal+OA3
When I downloaded the program,Avira said coat.dll contains malicious code.I think the test has not begun yet,so I click ignore.

After I ran the test,it seems it stuck at 270/340.I couldn't close the program.I clicked "test" again.Then It seems it went on and finished at 330/340.Still,It stuck there.I couldn't close the program.I need to end the process in tast manager.

  #35  
Old November 27th, 2008, 06:57 PM
3xist
 
Posts: n/a
Default Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by bonedriven
I'm using Avira personal+OA3
When I downloaded the program,Avira said coat.dll contains malicious code.I think the test has not begun yet,so I click ignore.

After I ran the test,it seems it stuck at 270/340.I couldn't close the program.I clicked "test" again.Then It seems it went on and finished at 330/340.Still,It stuck there.I couldn't close the program.I need to end the process in tast manager.


Try disabling Avira AV all together during the test.

Quote:
Originally Posted by firzen771
unless the HIPS has outbound protection as well... how else would ProSecurity (which is a HIPS) be able to get such a high rank at matousec?

I know ProSecurity has been discontinued, The owner/Developer joined Comodo - he was trying to sell the code before....
  #36  
Old November 27th, 2008, 07:58 PM
firzen771's Avatar
firzen771 firzen771 is offline
Massive Poster
 
Join Date: Oct 2007
Location: Ontario, Canada
Posts: 4,802
Default Re: Comodo Leak Tested Suite Updated!

hmm that sounds very promising for the developement of Comodo's D+ with his help.
__________________
Windows 7 x64 - Windows Defender: Disabled - UAC: Disabled

Real-Time: Avast Free / Zemana Free / WinPatrol
On-Demand: HitmanPro / MBAM
  #37  
Old November 27th, 2008, 07:59 PM
bonedriven's Avatar
bonedriven bonedriven is offline
Frequent Poster
 
Join Date: Jan 2007
Posts: 549
Default Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by 3xist
Try disabling Avira AV all together during the test.

Thank you for your reply.
The difference after I disable Avira AV is that I then can manually exit the test.But it still stuck at 270/340.If I click exit,it's ok.If I click test again,the result will show 330/340

So,I don't know which one is the result(the "?" button doesn't work either)

The test just doesn't go well with my system
  #38  
Old November 28th, 2008, 08:45 AM
alex_s alex_s is offline
Very Frequent Poster
 
Join Date: Aug 2007
Posts: 1,251
Default Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by firzen771
unless the HIPS has outbound protection as well... how else would ProSecurity (which is a HIPS) be able to get such a high rank at matousec?

Because ProSecurity is very good HIPS. Though, for now it has 93% against 62 tests. I'd like to see its result against all the 73 tests. And I think there is some upper limit for pure HIPS (even close to ideal) in matou rate.
  #39  
Old November 28th, 2008, 12:57 PM
alex_s alex_s is offline
Very Frequent Poster
 
Join Date: Aug 2007
Posts: 1,251
Default Re: Comodo Leak Tested Suite Updated!

What does it mean ? Do not ask me, please, how did I get these results, because they were got by self-made means and I'm completely sure everything was blocked correctly. It just seems "error" state doesn't count as "protected" which is wrong, I think.

Score 280/340

1. Hijacking: ActiveDesktop Protected
2. Hijacking: AppinitDlls Protected
3. Hijacking: ChangeDebuggerPath Protected
4. Hijacking: StartupPrograms Protected
5. Hijacking: SupersedeServiceDll Protected
6. Hijacking: UIHost Protected
7. Hijacking: Userinit Protected
8. Hijacking: WinlogonNotify Protected
9. Impersonation: BITS Protected
10. Impersonation: Coat Protected
11. Impersonation: DDE Protected
12. Impersonation: ExplorerAsParent Protected
13. Impersonation: OLE automation Protected
14. InfoSend: DNS Test Protected
15. InfoSend: ICMP Test Protected
16. Injection: AdvancedProcessTermination Protected
17. Injection: APC dll injection Error
18. Injection: CreateRemoteThread Error
19. Injection: DupHandles Protected
20. Injection: KnownDlls Protected
21. Injection: ProcessInject Protected
22. Injection: Services Protected
23. Injection: SetThreadContext Protected
24. Injection: SetWindowsHookEx Protected
25. Injection: SetWinEventHook Protected
26. Invasion: DebugControl Protected
27. Invasion: FileDrop Protected
28. Invasion: PhysicalMemory Protected
29. Invasion: RawDisk Protected
30. Invasion: Runner Protected
31. RootkitInstallation: ChangeDrvPath Error
32. RootkitInstallation: DriverSupersede Error
33. RootkitInstallation: LoadAndCallImage Error
34. RootkitInstallation: MissingDriverLoad Error
  #40  
Old November 29th, 2008, 06:58 PM
SamSpade SamSpade is offline
Frequent Poster
 
Join Date: Oct 2006
Posts: 415
Default Re: Comodo Leak Tested Suite Updated!

Just ran the CLT on Online Armor AV+ v. 3.x.208: 340/340

Had a pop-up for each test (sometimes more than one pop-up), so I was busy. But OA is doing the job it was created to do.

Second build in a row that has scored a perfect result, this time my browser (Firefox 3.04) was open. Not bad.

SamSpade


|||
__________________
Beta-testing Online Armor w AV (OA++); have used many others also.
  #41  
Old November 29th, 2008, 07:15 PM
Carver's Avatar
Carver Carver is offline
Very Frequent Poster
 
Join Date: Feb 2006
Location: USA
Posts: 1,417
Default Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by SamSpade
Just ran the CLT on Online Armor AV+ v. 3.x.208: 340/340

Had a pop-up for each test (sometimes more than one pop-up), so I was busy. But OA is doing the job it was created to do.

Second build in a row that has scored a perfect result, this time my browser (Firefox 3.04) was open. Not bad.

SamSpade


|||
I ran CLT on Online Armor AV and Opera v9.62 and Online Armor AV DELETED OPERA also all Opera icons were missing, I double clicked on the .exe and nothing happened, I had to re install to repair Opera.
  #42  
Old November 29th, 2008, 07:29 PM
SamSpade SamSpade is offline
Frequent Poster
 
Join Date: Oct 2006
Posts: 415
Default Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by Carver
I ran CLT on Online Armor AV and Opera v9.62 and Online Armor AV DELETED OPERA also all Opera icons were missing, I double clicked on the .exe and nothing happened, I had to re install to repair Opera.


I had a similar problem when I ran CLT under OA AV+ v. 3.x.203: OA changed my "program access" to "blocked" for Firefox under the "Firewall" tab. Once I fixed that, and also re-installed Ffox over the top, all worked as it should; but I did run the test the second time with Ffox closed.

I have tried Opera now (under OA AV+ v. 3.x.208 ) and Opera works fine.

Did you have Opera open when you ran CLT?? That could be the problem.

Sam

|||
__________________
Beta-testing Online Armor w AV (OA++); have used many others also.
  #43  
Old November 29th, 2008, 07:50 PM
Carver's Avatar
Carver Carver is offline
Very Frequent Poster
 
Join Date: Feb 2006
Location: USA
Posts: 1,417
Default Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by SamSpade
I had a similar problem when I ran CLT under OA AV+ v. 3.x.203: OA changed my "program access" to "blocked" for Firefox under the "Firewall" tab. Once I fixed that, and also re-installed Ffox over the top, all worked as it should; but I did run the test the second time with Ffox closed.

I have tried Opera now (under OA AV+ v. 3.x.208 ) and Opera works fine.

Did you have Opera open when you ran CLT?? That could be the problem.

Sam

|||
Yes, I re ran CLT, I closed Opera. This time it just blocked Opera.
  #44  
Old November 30th, 2008, 04:02 AM
SamSpade SamSpade is offline
Frequent Poster
 
Join Date: Oct 2006
Posts: 415
Thumbs up Re: Comodo Leak Tested Suite Updated!

Quote:
Originally Posted by Carver
Yes, I re ran CLT, I closed Opera. This time it just blocked Opera.


Very good!! If you unblock Opera in the rules, does OA still stop Opera from opening??


///
__________________
Beta-testing Online Armor w AV (OA++); have used many others also.

Last edited by SamSpade : November 30th, 2008 at 04:20 AM.
 

Wilders Security Forums > Security Products > other firewalls « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:27 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums