Advice Request Am I protected with COMODO Firewall only?

Please provide comments and solutions that are helpful to the author of this topic.
Status
Not open for further replies.
As long as someone doesn't find a Comodo bypass, you don't mess the settings and Comodo doesn't whitelist a malware and then you are hit with it because they notice then you are protected.

EDIT: After @Yash Khan comment remember to enable proactive profile for what i said to apply. Main protection comes from the sandbox.
 
Last edited:
If you are using the AutoSandbox feature and everything is configured correctly and working then you should be fine - the chances of you running into new unknown malware which will bypass the Comodo Sandbox is very small, how many people have you seen talk about how this happened to them? You've probably seen none, because it takes lots of expertise and knowledge on the product internals to do this, and most people with this expertise are on the good side trying to report the vulnerabilities to the vendors for money rewards, instead of risking themselves to facing jail time by helping black hat hackers. A lot of the "vulnerabilities" posted online about real sandbox bypasses are flawed one way or another (e.g. user error or just a bug as opposed to virtualised malware really gaining access to the host from the guest).

Regardless, don't be click-happy just because you are using an auto-sandbox otherwise you'll be begging for an infection. Make sure you still apply good online practises: don't handle attachments from unknown e-mails, don't run programs you are unsure of, and don't randomly visit websites found on search engines which appear to be suspicious.

You are always the first line of defence, remember this, drill this message into your brain... Never forget it. ;)
 
Enable autosandbox (disabled by default), turn on proactive defense, enable HIPS, check Filter IPv6 traffic, Block fragmented IP traffic, Do Protocol Analysis, Enable anti-ARP spoofing.

Set Sanboxto "All Applications", "All" locations/origins, file rating "Unrecognized" and restrict level "Untrusted".
 
  • Like
Reactions: Wave and Jashin
Enable autosandbox (disabled by default), turn on proactive defense, enable HIPS, check Filter IPv6 traffic, Block fragmented IP traffic, Do Protocol Analysis, Enable anti-ARP spoofing.

Set Sanboxto "All Applications", "All" locations/origins, file rating "Unrecognized" and restrict level "Untrusted".
thank you so much :)
 
  • Like
Reactions: Wave and RoboMan
LAST QUESTION: Should i remove AVG Internet Security and install ONLY Comodo Proactive Defence(with HIPS,firewall and auto-sandbox)or again Comodo FW and Panda Free AV???
 
  • Like
Reactions: Deleted member 2913
LAST QUESTION: Should i remove AVG Internet Security and install ONLY Comodo Proactive Defence(with HIPS,firewall and auto-sandbox)or again Comodo FW and Panda Free AV???
I would not run a security suite along with COMODO. That's not necessary and might cause conflicts. The most you need, assuming you like the idea of layered protection, is a light AV, such as Panda or Avast or Windows Defender.

I also beg to differ with some of the paranoid settings for COMODO that you were suggested.
I agree that proactive mode is a wise choice. But I would keep the default sandbox settings of proactive mode, and turn off the HIPS.

If you want extra protection, you could run your browser (and other sensitive apps) in sandbox.
 
I would not run a security suite along with COMODO. That's not necessary and might cause conflicts. The most you need, assuming you like the idea of layered protection, is a light AV, such as Panda or Avast or Windows Defender.

I also beg to differ with some of the paranoid settings for COMODO that you were suggested.
I agree that proactive mode is a wise choice. But I would keep the default sandbox settings of proactive mode, and turn off the HIPS.

If you want extra protection, you could run your browser (and other sensitive apps) in sandbox.
why HIPS off?
 
  • Like
Reactions: SHvFl
why HIPS off?
because autosandbox will stop any unrecognized file from executing, from anywhere on your PC, if you are in proactive config.
HIPS just controls what an unsandboxed file is allowed to do. If you don't let it out of the sandbox, you are always safe.
And if the file is not autosandboxed, because it is trusted, then HIPS will not give you alerts for it anyway. So you don't gain anything from HIPS, except in exceptional situations.
 
To answer the question.

Yes but with proper configuration.

Autosandbox is very powerful that sometimes can mislead to mistakes because of the nature where relies on reputation based.

HIPS on the other hand is different compare on version 4 or 5 of Comodo; it controls based on auto-sandbox mechanism unless you disabled it.
 
  • Like
Reactions: SHvFl
When I used COMODO myself I usually set it to block any unrecognised files - tested them in a virtual machine first - upload it to Virus Total if I was at all unsure.
 
Status
Not open for further replies.

You may also like...