App Review Comodo Firewall 8 4 vs Malware

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
D

Deleted member 2913

Yes. That's what he means.

COMODO Tech: Oh look Diddy - it's broken. You think we should fix it ?

Diddy (Melih): Nah... let's leave it. :D
You know EfficacyTest.exe is in Comodo Whitelist, right?

Its in whitelist & the samples executed through ET are allowed.

As CS mentioned in her post, testing methodology was flawed for the product tested.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
You know EfficacyTest.exe is in Comodo Whitelist, right?

Its in whitelist & the samples executed through ET are allowed.

As CS mentioned in her post, testing methodology was flawed for the product tested.
Sure in a way it's flawed because Comodo allows everything without detection to get spawned if the parent is safe. We can agree on that but the fact comodo safe list is huge doesn't give me much comfort. What happens if one of all those safe applications decides to spawn malware? They trust a million vendors and a billions applications. Too much maintenance for the user which lowers the safety level by a lot.
Sure one could change the settings but we know what happens when you play with Comodo settings(rule dissappearing bug incoming).
 

Andytay70

Level 15
Verified
Top Poster
Well-known
Jul 6, 2015
737
Sure in a way it's flawed because Comodo allows everything without detection to get spawned if the parent is safe. We can agree on that but the fact comodo safe list is huge doesn't give me much comfort. What happens if one of all those safe applications decides to spawn malware? They trust a million vendors and a billions applications. Too much maintenance for the user which lowers the safety level by a lot.
Sure one could change the settings but we know what happens when you play with Comodo settings(rule dissappearing bug incoming).
Wow get a job at comodo lol
 
D

Deleted member 2913

Sure in a way it's flawed because Comodo allows everything without detection to get spawned if the parent is safe. We can agree on that but the fact comodo safe list is huge doesn't give me much comfort. What happens if one of all those safe applications decides to spawn malware? They trust a million vendors and a billions applications. Too much maintenance for the user which lowers the safety level by a lot.
Sure one could change the settings but we know what happens when you play with Comodo settings(rule dissappearing bug incoming).
Whitelisted programs are allowed to spawned.......is a different thing.

Testing a product, testing methodology should be correct.
Like quite a few test utilities are in Comodo Whitelist, you cannot simply use those whitelisted test utilities to test Comodo, offcoz it will fail.
 
D

Deleted member 2913

This is the same malware pack that I tested CIS but with EfficacyTest.
Here is my test:



I'm sorry Cruelsister if it is wrong to put my link here.
If you (or anybody else) think is wrong I will delete this post.

I think And as cruelsister mentioned, test is flawed for the tested product.
So I think would be good to remove the test.
What you say?
 
H

hjlbx

You know EfficacyTest.exe is in Comodo Whitelist, right?

Its in whitelist & the samples executed through ET are allowed.

As CS mentioned in her post, testing methodology was flawed for the product tested.

If you look - I posted that he should have changed file rating for EfficacyTest.exe from Trusted to Unrecognized.

But it don't matter, my joke about the bugs has truth to it.

COMODO prioritizes their bugs: bypass top priority - everything else - we'll get to it -- someday.
 
H

hjlbx

Sure in a way it's flawed because Comodo allows everything without detection to get spawned if the parent is safe. We can agree on that but the fact comodo safe list is huge doesn't give me much comfort. What happens if one of all those safe applications decides to spawn malware? They trust a million vendors and a billions applications. Too much maintenance for the user which lowers the safety level by a lot.
Sure one could change the settings but we know what happens when you play with Comodo settings(rule dissappearing bug incoming).

COMODO safe list has had digitally signed malware on it. It is rare but it does happen - to all the AV vendors.
 
D

Deleted member 2913

COMODO safe list has had digitally signed malware on it. It is rare but it does happen - to all the AV vendors.
How will Kaspersky do if malware samples are tested with EfficacyTest?
EfficacyTest is trusted by Kaspersky i.e If I run EfficacyTest, it is in "Trusted" category under Application Control.
So will Kaspersky too fail like Comodo?
 

Av Gurus

Level 29
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Sep 22, 2014
1,767
I think And as cruelsister mentioned, test is flawed for the tested product.
So I think would be good to remove the test.
What you say?

No matter what, in this test, we can see when Comodo trust one program and that program runs other malicious programs, the system can easily be destroyed, especially if the HIPS is off, right?

As if you have friend that you trust, and he invite other friends that you do not know you're going to trust them even though they are stealing from your home TV, hi-fi, tables, chairs ...?
 
Last edited:

NekoHr

Level 3
Verified
Well-known
Feb 5, 2016
139
You know EfficacyTest.exe is in Comodo Whitelist, right?

Its in whitelist & the samples executed through ET are allowed.

As CS mentioned in her post, testing methodology was flawed for the product tested.

It is not flawed, it just show one specific situation.
What if malware author bundles EfficacyTest with malware and uses it to run ransome? On the other hand if you disable trust files installed by trusted installer you will get much much more popups and usability goes down. Not an easy nut to crack.
 
  • Like
Reactions: Deleted member 2913
D

Deleted member 2913

It is not flawed, it just show one specific situation.
What if malware author bundles EfficacyTest with malware and uses it to run ransome? On the other hand if you disable trust files installed by trusted installer you will get much much more popups and usability goes down. Not an easy nut to crack.
I agree with the security risks involved with whitelisted programs spawning freely...but guess whitelist in other products too work the same way...may be for security + usability.

My opinion -
I agree with the test showing a security risks involved with the implementation of feature.
I dont agree with the product failed, one cannot use whitelisted testing tools.
 

kibinimatik

New Member
Jul 19, 2016
1
This is the same malware pack that I tested CIS but with EfficacyTest.
Here is my test:



I'm sorry Cruelsister if it is wrong to put my link here.
If you (or anybody else) think is wrong I will delete this post.

Please tell me if you have changed CIS language after installation
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top