App Review Comodo Firewall Bypassing a Bypass

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.
Content created by
cruelsister

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,471
With UAC enabled and a person blocking everything that resulted in a UAC popup may make one "Feel Good" but won't add very much to overall security especially as UAC can be easily bypassed (I'm sure I made a couple of videos on this in the past).
The UAC bypasses usually happen when the security does not use strong containment. In the case of Comodo with containment set to Restricted or Untrusted, bypassing UAC would be much harder. I cannot recall any example of bypassing UAC in such containment.
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,471
@Andy Ful @cruelsister Does Silent Mode with the firewall set to block popup requests obviate the need to disable UAC?

You probably had in mind disabling LUA by using the reg tweak or GPO. This makes the Comodo sandbox fully functional. But, at the same time, anything running outside the sandbox is more vulnerable. The malware/exploit does not need to use privilege escalation or UAC bypass.

Second, if it does not, would disabling UAC after setting to always notify stop this exploit?
It does and disabling LUA can stop that exploit too.
By the way, if you disable LUA then UAC is automatically set to "Never notify."
But, when LUA is enabled and you set UAC to "Never notify", this will not change the LUA.

I understand it would cripple run-as and apparently mess with auto containment.
When LUA is disabled, everything executed by the user starts by default as administrator. So, the "Run as administrator" option is not needed anymore.

Third, I saw a brief mention of standard user accounts. What impact does it have to run Cruel CF in silent mode and block popup requests within a standard account, with or without UAC disabled?
That particular exploit will be blocked on SUA independently of the LUA enabled/disabled.
The advantage of using SUA happens when the UAC bypass is not contained by Comodo.
 
Last edited:

ebocious

Level 5
Verified
Well-known
Oct 25, 2018
235
When LUA is disabled, everything executed by the user starts by default as administrator. So, the "Run as administrator" option is not needed anymore.
In an administrative account, you mean. In SUA, it is, and will hamper installers and applications that require elevated privileges on every execution.
 

ebocious

Level 5
Verified
Well-known
Oct 25, 2018
235
No- please note that UAC (enabled) will prevent CF from reacting (as it normally would) to this attack, so any Comodo setting change after that file is run would be of no consequence. The real question here is if the use of UAC can be justified by anyone, especially as some cutesy cmd line arguments can be added to bring down other AM applications.

With UAC enabled and a person blocking everything that resulted in a UAC popup may make one "Feel Good" but won't add very much to overall security especially as UAC can be easily bypassed (I'm sure I made a couple of videos on this in the past). And even setting the UAC slider to Never Notify will still allow UAC to be enabled, opening up a system to potential issues.

But as always, your system, your choice.
Thank you. I am taking your advice in this instance, as I am of the understanding that a lot of exploits these days are designed to work in user context, in which case I would expect more mileage from Cruel CF than from UAC. I also have a standard account for regular use.

I don't know if you saw a comment I made previously, but I understand that CF is no longer free (only antivirus). The free firewall still gets signature updates, but not version updates. Are you using the paid product now, or sticking with the last free version?
 

ErzCrz

Level 22
Verified
Top Poster
Well-known
Aug 19, 2019
1,155
Thank you. I am taking your advice in this instance, as I am of the understanding that a lot of exploits these days are designed to work in user context, in which case I would expect more mileage from Cruel CF than from UAC. I also have a standard account for regular use.

I don't know if you saw a comment I made previously, but I understand that CF is no longer free (only antivirus). The free firewall still gets signature updates, but not version updates. Are you using the paid product now, or sticking with the last free version?
CIS / CF is still completely free. You can get CIS/CF Premium (Free) from here: CIS/CF Version 12.3.3.8152 which is the latest version. It's the Premium Version to download and then you can choose with the installer whether to install both Firewall and Antivirus or just one or the other as detailed in @cruelsister 's video: Comodo Firewall 2025 Setup & Commentary. This latest version fixes the recent Certificate issue.
 
  • Like
Reactions: ebocious

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,471
Why I do not recommend disabling LUA:
 
  • +Reputation
Reactions: ErzCrz

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top