App Review Comodo Firewall- Cruelsister Variation

It is advised to take all reviews with a grain of salt. In extreme cases some reviews use dramatization for entertainment purposes.

Nightwalker

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
May 26, 2014
1,339
I noticed that unknow files that request privilege elevation will run actually at "Partially Limited" settings instead of the "Restrited", isnt it dangerous?

And what about this change? Why disable this setting now?

w3fZEpb.png
 

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,716
FYI if you cut down the TVL to a few really trusted vendors, like many users do, this increases security a little, and increases false positives a lot.

If you run "Unrecognized" restricted in the sandbox, you are safe for sure. I have even set it to run Virtually and added the extra option to "Run Limited" to the rule. I feel safe. This means that programs have a half decent chance of running so I can see what they do in the sandbox. With OSArmor there and AppCheck, I feel like it's safe.

Trimming the TVL is great for learning the program, but it's not really an improvement on protection, considering Cloud Lookup has to be turned off too. At least, if you don't want Comodo adding vendors to the TVL every time you install a program from a vendor you removed.

I think the best solution is to run Comodo for about 6 months, save your settings, and then uninstall and reinstall the latest. The update process is still rough for sure. I haven't ever experienced a loss of settings from an update, however, and I don't think it's a common thing.

I would say the biggest thing to look for would be something like->install Comodo Internet Security Essentials during installation of Comodo->remove CISE because it doesn't do anything->Comodo main still wants it->"error...Comodo must be reinstalled"...this kind of thing. I really don't like the CISE element of the program. Appears to break things to me. Still, I think Comodo has very few bugs under the hood. When there is a problem, protection doesn't quit...at least as far as I can tell. Like an old car with low miles LOL...
 

AtlBo

Level 28
Verified
Top Poster
Content Creator
Well-known
Dec 29, 2014
1,716
I noticed that unknow files that request privilege elevation will run actually at "Partially Limited" settings instead of the "Restrited", isnt it dangerous?

And what about this change? Why disable this setting now?

I guess I do alot of stupid things. One of them is allow these alerts. Basically, it's because they happen like maybe a second before the containment/sanbox alert. If I know I want to run something, I can use this to bypass the sandbox. Is it safe...NO

I think Comodo wants to do something with that setting but they don't know what to do. Users want to know, and I think the devs sense that some want to run without UAC and so on. Maybe they will come up with a way of burying advanced/risk taker settings eventually or something...
 

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
Nightwalker- Comodo has actually upped the protection of the sandbox, so the Privilege Elevation alert would just result in an unneeded popup that may confuse some. Any such request for elevation will be negated by the sandbox at this level (Restricted).

I did not make this clear and you have my apologies for that omission.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
An allegory for Comodo installations and program updates:

Ten people ran through a minefield.
Two died.
Two were wounded.
The remaining six were interviewed by the press the next day.
Five said they were glad they made it, but they consider themselves lucky.
One said, "Heck, if I can do it, anyone can do it. It's their own fault for getting blown up!"
The Comodo Daily quoted one of them...
 

Garzaman

Level 3
Verified
Well-known
Nov 14, 2017
126
An allegory for Comodo installations and program updates:

Ten people ran through a minefield.
Two died.
Two were wounded.
The remaining six were interviewed by the press the next day.
Five said they were glad they made it, but they consider themselves lucky.
One said, "Heck, if I can do it, anyone can do it. It's their own fault for getting blown up!"
The Comodo Daily quoted one of them...
Hahaha! Good point
 

Nightwalker

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
May 26, 2014
1,339
Nightwalker- Comodo has actually upped the protection of the sandbox, so the Privilege Elevation alert would just result in an unneeded popup that may confuse some. Any such request for elevation will be negated by the sandbox at this level (Restricted).

I did not make this clear and you have my apologies for that omission.

Thanks again for your insights, it is very much appreciated.

Far from me to ever correct you, but I noticed that if I uncheck this setting it will actually result in more unneeded popup.

See below (your settings):

DhKpJFw.png



If I click to run at Auto Contention (default) it will run at Partial Limited settings, should it works at this way?
 
  • Like
Reactions: AtlBo and ZeroDay

upnorth

Level 68
Verified
Top Poster
Malware Hunter
Well-known
Jul 27, 2015
5,458
The domain owner updated that sites register about a month ago for one more year.
 
  • Like
Reactions: AtlBo

Nightwalker

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
May 26, 2014
1,339
Thanks again for your insights, it is very much appreciated.

Far from me to ever correct you, but I noticed that if I uncheck this setting it will actually result in more unneeded popup.

See below (your settings):

If I click to run at Auto Contention (default) it will run at Partial Limited settings, should it works at this way?

It seems to be a problem with Windows 10:

ht5VmXJ.png


DbeFfXc.png


From my understanding, it is specific to Windows 10 & Windows 8.1. {awaiting confirmation}

What's not intended : creating a rule and being ignored.
What's intended (by design, currently): applications that require UAC will get "Partially Limited" restriction, regardless of imposed restriction.

Login


I can confirm this behavior and it doesnt sound good to me.

@cruelsister I dont know if I am being paranoid, but it seems that Windows 10 with Comodo Firewall needs some special settings (block privilege elevation) ....
 
Last edited:
  • Like
Reactions: codswollip
D

Deleted member 178

I lost faith on Comodo long time ago after they can't manage to fix a simple bug, i gave it some tries since but this one just confirmed i was right to ditch it after all...
 
  • Like
Reactions: shmu26 and Faybert

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
A couple months ago, I installed CFW at default settings, i.e., HIPS is on and autocontainment is off.
The HIPS failed to block the execution of certain unrecognized files.
I reported it on the Comodo forum, and the bug was confirmed, but later on, the people who were supposed to fix it denied the issue. That's how it goes with Comodo.
Just for the record, this bug does not affect CS settings.
And just for the record, ignoring bugs is not limited to Comodo.
Nevertheless...
 

cruelsister

Level 43
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
Hi Guys- a couple of things:

1). Regarding the Spyshelter test- yeah it is odd that for this SPECIFIC file under Win10 it will be knocked back to PL. This is actually less of an issue (actually not an issue at all) than in times past. As I mentioned earlier and elsewhere the base protection of Containment has been upped. For example, formerly a ransomware file would have the ability to change the Desktop Wallpaper under the PL setting whereas currently it can't even do this.

Personally I find this issue trivial in the extreme, but what do I know?

2). Regarding the setting "Do Not Show Privilege Elevation Alerts"- this has to do with popups and not protection. I'm gonna try to put out a really quick video about it soon. The issue here for me is that in my video if I suppress popups there are those that really want them, and it I allow them there are those (like me) who wonder why they are allowed.

3). Finally again about Spyshelter- and this comment is only for total Virtualization Newbies- You may notice that when run in Comodo's Sandbox Spyshelter thinks that it succeeds when you run the System Protection tests. This is only because Spyshelter, running within Containment, can only "see" things within that environment. So although stuff changes in the virtual environment that can be flushed like garbage nothing is actually done to your actual system.
 
5

509322

2). Regarding the setting "Do Not Show Privilege Elevation Alerts"- this has to do with popups and not protection. I'm gonna try to put out a really quick video about it soon. The issue here for me is that in my video if I suppress popups there are those that really want them, and it I allow them there are those (like me) who wonder why they are allowed.

The guy thinking that setting has anything to do with UAC alerts proves one central point...

the 99% cannot handle security softs (nor Windows). Period. That includes COMODO and that includes AppGuard. It includes all security softs; the 99% cannot even handle something as simple as Windows Defender.

That so many people need guides and videos to configure and use 3rd-party Windows security software means a great number of things - and none of them are good. For one, and most importantly, nobody is teaching the 99% about Windows security. Beyond basic instruction on their product, it is not the responsibility of security software publishers to educate users to the level that they need. Besides, security soft publishers are not educators nor are they equipped to handle that role.

Windows security is far too complex and requires too much effort for the 99%. That is wholly Microsoft's doing and therefore wholly its fault.

Windows was released November 20, 1985. And 32 years later the general state of user-Windows security is more pathetic now than it has ever been.
 
Last edited by a moderator:
  • Like
Reactions: DavidLMO

Nightwalker

Level 24
Verified
Honorary Member
Top Poster
Content Creator
Well-known
May 26, 2014
1,339
Hi Guys- a couple of things:

1). Regarding the Spyshelter test- yeah it is odd that for this SPECIFIC file under Win10 it will be knocked back to PL. This is actually less of an issue (actually not an issue at all) than in times past. As I mentioned earlier and elsewhere the base protection of Containment has been upped. For example, formerly a ransomware file would have the ability to change the Desktop Wallpaper under the PL setting whereas currently it can't even do this.

Personally I find this issue trivial in the extreme, but what do I know?

2). Regarding the setting "Do Not Show Privilege Elevation Alerts"- this has to do with popups and not protection. I'm gonna try to put out a really quick video about it soon. The issue here for me is that in my video if I suppress popups there are those that really want them, and it I allow them there are those (like me) who wonder why they are allowed.

3). Finally again about Spyshelter- and this comment is only for total Virtualization Newbies- You may notice that when run in Comodo's Sandbox Spyshelter thinks that it succeeds when you run the System Protection tests. This is only because Spyshelter, running within Containment, can only "see" things within that environment. So although stuff changes in the virtual environment that can be flushed like garbage nothing is actually done to your actual system.

Hi cruelsister, thanks again for your insights.

Unfortunately I tried other files and the result is the same on Windows 10, thats why I searched in Comodo forum.

I realized this "bug" when I ran ShinoLocker and saw the restriction as PL.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top