- Apr 28, 2015
- 271
I have the same as you but instead of 'Block', I have 'Run inside the Container'.
Someone else will have to confirm which is 'correct'.
Someone else will have to confirm which is 'correct'.
Please provide comments and solutions that are helpful to the author of this topic.
I have all unrecognized applications set to run virtually/restricted.This is ok if you want to set CF like anti-exe.
What is your settings under Auto-Container?
I don't think there's a need since cruelsister's settings should be the easiest and thinking is slow and expensive. The lack of prompts should minimize that.I want to see more contribution and activity over this thread to help millions of users like me understand how to configure CFW properly and achieve maximum security on their system. A million thanks for our hero @Umbra for all of his great effort over MT I wish him a very good luck with his job and life
IMHO somewhere in-between CS settings and Umbra settings should hit the sweet spot for a lot of people.I don't think there's a need since cruelsister's settings should be the easiest and thinking is slow and expensive. The lack of prompts should minimize that.
Thank YouI want to see more contribution and activity over this thread to help millions of users like me understand how to configure CFW properly and achieve maximum security on their system. A million thanks for our hero @Umbra for all of his great effort over MT I wish him a very good luck with his job and life
@Umbra Did Comodo fix the disappearing rules issue? I only ask because I remember you saying you'd never use it until they did, I'm hoping they've either fixed it or given us a way to quickly get our rule back.
i couldn't wait to see if they fixed it, my job requires me to be updated about it so i can inform users using both EAM with CFW. But for the moment, it didn't appeared.@Umbra Did Comodo fix the disappearing rules issue? I only ask because I remember you saying you'd never use it until they did, I'm hoping they've either fixed it or given us a way to quickly get our rule back.
I think that refers to Microsoft Windows installer etc.Maybe this:
View attachment 171594
When you run HIPS in training mode, does it make allow rules for a whole set of actions for a given process?
And what about if you "unblock" a process from blocked applications? What does it actually allow?
Then I went and installed Sandboxie. I saw no alert prompt, except for firewall, and after installation, I saw Invincea in the TVL. What just happened?
It creates allow rules and when you switch to another mode it applies them.Not sure about training mode as I never used it. Unblocking from the Unblock Applications actually goes so far as to change the process file rating to trusted AND add an allow rule for each, Firewall and HIPS (except start a process which I think is set to ask) and then an ignore rule in containment. This is what I have seen, and you can test with any unrecognized portable app if you like.
If you could say what you have seen from training mode so far, maybe I could help some. Is it supposed to create rules but not enforce them...is that the idea?