Advice Request Comodo Internet Security Setup/configuration thread

Please provide comments and solutions that are helpful to the author of this topic.

Does this thread helped/informed you?


  • Total voters
    94
Status
Not open for further replies.
D

Deleted member 178

Thread author
They will not work together until some tweaks have to be made in CIS. Sbie wont run.
 
H

hjlbx

Thread author
Referring to the question whether sandboxie works well with Comodo Sandbox; I would also like to know. Currently all my browser is ssandboxed by Comodo everytime I want to open it. But if I install Sandboxie and configure it force sandbox on my browser, wouldn't that conflict? Wondered if it happens which sandbox goes in first? Just a thought, since I want to try sandboxie too possibly next yr.

If I use Sandboxie with Comodo, then I use Sandboxie to force browser.

I never tried to force browser in both Comodo and Sandboxie - which is not necessary. One or the other is sufficient.

Don't know. Can't answer your question at moment as I uninstalled SBIE.

Maybe @Umbra knows...
 

CMLew

Level 23
Verified
Well-known
Oct 30, 2015
1,251
If I use Sandboxie with Comodo, then I use Sandboxie to force browser.

I never tried to force browser in both Comodo and Sandboxie - which is not necessary. One or the other is sufficient.

Don't know. Can't answer your question at moment as I uninstalled SBIE.

Maybe @Umbra knows...

In Comodo, I didn't really force it. I set the rules such that whenever I open browser, it runs virtually. Does that equivalent to force browser?
 
H

hjlbx

Thread author
In Comodo, I didn't really force it. I set the rules such that whenever I open browser, it runs virtually. Does that equivalent to force browser?

Yes. Set rule to always run browser sandboxed = "forced".
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
@hjbx No i get it even though the app is trusted because it's trying to access a protected part of comodo.
I went back to check though and notice the default rules are gone which is stupid. From what is see it happens when cmdagent.exe crashes.
 
D

Deleted member 178

Thread author
@hjbx No i get it even though the app is trusted because it's trying to access a protected part of comodo.
I went back to check though and notice the default rules are gone which is stupid. From what is see it happens when cmdagent.exe crashes.

yep observed it too, sometimes after i reboot...
 
H

hjlbx

Thread author
@hjbx No i get it even though the app is trusted because it's trying to access a protected part of comodo.
I went back to check though and notice the default rules are gone which is stupid. From what is see it happens when cmdagent.exe crashes.

@SHvFl
@Umbra

From log what is Sandboxie trying to access ?

Maybe if create rule and allow access it will solve problem...
 
D

Deleted member 178

Thread author
Add sandboxie's whole folder as trusted in File List, after depending the browser , add its exe in Shellcode Injection exceptions.
 
H

hjlbx

Thread author
Add sandboxie's whole folder as trusted in File List, after depending the browser , add its exe in Shellcode Injection exceptions.

Does Comodo Defense+ log record exactly what the offending access is... ?
 
D

Deleted member 178

Thread author
since Sbie is whitelisted everywhere on my system, i dont have any, but maybe @SHvFl does.
 
H

hjlbx

Thread author
@SHvFl can you share log entry\(ies) or post image of log ?

With infos we can see exactly what is happening and perhaps figure a good workaround.

It is likely @Umbra's suggested config modifications will solve your problem, but it would be good to have log entries - this info will be useful to help others.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
I solved all my issues and my last message was not about sandboxie. I just forgot to quote you. It was a reply to you asking me "you get the above while sandboxed, using virtual desktop or unsandboxed (standard) use ?"
By adding ipoint in ingore list of comodo protected files. (It was trying to access cis.exe memory)
About my lost rules i recreated them and this time i added a backup not like a retard i was before.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
We're both Comodo geniuses... :D
So apparently i have this bug/issue which forced me to disable hips for now. I can't import the settings with each restart.
Problem with HIPS rules. - Defense+ / Sandbox Help - CIS

Might have fixed it. Time will show.

@hjlbx @Umbra Any of you guys running firefox in sandbox because for me the flash plugin keeps crashing until it freezes the browser. Any ideas? Btw thanks for your helps guys. It's been years since i used comodo and i am out of the loop but i am getting back.
 
Last edited:

CMLew

Level 23
Verified
Well-known
Oct 30, 2015
1,251
Just read some introduction to firewall rules from youtube.
So I compare it with CIS firewall settings.
1) Does the Global Rules are fired in order from top to bottom?
2) I noticed both @hjlbx and @Umbra didn't touch any settings on that. So I supposed it is good to run as default?
3) Does the firewall have default policy like DENY or ALLOW? Din see that setting.
 

SHvFl

Level 35
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Nov 19, 2014
2,350
@CMLew
1)Yes
2)Depends what you are trying to achieve. For example you can use global rules to create a vpn kill switch
3)When you launch an application and it's not safe(assuming you have it to create rules for safe applications) it will give you a popup asking to allow/block, etc. If you want to default allow or block go in firewall settings.
NjC3zof.png
 
  • Like
Reactions: Deleted member 178
H

hjlbx

Thread author
Just read some introduction to firewall rules from youtube.
So I compare it with CIS firewall settings.
1) Does the Global Rules are fired in order from top to bottom?
2) I noticed both @hjlbx and @Umbra didn't touch any settings on that. So I supposed it is good to run as default?
3) Does the firewall have default policy like DENY or ALLOW? Din see that setting.

I use Outgoing Only rule for applications.

You can create global firewall rules to Block - for example a specific port, protocol, etc - if you feel the need.

You can create application rules to allow, block - e.g. specific IP addresses - if you wish.

Customization of firewall rules in Comodo is built-in - I just use the generic Outgoing Only rule.

Yes. Rules are fired top of list to bottom. Newly created rules are inserted at the top of the list - same for both HIPS, Sandbox and Firewall rules.
 

darko999

Level 17
Verified
Well-known
Oct 2, 2014
825
I have a little question I'd like to share heh

If I have disabled "Create rules for safe applications" on HIPS settings.
I have of course, re-built the "Trusted Software Vendors list"

From Comodo web:


HIPS trusts the applications if:
  • The application/file is rated as 'Trusted' in the File List
  • The application is included in the extensive and constantly updated Comodo safelist
What is the Comodo safelist, the HIPS could trust an application that is not in the trusted file list, neither in the trusted software vendors list, but actually in the comodo safelist? I know this may have been answered a lot of times already, or comodo needs the 3 rules above to be present in order to trust the application, also how is the performance impact for day to day usage? Has anyone noticed any performance issues that may equals to keep this setting disabled? Thank you all in advnace! NIce thread btw.
 
D

Deleted member 178

Thread author
What is the Comodo safelist, the HIPS could trust an application that is not in the trusted file list, neither in the trusted software vendors list, but actually in the comodo safelist?

i guess if the soft is in the safelist , it is already in TVL & trusted list.

also how is the performance impact for day to day usage? Has anyone noticed any performance issues that may equals to keep this setting disabled? Thank you all in advnace! NIce thread btw.

on or off , same perfs. idon't see any noticeable differences.
 
  • Like
Reactions: darko999
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top