Andy Ful
From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Forum Veteran
Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
I understand what youre saying but i can not agree. For this lack of interest in solving this exploitation now cis has a "friend". cis trust an ransomware so it can run and do whatever he wants. the video is online. ill bring a topic about it.DecimaTech explained the Comodo/UAC flaw, which is well-known to Comodo staff. If you think other AV vendors are eager to patch all known flaws, you will be disappointed.
Furthermore, despite this incompatibility, you can hardly find a stronger solution than @cruelsister settings + safe mode HIPS + some hardening via Script Analysis (of course there can be some with similar strength).
Comodo has some important advantages for non-enterprise users:
If you will see malware attacking your personal computer, it will not be the sandbox bypass, except when you are a celebrity, dissident, or VIP. If something might pass by your Comodo protection, it would be via DLL hijacking or a similar fileless (non-EXE) technique. Even then, you will have a fair chance to stop the attack flow because many attacks starting from fileless vectors, still use standard methods at the later infection stages. So in the end, the final payload can be contained anyway.
- It is rarely a target of criminals.
- It uses auto-containment and most solutions do not.
As an example, one could take the @Loyisa exploit. From points 1-2 it follows, that you hardly can see such an exploit on your computer, but rather a modified version when the auto-containment bypass via creating service is replaced by a UAC bypass unrelated to sandbox escape. Such a UAC bypass can be mainly contained with no escape. In the case when the file with UAC bypass is not contained and tries to run an EXE payload, the payload can be auto-contained into a full-strength sandbox (payload will start with Administrator privileges before containment = no sandbox escape).
Of course, there is still some possibility that malware can compromise your protection (via purely non-EXE attack or by using some unrestricted LOLBin), but such malware is very rare and other solutions can hardly do better. Anyway, there is nothing wrong with trying.
I am afraid that after moving on, most people will replace strong protection + known but rarely exploited feature, with not-so-strong protection + unknown by the user (but known by attackers) more frequently exploited features.
and here i have to disagree with you.Hi @Andy Ful , please, once again, and with all due respect, allow me to disagree with your last post.
Comodo is an abandon-ware, it has not had any real update/upgrade for years, it is full of dangerous unfixed bugs, most of its features are garbage, and several times "Containment" already has been proven by-passable. Therefore, in this context, as a matter of principle, no software in this condition should be used. Period!
The problem is the IMMORALITY and IRRESPONSIBILITY, both, of Comodo (which continues to promote its software as "the most complete solution for cyber security"), as well as of its fanatics, who lie, omit and manipulate information, creating a false myth that has lasted for years.
In addition, Comodo is not able to detect viruses/malware, so at best it can only be classified as a “blocker”. However, with the lack of updates + no bug fixes, nowadays not even the blocker function is reliable! Also, it's worth mentioning the fact that 99% of users are NOT suitable to use blockers as security systems. And if it is a matter of “blocking” stuff, then it would be enough to harden Windows. Finally, there is also no logical reason to use a blocker, when there are countless excellent free alternatives on the market, real antivirus/antimalware, modern and well maintained.
In this pathetic context, continuing to promote Comodo, besides being immoral and irresponsible, is like promoting the unplugging of a computer from the internet or electricity, as the most “infallible complete cyber security system”... RIDICULOUS! Every time a problem is reported with Comodo, what is always proposed is a patch/hack where more and more stuff is blocked. And considering that the current blocker function (Containment) already triggers hundreds of false blockings (safe files blocked), the only thing they will achieve by hardening/patching/hacking Comodo more and more is that its security will be analogous to unplugging a computer from the internet/electricity (Comodo will totally kill user usability). Comodo has been dangerous for years, and now they are turning it into a totally unusable software.
As I mentioned, 99.99% of users are not prepared to use any kind of blocker as security software. And by hardening/patching/hacking Comodo (instead of fixing or improving Comodo), the only thing they will achieve is that 99.999999% of users will NOT be able to use Comodo.
And the fact that Comodo is useful for 0.000001% of users does not justify the immorality and irresponsibility of Comodo fanatics, who continue to promote Comodo as an alternative for everyone.
? no feelings about him or anything else. just comenting things that are happening these daysYou're either gonna fall in love with Melih or fall in love with the fact that you can't beat him."D" knows what I'm talking about!
![]()
here i see some sarcasm, or some kind of "i have the truth in me and everyone else is wrong and if someone disagree can go out my beloved topic",OK. The off-topic discussion about the general Comodo recommendations and opinions is now closed.
I commented on @vitao's post because of my video. Anyone can post comments about Comodo and "moving on ..." to the threads he has opened if necessary.![]()
here i see some sarcasm, or some kind of "i have the truth in me and everyone else is wrong and if someone disagree can go out my beloved topic",
sorry, it seemed a little sick but its not the goal nor the point. i dont know how to express this kind of "idea" in other languages than mine so if this feels strange, please ignore, or try to understand without rocks on hand...![]()
that was not my point but i understand and i agree with you. and sorry if i did bring any kind of offtopic for this topic and if i, in some way, contributed to it. not my intention. lets focus on the first post of yours here.No sarcasm. I closed the interesting (but off-topic) discussion in this thread, but someone can have another opinion and may want to share it with you.
Guys please, talk about general Comodo problems in another thread.
If you want I can ask the MT staff to move the interesting (but off-topic here) posts to one of your threads, where they can be non-off-topic.
Any posts about killing Comodo, Comodo bypasses, escaping from the sandbox, UAC incompatibilities, etc. are welcome here.![]()
that was not my point but i understand and i agree with you. and sorry if i did bring any kind of offtopic for this topic ....
The official love song of COMODO... Come On, Melih, Open Door, Oh!in fact, maybe he will fall in love with me it that thing continues...
https://malwaretips.com/threads/comodos-killer.133558/post-1107412The official love song of COMODO... Come On, Melih, Open Door, Oh!![]()
You seem unable to understand that "readers who not NOT use Comodo" do not care.It is about the readers who do NOT use Comodo
https://malwaretips.com/threads/comodos-killer.133558/post-1107412You seem unable to understand that "readers who not NOT use Comodo" do not care.
Nobody that uses or "promotes" Comodo at MT is harming anyone.
If you use Comodo in non-enterprise environment, you can still use it. Please note:Hello,
thanks Andy for this video on comodo. as i already reported in another post, there have already been "issues" on comodo, with Shaolan who also reported a bug and obviously he was banned, in short... to this day we have no means of protection against this kind (poc? if i'm not mistaken) and for the challenge of comodo and other editors elsewhere, what would you recommend as protection software? i admit that i like comodo for its lightness (the full installation consumes very little ram compared to competitors) and its ease of use (compared to old versions of comodo i mean). Because in firewalls, apart from zonealarm and wfc, there is not much accessible to the general public apart from paid software. Huorong, which seems to be the closest to Comodo in terms of features is not very conclusive in light of the tests. What do you think? THANKS.
Nice .
Did you tested it on HIPS + Paranoid
And clear the default HIPS configuration .
can you provide me this file?i would like to do some testings and some videos
Members who viewed this thread in the last 5 minutes