But when malicious activity takes place, doesn't Comodo hips alert of that suspicious/malicious activity?
But when malicious activity takes place, doesn't Comodo hips alert of that suspicious/malicious activity?
hello my love!Still, you don't need to escape the containment, DLL hijacking Is All You Need.
View attachment 299022
But as far as I understand, sandboxing won't help against data theft?
Still, you don't need to escape the containment, DLL hijacking Is All You Need.
Comodo cannot contain DLLs loaded by Trusted processes. Only Xcitium has an option to do it.So in this case the DLL was not auto contained?
and even excluding the whole folder in WHHL did not stop WDAC from blocking Vulkan.dll of Yandex browser according to events log.Comodo cannot contain DLLs loaded by Trusted processes. Only Xcitium has an option to do it.
As for a home product, allowing such DLLs is understandable because it would trigger many false positives.
Smart App Control can do it, and we know how many false positives can happen. Many signed applications use unsigned DLLs.
Hi, Like the previous version, everything that goes through the sandbox doesn't connect, which limits its usefulness because we can no longer launch our browsers in a Comodo sandbox (so we go back to the Windows sandbox). It's a shame about that, but otherwise it's good. Now we'll have to see how it holds up over time.
Workaround found by any more experienced person. In the HIPS Settings (even if you have disabled) you need to remove "Windows Sockets Interface" from Protected Files. You'll then be able to allow internet connection with sandboxed browsers. I don't run browsers sandboxed myself so leaving it there at my end.
![]()
Although Comodo's help(http://help.comodo.com/topic-72-1-766-9163-HIPS-Settings.html) states:But when malicious activity takes place, doesn't Comodo hips alert of that suspicious/malicious activity?
However, HIPS in Safe Mode will allow all activities of trusted processes(even it loaded malicious DLL)
- Safe Mode: While monitoring critical system activity, HIPS automatically learns the activity of executables and applications certified as 'Safe' by Comodo. It also automatically creates 'Allow' rules for these activities, if the checkbox 'Create rules for safe applications' is selected. For non-certified, unknown, applications, you will receive an alert whenever that application attempts to run. Should you choose, you can add that new application to the HIPS rules list by choosing 'Treat as' and selecting 'Allowed Application' at the alert with 'Remember my answer' checked. This instructs the HIPS not to generate an alert the next time it runs. If your machine is not new or known to be free of malware and other threats then 'Safe Mode' is recommended setting for most users - combining the highest levels of security with an easy-to-manage number of HIPS alerts.
Agreed but the only immediate workaround I could find though I think you can refine the rule or create a specific hips/edr rule for a browser but as I don't want anything in sandbox to connect out, I leave it as is. Not done any testing with the new version on this front.It is worth mentioning that this solution allows contained malware to use network services.