SearchLight Basic Security Config - Am I OK?

Status
Not open for further replies.

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,822
Last edited:

SearchLight

Level 13
Thread author
Verified
Top Poster
Well-known
Jul 3, 2017
626
v10 of CFW has a flaw in my opinion in that when CFW blocks a file according to CS settings, the only way to remove a file that may be legit or erroneously blocked from the BLOCKED LIST is to click on the unblock button. By doing so, if that file should reappear again, v10 would not touch it again because you unblocked it.

In v8, the file is put into QUARANTINE, and the program provides options of what you want to do with it. I will attach a screenshot of what I am talking about in v8.

Btw, this featureset is listed on the Comodo Forum as a wish list item for the next v10
 

Attachments

  • 2017-07-19 15_08_31-COMODO Quarantine.png
    2017-07-19 15_08_31-COMODO Quarantine.png
    14.5 KB · Views: 390

Maxwell Sien

Level 2
Verified
Nov 15, 2016
97
Suggestions:
Any particular reason you're using Comodo Firewall v8 instead of v10?

The rest of your config's solid.
Thanks for sharing. :)
But Comodo already have HIPS, why should he Activate UAC again? He would get Double alert i think.
 
  • Like
Reactions: Sunshine-boy

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,822
Sorry, i missed that..
UAC isn't particularly useful with CS configuration either but malware requesting privilege escalation on execution will trigger a UAC prompt (assuming it doesn't bypass) before Comodo sandboxes it which can be a helpful alert to the user.
 

SearchLight

Level 13
Thread author
Verified
Top Poster
Well-known
Jul 3, 2017
626
Changed my mind. Swapped out NPE for ZAM as my on-demand.

Btw, I am waiting for the Comodo Forum people to tell me if the features that I like and have been working with in v8, have been split into separate functions Block and Quarantine on v10. I like the simplicity of dealing with just the Quarantine in v8, and not have to worry about unblocking a program premanently by accident and then it returns without a notification or action.

In other words, something so simple, seems to have been made more complicated. I think the word often used is the software has become more bloated with added features which may, or may not be useful. All this is my own opinion.
 

Maxwell Sien

Level 2
Verified
Nov 15, 2016
97
UAC isn't particularly useful with CS configuration either but malware requesting privilege escalation on execution will trigger a UAC prompt (assuming it doesn't bypass) before Comodo sandboxes it which can be a helpful alert to the user.

But Sandbox Alert come first and then UAC and then Comodo SandBox it.
 
  • Like
Reactions: Sunshine-boy

Arequire

Level 29
Verified
Top Poster
Content Creator
Feb 10, 2017
1,822
But Sandbox Alert come first and then UAC and then Comodo SandBox it.
Sure you aren't seeing a firewall alert first? If the file is unknown CF will block inbound/outbound network access for said application if you're using CS settings.
 

Exterminator

Level 85
Verified
Top Poster
Well-known
Oct 23, 2012
12,527
As others have said you do not need Malwarebytes Anti-Ransom.
Consider adding an on demand scanner(s).
You have a secure Windows 10 config! Thanks for sharing it with us :)
 
  • Like
Reactions: JM Safe

SearchLight

Level 13
Thread author
Verified
Top Poster
Well-known
Jul 3, 2017
626
Well everyone, I decided to revert back to v10 of CFW because a previous poster stated that I do not need MBRW Beta protection as this version of CFW protects from Ransomware. That being said, I realized my confusion came from not understanding that the "Unblocking List" tells you what feature of CFW has blocked the possible malware which in this case would be Containment, and whether you do not want it blocked again. Using CS settings, no harm in experimenting to get back on the right path. At least I know, v8 could always be used as a backup, if needed.

So now my arsenal is WD+CFWv10+AdGuardPremium+ ZAM On-Demand Scanner. Thanks all for all your tips.

I think I am now ok:). Agree?
 
Last edited:
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top