If Comodo could 100% solve this problem, everyone else would too and then there won’t be malware, anti-malware, there wouldn’t even be MalwareTips.And yes, unfortunately, Comodo is clearly not infallible (no AV is anyway).
Thank you for the test. Please don't take it the wrong way, but "popular practice" is not a test of Comodo, especially for a bypass test. The vendor's configuration should be tested for such tests, in which case proactive comes with HIPS enabled. But the test was informative and showed, as you mentioned, that there can be some cons to the popular practice.I disabled HIPS not to make the attack easier, but because it is a pretty popular practice when the Auto-Containment is set to Untrusted. As we can see, there can be some cons of that.
Please don't take it the wrong way, but "popular practice" is not a test of Comodo, especially for a bypass test.
Thanks. All about layers I guess. Thankful that i have CyberLock to help bolster whatever security setup I'm using.Not many, but you do not know which should be blocked. Furthermore, some external LOLBins can do the same.
Same here. I am from the old school and still like to have it around.I always use HIPS module enabled.
This test is not fair because he disabled everything in Xcitium as ozer metins says if he wouldnt disable everything in Xcitium Xcitium would have protected the system with Auto-Containment and HIPS and the attack would be prevented
It's true that Comodo is efficient, but it's not as perfect as its competitors.
The one problem with enabling the HIPS and blocking by default every conceivable LOLBin imaginable, then having to create individual rules to allow trusted programs to use the required LOLBins, is that it is time-consuming, tedious work and the end user will have to have rather intimate knowledge of what they're doing, otherwise they will either allow something too permissively, cripple their system by being too restrictive, or a combination of both. I'm pretty sure sure this is one reason why Cruelsister does not enable HIPS in her Comodo setup.
Won't containment set to block prevent the attack from executing?
There is also the bug (does it still exist in the latest release??) where all the HIPS rules disappear without warning.
Won't containment set to block prevent the attack from executing?
They will be very sad watching these videos. All 5 of them.because only few fanatics use Comodo's products.
They will be very sad watching these videos. All 5 of them.