・Firewall Behavior Settings Safe ModeかCustom Policy Mode、HighかVery Highにする This computer is an internet connection gateway (i.e. an ICS server)はインターネット接続共有してなければ外してもOK
・Attack Detection Settings Protect the ARP CacheとBlock gratuitous ARP framesは任意でチェック(ネットワーク管理者ならチェック推奨) Do Protocol Analysisも任意でチェック
・Stealth Ports Wizard 基本的にDefault(Alert me to incoming connections - stealth my ports on a per-case basis)でOK 任意でDefine a new trusted network - Stealth my ports to EVERYONE elseでNICを選択しルールを作る
複数のアドレスやポートでルールを作りたい時はMy Network ZonesとMy Port Setsでまとめる Predefined Firewall PoliciesのDefaultルールなどを活用して自分なりのルールを作ろう!
>>43 Whats new in 3.5.61373.458 BETA? --------------------------------------------------
NEW! Threatcast integration: COMODOs community based alerts reply statistics reintroduced NEW! Native Vista Firewall: New COMODO Network Stack based firewall engine using new vista technologies(dramatic performance improvements) NEW! Native Vista HIPS: New Vista HIPS compatible with Vista PatchGuard. Now Defense+ introduces kernel level protection in Vista SP1 X64 or later NEW! COMODO Memory Firewall integration: CIS now includes builtin system wide buffer overflow protection NEW! AV Heuristics: The AV engine now includes heuristics scanning capable of detecting unknown viruses generically IMPROVED! Trusted software vendor list is expanded, capable of detecting thousands of applications generically without any signatures IMPROVED! Revised AV engine: AV engine scanning and updating speed increased significantly
Known Issues: ----------------------- * First boot after the installation might sometimes take longer than expected: This issue is being investigated * The virus database in this version is a test database and is therefore different from the virus DB of the released version. This means detection rates are different
Comodo CA Limited ComodoCP,Inc Microsoft Corporation Microsoft Windows Microsoft Windows Publisher Microsoft Windows Component Publisher Sun Microsystems,Inc, Apple Inc, Google Inc Mozilla Corporation Adobe Systems,Incorporated PGP Corporation Skype Technologies SA Opera Software ASA
つまりFWにバイナリチェックという付加機能が付いていてもおかしくないといってる訳だ もしFWに付加機能が付いてるのが悪いというならView Active Connectionsなんて付加機能があるcomodoがおかしいってことになる >>229の理屈でいえばルールで許可したアプリが通信するのは正常だから表示する必要なんてないってことでcomodoはおかしい
What's new in COMODO Internet Security 3.8.61948.459 Beta: ・ Fixed - System reboot takes too much time when CIS is installed ・ Fixed - AV Heuristics produces false reports for certain files ・ Fixed - Diagnostics utility produces wrong reports ・ Fixed - Password protection does not work properly
一応COMODOのクリーンアンインストール手順書いておく スタートアッププログラムからUninstall or Upgradeで削除、再起動 Program FilesのCOMODOフォルダ削除 C:\Documents and Settings\<username>\Application Data\のCOMODOフォルダが残ってれば削除 C:\Documents and Settings\<username>\Local Settings\Application Data\のCOMODOフォルダが残ってれば削除
C:\Documents and Settings\All Users\Application Data\のCOMODOフォルダが残ってれば削除 C:\WINDOWS\Prefetch\のCIS、CFP、COMODOを検索して削除 CCleanerで削除、再起動 新しくインストール
Defense+をParanoid Modeで Block all unknown requests if the application is closed を 有効にして使っているんだけど、Block all.... を有効にした状態で boot すると、読み込めないDLLが 出てくるんだ ノートPCなので省電力管理関係なんかがOSのBoot時に読み込まれるんだけど、 Blockされてしまうので、この弾かれるものだけ許可させたいんだけどどうすればいいのか、誰か知らない?
>>541 DEFENCE+ Advanced Computer Security Policy %windir%\system32\rundll32.exe Use a Custom Policy - Access Rights Run an executable - Ask - Modify... Allowed Applications
What's New in this version? NEW! COMODO Threatcast - COMODO's community based alerts statistics NEW! Native Vista Firewall - Improved Firewall with Windows Vista enhancements NEW! Native Vista HIPS - Improved HIPS compatible with Windows Vista enhancements NEW! Buffer Overflow Prevention - Defense+ can now detect and prevent one of the most common attacks used by attackers: shellcode injection NEW! Antivirus Heuristics: The Antivirus engine now includes heuristics scanning capabilities NEW! Proxy server settings for AV and program updates IMPROVED! Trusted software vendor list is expanded, capable of detecting thousands of applications generically without any signatures IMPROVED! Revised AV engine - AV engine scanning and updating speed increased significantly IMPROVED! File submission engine has been redesigned
AddでShare用ルール追加 (ルール1) Action = Allow Protocol = TCP Direction = In Description = Rule for incoming TCP connections Source Address = Any Destination Address = Any Source port = A port range = (start port = 1025 / end port = 65535) Destination port = 開放ポート番号 (ルール2) Action = Allow Protocol = TCP Direction = Out Description = Rule for outgoing TCP connections Source Address = Any Destination Address = Any Source port = A port range = (start port = 1025 / end port = 65535) Destination port = A port range = (start port = 1025 / end port = 65535) (ルール3) Action = Block "Log as a firewall event if this rule is fired"にチェック Protocol = IP Direction = In/OUT Description = Block and Log All Unmatching Requests Source Address = Any Destination Address = Any IP Details = Any
FIREWALL-Advanced-Network Security Policy-Application Rules Addでルール追加 Use a Predefined Policyを選択してPredefined Firewall Policiesで設定したルールを読み込み