查看: 2119|回复: 8
收起左侧

[讨论] COMODO好象不校验文件的MD5?

[复制链接]
dyzg
发表于 2007-11-27 20:34:31 | 显示全部楼层 |阅读模式
我用其他文件改成允许的文件名,可以运行,那COMODO只认文件名和路径吗?这样怕是谈不上安全
GBUser
发表于 2007-11-27 21:31:50 | 显示全部楼层
有Defense+呢
EQ默认也是不进行校验的
不过觉得还是有校验比较好,多一层保护
ubuntu
发表于 2007-11-27 21:57:06 | 显示全部楼层
开发人员的思路是 FD 配合 My Pending Files 完全不用MD5;
如果对文件操作敏感,可以多注意 My Pending Files 的文件变化。

The Defense+ must have shown you the alerts before replacing the files. Once approved by the user or by the "Computer Security Policy" CFP will not ask about the already approved change again. These are cooperating systems. Even if Defense+ is deactivated, you will receive a file modification alert if an unknown program modifies an application *which has a firewall rule*.

However, if you say "I have replaced/renamed those files without any alerts from Defense+", this can be because :

"You may have a rule in Computer Security Policy which allows explorer.exe(assuming you used Windows Explorer to rename those files) to modify protected files" or you disabled file system protection completely.

All these hash keeping practices are to prevent malware hijacking the allowed applications. You need to keep hashes if you dont know what is going on in the file system. CFP 3 knows all these.

There is a leaktest in www.grc.com. LeakTest 1.2.exe. You can rename that application as firefox.exe and test.

So you have a guaranteed defense against malware tampering. Why would you need hashing?

Besides, CFP 3 allows you to use wildcard characters while defining the applications. In this case, hashing is just useless. You cant keep hashes for such a set of applications. Thats why, IMHO,  other firewalls do not have such a feature as wildcard based rules.


Hope this helps,
Egemen
30794
发表于 2007-11-28 05:01:06 | 显示全部楼层
V3开发者的意思是即使关闭Defense+,被监控的文件改动还是会有警告,另外如果采用hash校验,就不方便设置有通配符的规则

V3的FD是靠patent pending来维系的,这个patent pending实际上就是cmdagent.exe
V3现在还有一些bug,是有空子可钻的,比如一些软件运行会导致cfp.exe出错自动退出,cfp.exe退出后,一些暴力工具运行就不会有警告,如冰刀,再用冰刀结果了cmdagent.exe,V3的保护就被终止了,当然patent pending也就没有了

至于规则通配符的问题也好办,有些HIPS也支持通配符,也有hash校验,可以这样设置,无通配符的规则采用hash校验,有通配符的规则不用,无通配符的规则优先于有通配符的规则
Oceanzd
发表于 2007-11-28 07:07:16 | 显示全部楼层

回复 4楼 ubuntu 的帖子

貌似Comodo的FD还没有区分删除和修改
zerosu6652
发表于 2007-11-28 07:10:29 | 显示全部楼层
反病毒会校验
夏春秋
发表于 2007-11-28 07:34:05 | 显示全部楼层
这是comodo简化用户操作的一种尝试,V2就有MD5校验,是否合适当然见仁见智
sxingbai
发表于 2007-11-28 08:38:43 | 显示全部楼层

回复 6楼 Oceanzd 的帖子

也注意到了
删除时也提示是修改
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-4-30 20:06 , Processed in 0.139215 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表