dll validation too
one aspect I like is that when a DLL is loaded with network access, the firewall
can bless or deny access to the net at this level. This means you get a chance
to see what svchost (and other *.exe programs) is loading for fine-grain
control. You can set an option to LEARN the components and then after a couple
of days, revert to monitor components=ON
(so clearly, I like 4.the Application behaviour monitoring)
the logging is interesting, in that it reports the parent of the application,
the application itself, and the activity that was attempted. the classification of
Severe, High, Low risk is arbitrary, so don't get too alarmed at these.
the firewall comes PRE-CONFIGURED with not only reasonable defaults, but
it also is prepared to support a VPN connection;
allow IP/GRE {in,out}bound
the access to port 53 (ie: dns) is caught and if the app/dll is not totally mapped
by the firewall, it is rated Severe (or was it High) Risk. Heck, all URL translations
need port 53 so plan on setting it as ALLOW.
the other day, a web application had a link for email us and upon clicking,
my email program (Thunderbird) was launched; Comodo caught the action
and clearly showed the attempted SILENT invocation of Thunderbird.
Yea sure it had a window and I knew what/when and why, but if some
vile bugger was launched w/o a window I would have not known it unless
Comodo was there to show me
{4. Application behaviour monitoring in effect }