• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Comodo Firewall vs ESET Smart Security

vitalym

Limp Gawd
Joined
Sep 12, 2008
Messages
295
ESET SS is also a firewall correct?

Which combination is the most effective one, Comodo + ESET antivirus or ESET AV + SS?

I want to be given an option evertime something wants to connect to the Internet and the option to deny or allow it, I know Comodo does this, does ESET Smart Security do it?
 
On what OS?
On Vista and XP both, the default firewall is just fine.

While I swear by NOD32, ESS is just a waste of money IMO.
 
On what OS?
On Vista and XP both, the default firewall is just fine.

While I swear by NOD32, ESS is just a waste of money IMO.

Yes, I use XP.

Well you can't go wrong with Comodo as it's free.

Guess I'll use NOD32 + Comodo.
 
Yes, I use XP.

Well you can't go wrong with Comodo as it's free.

Guess I'll use NOD32 + Comodo.

XP's firewall is builtin, gets automatic patches (if you have turned on) and requires no extra downloads or programs...
 
Does it prompt you for every program that wants to access the Internet or install?

You can set it to block everything, yes.

If you're talking about outbound filtering, that's a bigger PITA than it's worth.
 
Outbound filtering = essential.
Comodo is great, stick with it :)
 
Outbound filtering = essential.

How so?

The theory is broken because if you've got something on the inside of your network anyway, you're screwed no matter what you do.

There are so freaking many programs that access many outbound ports it is not funny. You're absolutely going to guarantee me that every single thing that wants outbound access you'll go and find the process and exactly what it's doing? Going by the little "Friendly Game wants to access the Internet" is flawed. That can be easily spoofed.


If you've got a business network the story changes just a bit, but in ANY network I'd much rather see measures taken to prevent it hitting the network EVER rather than admitting defeat and trying to stop it once it's already infected the machines inside the network.
 
There are so freaking many programs that access many outbound ports it is not funny. You're absolutely going to guarantee me that every single thing that wants outbound access you'll go and find the process and exactly what it's doing? Going by the little "Friendly Game wants to access the Internet" is flawed. That can be easily spoofed.

Yup...99.9% of end users simply see "explorer.exe is trying to access the internet..what do you want to do?" Or..."SVCHost.exe is trying to access the internet..what do you want to do?"

..and they click "Yes" just to shutup the dang annoying firewall.
 
How so?

The theory is broken because if you've got something on the inside of your network anyway, you're screwed no matter what you do.


That is an extremely negligent attitude and is very wrong.
I do what I can to keep my clients data in their own network.
With no outbound protection, much more can escape the network and other machines can be infected easier once a machine is compromised.
 
That is an extremely negligent attitude and is very wrong.
I do what I can to keep my clients data in their own network.
With no outbound protection, much more can escape the network and other machines can be infected easier once a machine is compromised.

Your primary job is to protect your clients, not everyone else running their machines wide open on the internet.

Outbound filtering won't stop malware from propagating through your network, unless you have it on each and every PC.
It's an Administrative nightmare. For it to be worth half a darn you'd have to lock it down to where they cannot allow stuff through. And then any new software they install you'd have to verify what it is, and then allow it through all the firewalls.

Like I said, it's a huge PITA and isn't worth it in the vast majority of situations. Focus your energy on stopping it from getting to your network in the first place.
 
Yup...99.9% of end users simply see "explorer.exe is trying to access the internet..what do you want to do?" Or..."SVCHost.exe is trying to access the internet..what do you want to do?"

..and they click "Yes" just to shutup the dang annoying firewall.

And these are two really good examples.

Like I said, if the malware is on your machine in the first place, you're screwed. It can take numerous shapes and forms, not all malware will blatantly identify itself as "malware.exe".
 
Your primary job is to protect your clients, not everyone else running their machines wide open on the internet.

Outbound filtering won't stop malware from propagating through your network, unless you have it on each and every PC.
It's an Administrative nightmare. For it to be worth half a darn you'd have to lock it down to where they cannot allow stuff through. And then any new software they install you'd have to verify what it is, and then allow it through all the firewalls.

Like I said, it's a huge PITA and isn't worth it in the vast majority of situations. Focus your energy on stopping it from getting to your network in the first place.

Exactly, each machine should have a firewall with outbound filtering.
Maybe its a PITA for you, I dont have that problem.

And lol, what makes you think that other parts of my network security arent up to scratch?
It seems you are the one not implementing very useful techniques of keeping machines safe!
 
As a gamer I always have issues with ESET's firewall blocking network games at LAN parties. I disable it and games cannot connect, I then uninstall it and then there is no problem. But keep in mind I have not had a LAN in 6 months, this could have been resolved...
 
Comodo is great and just works. I use comodo + avast! at home.

As to the argument about outbound filtering, I can see both sides of the argument. Personally I see it as essential. If something on my computer is trying to "phone home" I like having the ability to see that and make a decision on it. If it is something that is being "spoofed" then yeah, maybe I'm beat, but that seems unlikely. It seems especially unlike that something will be spoofed at the exact moment that I expect outbound traffic.

On the other hand, I installed Comodo for my mom, and she is definitely just a "click yes to make it go away" type. I gave the fairly simple instruction of click deny unless you just ran something and expect the traffic, but she doesnt get it. ZoneAlarm put some sort of "adaptive firewalling" in place awhile back and it was my understanding that the goal was anomaly based firewalling, which may be a good middle ground, but I havent used it enough to really comment on it.

At work, we definitely use outbound ACLs. I think anything less with be pretty negligent.
 
If it is something that is being "spoofed" then yeah, maybe I'm beat, but that seems unlikely.
The well written stuff that everyone should be more concerned about disguises itself so well you won't know it's there.
It WILL spoof itself and make it appear like a valid system process.



It seems especially unlike that something will be spoofed at the exact moment that I expect outbound traffic.
This is also flawed. Some malware circumvents this by simply mirroring what the computer does. If it's idle, it stays idle. As soon as you begin surfing the net or anything else with outbound activity, it'll start transmitting just for that reason of making people think that it is THEIR activity doing it.
This is why I mentioned previously, will you guarantee me that every single little process that wants to get out the door is throughly researched? My guess is no.
 
The well written stuff that everyone should be more concerned about disguises itself so well you won't know it's there.
It WILL spoof itself and make it appear like a valid system process.

This is also flawed. Some malware circumvents this by simply mirroring what the computer does. If it's idle, it stays idle. As soon as you begin surfing the net or anything else with outbound activity, it'll start transmitting just for that reason of making people think that it is THEIR activity doing it.
This is why I mentioned previously, will you guarantee me that every single little process that wants to get out the door is throughly researched? My guess is no.

That's all interesting. I'd really like to see it in action. However, I just don't see it working. If something suddenly starts trying to go out, even if it is a known process, it is at least going to raise a red flag in my mind. Then, I will research the destination address and figure out what is going on.

On your second point, again, I just don't see it working. You say it will wait until I'm surfing and then transmit. Is that to say it will spoof itself as firefox.exe (or the process ID firefox is using) and go out over port 80? If it can do that, it will be permitted anyways and I'll never get an alert as outbound 80 is permitted from firefox.

Maybe I am ignorant to the workings of malware and am underestimating the it's capabilities, but I just don't see this working.
 
If you seem to have a method that "works" please feel free to enlighten us all on how you do it without any problems.;)

Please tell me what presents such a big issue, I just dont see it.
If you allow all your users to install new software on their PC's that may be where your problems start.
For those few that are allowed to install software, any issues are easily cleared up with a phone call.
 
That's all interesting. I'd really like to see it in action. However, I just don't see it working. If something suddenly starts trying to go out, even if it is a known process, it is at least going to raise a red flag in my mind. Then, I will research the destination address and figure out what is going on.

On your second point, again, I just don't see it working. You say it will wait until I'm surfing and then transmit. Is that to say it will spoof itself as firefox.exe (or the process ID firefox is using) and go out over port 80? If it can do that, it will be permitted anyways and I'll never get an alert as outbound 80 is permitted from firefox.

Maybe I am ignorant to the workings of malware and am underestimating the it's capabilities, but I just don't see this working.

It all comes does to who is in charge of controlling the firewall. I personally take your route earnstaf, I always check the process. If I'm using something that connects to the Internet, most likely I would have already given it permission to do so a while back so if it is asking again, I will surely look more into it.
 
Please tell me what presents such a big issue, I just dont see it.
If you allow all your users to install new software on their PC's that may be where your problems start.
For those few that are allowed to install software, any issues are easily cleared up with a phone call.

Why are you avoiding directly answering the question? What products do you use to control outbound access? How do you administer them en mass? How do you ensure the firewalls are updated to allow the "safe" programs? How many systems are you administering?

You said you don't have any issues with setting up clients, so I'm asking you to elaborate so we can all learn.
 
That's all interesting. I'd really like to see it in action. However, I just don't see it working. If something suddenly starts trying to go out, even if it is a known process, it is at least going to raise a red flag in my mind. Then, I will research the destination address and figure out what is going on.

On your second point, again, I just don't see it working. You say it will wait until I'm surfing and then transmit. Is that to say it will spoof itself as firefox.exe (or the process ID firefox is using) and go out over port 80? If it can do that, it will be permitted anyways and I'll never get an alert as outbound 80 is permitted from firefox.
It's almost like you think I'm taking the pro-outbound filtering approach. I'm not.
For the exact reasons you listed, is why outbound filtering doesn't work, among others.

Outbound filtering essentially has you admitting defeat that your network is compromised. Think of it this way... It's like a huge fortress with a moat of water around it. The thing catches on fire. All you're doing is stopping it from spreading to other villages. The fortress itself is already compromised.

Why are you avoiding directly answering the question? What products do you use to control outbound access? How do you administer them en mass? How do you ensure the firewalls are updated to allow the "safe" programs? How many systems are you administering?

You said you don't have any issues with setting up clients, so I'm asking you to elaborate so we can all learn.
Exactly, I'd like to know as well.

I will admit, theoretically and technically on paper, outbound filtering can work. However from a business and "get work done" standpoint, it is more of a bother for absolutely everyone than it is worth.

You can be much more effective at using measures to stop malware in the first place than you'd ever be trying to stop it getting back out once it has infected your machines.
 
Outbound detection is a good thing, you want to know if the castles on fire. I want to know if someone is running IRC on my network so I can smack them with a large trout. That's not a discrete workstation issue though - thats more of an infrastructure function
 
Why are you avoiding directly answering the question? What products do you use to control outbound access? How do you administer them en mass? How do you ensure the firewalls are updated to allow the "safe" programs? How many systems are you administering?

You said you don't have any issues with setting up clients, so I'm asking you to elaborate so we can all learn.

I'm not avoiding anything I dont have to :)
We use Comodos CIS and manage its configuration by importing pre-defined configurations direct to the registry.
File hashes can also be updated with this method so when new software apps/updates are rolled out, the firewall is configured to trust the hashes for the apps and the parent apps that are authorised to start them.
The Firewall uses a controlled whitelist for allowed apps.

I am not at liberty to discuss the network topology soz.
 
Outbound filtering essentially has you admitting defeat that your network is compromised. Think of it this way... It's like a huge fortress with a moat of water around it. The thing catches on fire. All you're doing is stopping it from spreading to other villages. The fortress itself is already compromised.

I just don't see that as being true. In the case of a worm, or similar, maybe... but anything that is trying to send back your personal data will not be permitted.

Exactly, I'd like to know as well.

I will admit, theoretically and technically on paper, outbound filtering can work. However from a business and "get work done" standpoint, it is more of a bother for absolutely everyone than it is worth.

You can be much more effective at using measures to stop malware in the first place than you'd ever be trying to stop it getting back out once it has infected your machines.

You must not be a security guy. That "bother" is called security. There is a give and take relationship between security and convenience. As you add security, convenience is compromised and visa-versa. I'll err on the side of security.
 
I don't see why this has moved into businesses, but this is for home use.

No need to argue something that I don't need.
 
That's not a discrete workstation issue though - thats more of an infrastructure function
Exactly, outbound is great in business environments. It's a great control on what programs and protocols are allowed to run (IM apps, etc).

However this is home use.

I just don't see that as being true. In the case of a worm, or similar, maybe... but anything that is trying to send back your personal data will not be permitted.
Not if Average Joe just clicks yes when he sees Explorer.exe trying to access the internet. Can you honestly. Honestly tell me, on your personal home computer, not just click through a warning if you're busy and trying to get a problem resolved remotely?



As you add security, convenience is compromised and visa-versa. I'll err on the side of security.
I'd disagree. Both can coexist peacefully. My argument is that outbound filtering won't save you once the castle is already on fire.
 
I'd disagree. Both can coexist peacefully. My argument is that outbound filtering won't save you once the castle is already on fire.

Its not possible to make a blanket statement like that.
Outbound filtering adds another layer of security that malware has to get through if it wants to send data from your machine.

So if you do get a virus, it wont be able to infect other machines and will not be able to send any of your valuable data across the internet.
Thats pretty good if you ask me.
 
Not if Average Joe just clicks yes when he sees Explorer.exe trying to access the internet. Can you honestly. Honestly tell me, on your personal home computer, not just click through a warning if you're busy and trying to get a problem resolved remotely?

Yes, I can say that honestly. If explorer.exe is trying to talk out, I would at the very least look into it further. If I can't determine conclusively what it is trying to do, I'll deny it. If it happens repeatedly then I know I have bigger issues.

Before I used Comodo, there were times when I'd get "clicky" on the permit when installing software or such and something may have been able to slip in, but even then I would likely notice ""blah.exe" is trying to access you HD directly" and "blah.exe is trying to access a remote device on TCP/4924" However, Comodo has the option to treat a particular executable as an "installer or updater" which is pretty nice.
 
Back
Top