PDA

View Full Version : SandboxIE+NOD2.7


Stijnson
April 4th, 2008, 07:28 AM
At the moment NOD32 2.7 is my AV. This AV has 2 modules called AMON (monitors all disk writing/reading) and IMON (monitors internet files reading/downloading etc).

Does anyone if these modules continue to work properly (read: scan files) when a browser is sandboxed? I hope there are other NOD32 2.7 users here who can help me out.

MikeNAS
April 4th, 2008, 07:51 AM
-{ Quote: "At the moment NOD32 2.7 is my AV. This AV has 2 modules called AMON (monitors all disk writing/reading) and IMON (monitors internet files reading/downloading etc).

Does anyone if these modules continue to work properly (read: scan files) when a browser is sandboxed? I hope there are other NOD32 2.7 users here who can help me out." }-

Yes of course they work like before.

Stijnson
April 4th, 2008, 08:16 AM
-{ Quote: "Yes of course they work like before." }-

Apparently not, because the number of files scanned by IMON doesn't increase when browsing sandboxed. Or is there a workaround for this?

MikeNAS
April 4th, 2008, 08:58 AM
-{ Quote: "Apparently not, because the number of files scanned by IMON doesn't increase when browsing sandboxed. Or is there a workaround for this?" }-

I installed latest Sandboxie and latest (I can't download 2.7 NOD via their web pages) NOD. I run Firefox inside of Sandboxie and Web access protection number of scanned objects working like it should.

EDIT: It's nice that I don't have to restart computer if I like to use NOD :D

Stijnson
April 4th, 2008, 09:00 AM
-{ Quote: "I installed latest Sandboxie and latest (I can't download 2.7 NOD via their web pages) NOD. I run Firefox inside of Sandboxie and Web access protection number of scanned objects working like it should.

EDIT: It's nice that I don't have to restart computer if I like to use NOD :D" }-

Yes, but that means that you are using NOD v3 (which works without AMON/IMON modules).

MikeNAS
April 4th, 2008, 09:04 AM
-{ Quote: "Yes, but that means that you are using NOD v3 (which works without AMON/IMON modules)." }-

Yeah maybe that is problem :argh:

Stijnson
April 4th, 2008, 09:06 AM
-{ Quote: "Yeah maybe that is problem :argh:" }-

I guess so ;D
So my initial question still stands...:)

MikeNAS
April 4th, 2008, 09:08 AM
-{ Quote: "I guess so ;D
So my initial question still stands...:)" }-

I test version 2.7 now. I inform results soon.

MikeNAS
April 4th, 2008, 09:21 AM
It looks like that IMON scans sandboxed browser but scanned files number is always same. File: status changed correctly so that's why I believe everything is ok. Some wiser can correct if my opinion is wrong :D

Stijnson
April 4th, 2008, 09:22 AM
-{ Quote: "I test version 2.7 now. I inform results soon." }-

That's great MikeNAS. Could you also let me know how AMON behaves INSIDE the Sandbox? Does it scan all files, so also the files IMON doesn't?

Stijnson
April 4th, 2008, 09:23 AM
-{ Quote: "It looks like that IMON scans sandboxed browser but scanned files number is always same. File: status changed correctly so that's why I believe everything is ok. Some wiser can correct if my opinion is wrong :D" }-

File status changed? Can you explain what this means?
I think Marcos at some point stated that IMON wasn't able to scan inside a sandbox, that's why I'm amazed about your findings.

MikeNAS
April 4th, 2008, 09:26 AM
-{ Quote: "That's great MikeNAS. Could you also let me know how AMON behaves INSIDE the Sandbox? Does it scan all files, so also the files IMON doesn't?" }-

AMON working correctly. Scanned files number is ok too.

-{ Quote: "File status changed? Can you explain what this means?
I think Marcos at some point stated that IMON wasn't able to scan inside a sandbox, that's why I'm amazed about your findings." }-

I mean that IMON actually see sandboxed browser web page address and files.

Stijnson
April 4th, 2008, 09:29 AM
-{ Quote: "AMON working correctly. Scanned files number is ok too.



I mean that IMON actually see sandboxed browser web page address and files." }-

So it DOES show the correct url in IMON, but the number of files scanned doesn't increase? Is that a correct assumption?
This could also mean that the files aren't being scanned by IMON at all, just showing the correct url...Hmmm.
Does AMON scan these files I wonder.

MikeNAS
April 4th, 2008, 09:33 AM
-{ Quote: "So it DOES show the correct url in IMON, but the number of files scanned doesn't increase? Is that a correct assumption?
This could also mean that the files aren't being scanned by IMON at all, just showing the correct url...Hmmm.
Does AMON scan these files I wonder." }-

That's correct assumption. AMON scans sandboxed saved files.

Stijnson
April 4th, 2008, 09:36 AM
-{ Quote: "That's correct assumption. AMON scans sandboxed saved files." }-

Saved files being files downloaded and saved outside the sandbox? But what about the urls and links a user visits while browsing in a sandbox?
Wouldn't this be harmful?

MikeNAS
April 4th, 2008, 09:45 AM
-{ Quote: "Saved files being files downloaded and saved outside the sandbox? But what about the urls and links a user visits while browsing in a sandbox?
Wouldn't this be harmful?" }-

saved files = inside of sandboxie and of course outside too :D

urls and links aren't harmful because all files are inside of sandboxie and if something comes to your sandboxed computer AMON scans that. And of course just empty your sandbox and everything is gone.

Stijnson
April 4th, 2008, 09:53 AM
-{ Quote: "saved files = inside of sandboxie and of course outside too :D

urls and links aren't harmful because all files are inside of sandboxie and if something comes to your sandboxed computer AMON scans that. And of course just empty your sandbox and everything is gone." }-

All I needed to hear. Thanks Mike, you've been of great help! :thumb: :thumb: