View Full Version : An Alternative To Sandboxing Your Browser?
arran
March 9th, 2009, 10:57 AM
Has anyone disabled the cache in FF3 and changed it to 0. ? Because if you do this, Fire Fox doesn't save any files. So therefore there is no files coming into your sandboxie and there is Nothing to delete at the end of your browsing session.
I also use a combination of the Cache turned off, cs lite to block all cookies, no script and admuncher, and I am finding now that there is nothing to delete from my sandboxie at the end of each browsing session even after surfing 100 porn sites loaded with malware, because "NO Files" are ever downloaded from the internet by my browser.
So I am beginning to ask myself do I still need sandboxie?
Peter2150
March 9th, 2009, 11:08 AM
-{ Quote: "Has anyone disabled the cache in FF3 and changed it to 0. ? Because if you do this, Fire Fox doesn't save any files. So therefore there is no files coming into your sandboxie and there is Nothing to delete at the end of your browsing session.
I also use a combination of the Cache turned off, cs lite to block all cookies, no script and admuncher, and I am finding now that there is nothing to delete from my sandboxie at the end of each browsing session even after surfing 100 porn sites loaded with malware, because "NO Files" are ever downloaded from the internet by my browser.
So I am beginning to ask myself do I still need sandboxie?" }-
Interesting. Personally, I would still run Sandboxie, but that is me.
Searching_ _ _
March 9th, 2009, 11:10 AM
Are talking about the Prefernces>Advanced>Network>SOffline Storage cache = 50mb ?
jmonge
March 9th, 2009, 11:15 AM
-{ Quote: "Has anyone disabled the cache in FF3 and changed it to 0. ? Because if you do this, Fire Fox doesn't save any files. So therefore there is no files coming into your sandboxie and there is Nothing to delete at the end of your browsing session.
I also use a combination of the Cache turned off, cs lite to block all cookies, no script and admuncher, and I am finding now that there is nothing to delete from my sandboxie at the end of each browsing session even after surfing 100 porn sites loaded with malware, because "NO Files" are ever downloaded from the internet by my browser.
So I am beginning to ask myself do I still need sandboxie?" }-cool man this is a smart question leading to very brave and smart decision too,i also ask same question;)
Sully
March 9th, 2009, 12:12 PM
But, ask yourself, if you don't run sandboxie to contain your browser when you surf to pornsites with malware, what happens when code is ran? True you may not be writing to the cache or what have you, but does this really protect your OS? Are there exploits that can use your browser to escape to OS environment?
If you are talking of being in LUA, and firefox.exe has restricted permissions, then perhaps a level of confidence could be presumed that this method might be secure.
However, if you are running as admin and using firefox under those credentials, I don't see this as being very safe. Maybe convenient though. I think the whole key to sandboxie is not that is writes things to the sandbox folder, which you are circumventing by not writing there. But the key is that by writing to sandbox folder, things are virtualized, and not just file writes, but registry etc.
I would personally think ditching SB in favor of what you say is not as secure as continuing your method within sandbox. But then, I will defer to peeps who have better knowledge than myself.
Sul.
Eirik
March 9th, 2009, 12:28 PM
Interesting stuff Sully. I should ask our EdgeGuard team to craft some browser policy templates along these lines and flesh out the resulting user-experience.
The Firefox settings and all diminish the risk surface. However, any other Firefox vulnerability that facilitates arbitrary execution of code (drive-by), still poses a risk to the LUA use-case, which allows code to run from user-space.
Cheers,
Eirik
arran
March 9th, 2009, 02:32 PM
yea I probably won't be ditching sandboxie, just making a point that there is never anything to delete.
Regarding remote code in technical terms how would this work, because with EQS I have given my browser very limited privileges. Also my browser does not even connect to the websites I visit, it is only allowed to connect to 1 IP address on port 53 which is for DNS Requests. Its my admuncher which connects to websites only on port 80 and filters the data before sending it to Fire Fox. So any remote code would have to be written in such a way to be able to use admuncher.
Sully
March 9th, 2009, 03:14 PM
Yeah, assuming you were to have only AV, router and firefox, running as admin, there could be holes. Using DW or EQS or other security app (admuncher in your case) merely give a layer. To get the exploit to happen then, first it would have to bypass whatever layers one would have.
I only point this out because SB does a fine job overall of segregating the sandboxed app from the rest of the system. Ditching it for simply no disk writes via browser settings does not sound like an upgrade. Granted other security tools may exist.
How do you feel your browsing is with your cache turned off? Visiting a site often (like wilders) would require longer load times it would seem. I personally keep my cache pretty small, but I definatly notice when I clear it out somewhat longer load times as it is built back up.
Not bashing your idea or anything, just thinking out loud.
Sul.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums