PDA

View Full Version : Tracking cookie bypassing Sandboxie???


AlexC
August 14th, 2009, 07:55 PM
Hello,

I´m currently using Comodo Internet Security (with Defense+ in safe mode), Sandboxie (registered version), and Avira Personal.

The sandbox is automaticly emptyed when i close the browser (i use Opera or IE). However it seems that a particular adware tracking cookie can always bypass sandboxie... is called "alexc@atdmt[2].txt" and is located in "C:\Documents and Settings\AlexC\Cookies\

Take a look:
http://img44.imageshack.us/img44/562/screenshot002kzp.jpg

Concerning to sanboxie configuration, i only allow direct access to Opera bookmarks. I don´t allow direct access to cookies.

So, how can this tracking cookie bypass sandboxie???

Thanks.

arran
August 14th, 2009, 08:18 PM
It can't bypass sandboxie. The cookie would have already been there before your installed sandboxie OR at some stage you ran your browser outside of sandboxie.

funkydude
August 14th, 2009, 08:20 PM
Block 3rd party cookies in your browser.

Joeythedude
August 14th, 2009, 08:57 PM
-{ Quote: "It can't bypass sandboxie. The cookie would have already been there before your installed sandboxie OR at some stage you ran your browser outside of sandboxie." }-

Have you any idea what site the cookie is from ?
Maybe you could do a fresh test and see if this is what happened.

AlexC
August 15th, 2009, 12:35 PM
After some testing i discovered that the contents of the sandbox were not being automatically deleted when i close IE, because i was not alowing "rundll32.exe" to start running inside the sandbox. So, is possible that the other times when SUPERAntispyware discovered the same tracking cookie, she was located inside the sandbox and i haven´t noticed ("C:\Sandbox\Documents and Settings\AlexC\Cookies\alexc@atdmt[2].txt").

-{ Quote: "It can't bypass sandboxie. The cookie would have already been there before your installed sandboxie OR at some stage you ran your browser outside of sandboxie." }-

But this time the tracking cookie was outside the sandbox ("C:\Documents and Settings\AlexC\Cookies\alexc@atdmt[2].txt"), so i think that arran is right, and probably, at some stage (although i don´t remenber), i ran IE or Opera outside the sandbox.

Thanks!