Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 1st, 2012, 05:14 PM
marse.robert's Avatar
marse.robert marse.robert is offline
Frequent Poster
 
Join Date: Nov 2004
Location: Langar: Nottinghamshire: UK
Posts: 240
Default Sandboxie with Shadow Defender

Hi all,

I need some advice how to run Sandboxie and Shadow Defender in tandem.


Thank you in anticipation


Marse
  #2  
Old April 1st, 2012, 10:28 PM
Osaban's Avatar
Osaban Osaban is offline
Massive Poster
 
Join Date: Apr 2005
Posts: 3,086
Default Re: Sandboxie with Shadow Defender

Some people think it is overkill. I tend to think that it depends on the circumstances. If you are testing malware or you know you are visiting very infected websites/plugging in friends flashdrives it might be safer to use them in tandem.

Sandboxie in my experience is excellent when surfing the Internet, Shadow Defender is probably a better alternative for malware coming from other sources than the Internet. A practical aspect of using Sandboxie on its own is that one can download and save files without having to "commit" and reboot. From experience I have occasionally lost some stuff in the past using SD.

I should think that Sandboxie and SD are great to use for banking and credit card transactions online, making sure that Sandboxie is tightly configured to block keyloggers.
__________________
Samsung Series 7 Chronos & Windows 8 (64bit)
“We are the cosmos made conscious and life is the means by which the universe understands itself.” Brian Cox
  #3  
Old April 1st, 2012, 11:11 PM
AlexC's Avatar
AlexC AlexC is offline
Very Frequent Poster
 
Join Date: Apr 2009
Posts: 1,111
Default Re: Sandboxie with Shadow Defender

Quote:
Originally Posted by marse.robert
Hi all,

I need some advice how to run Sandboxie and Shadow Defender in tandem.


Thank you in anticipation


Marse

marse.robert, there's nothing special about it, you just need to get familiarized with both applications. However keep in mind that if your system is already infected with some keylogger/screenlogger/trojan, etc., no matter how tight you configure Sandboxie, the security of your data is compromissed. And the same applies if during a browsing session you download malware to a "real" location (non-sandboxed): the system will remain infected until the next reboot, when Shadow Defender do is job (assuming that that location isn't also excluded from Shadow Mode).

A good strategy, IMO, is to submit the downloaded files to Virus Total (you can use VirusTotal Uploader to make that task easier -http://www.softpedia.com/get/System/OS-Enhancements/VirusTotal-Uploader.shtml-), and have a on-demand AV for larger files that cannot be subtimed (for instance, Avira or Avast installed without the real-time shields).
__________________
Linux Mint 13 MATE x64
  #4  
Old April 2nd, 2012, 01:57 PM
kjdemuth's Avatar
kjdemuth kjdemuth is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Boston, MA
Posts: 2,340
Default Re: Sandboxie with Shadow Defender

I've been using SD and sandboxie now for a few years. The only thing that you have to worry about is tightening up sandboxie and remembering to commit files you want to keep. What I do is have sandboxie internet restricting everything except Chrome and adobe. Adobe of course has it's own sandbox. I also have drop my rights and restriction on what can run and start. I added an excluded "Save" folder on shadow defender. This also is a sandboxed folder. All downloads go into this folder. This way I won't forget and not commit it to the system. It's excluded from SD but is still sandboxed. This way I can keep an eye on it even though it makes it passed SD.
__________________
Realtime:
WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS.
On-Demand:
MBAM+EAM
Hitman pro (Scans daily)
  #5  
Old April 2nd, 2012, 02:51 PM
Blues7's Avatar
Blues7 Blues7 is offline
Frequent Poster
 
Join Date: May 2009
Location: Blue Ridge Mountains
Posts: 639
Default Re: Sandboxie with Shadow Defender

Quote:
Originally Posted by kjdemuth
I've been using SD and sandboxie now for a few years. The only thing that you have to worry about is tightening up sandboxie and remembering to commit files you want to keep. What I do is have sandboxie internet restricting everything except Chrome and adobe. Adobe of course has it's own sandbox. I also have drop my rights and restriction on what can run and start. I added an excluded "Save" folder on shadow defender. This also is a sandboxed folder. All downloads go into this folder. This way I won't forget and not commit it to the system. It's excluded from SD but is still sandboxed. This way I can keep an eye on it even though it makes it passed SD.

That's pretty much exactly how I envisioned using the two together if I were to do so on a regular basis. (Substitute Firefox in my case.)

I just haven't (yet) made the decision to do so as things are working so well in their current configuration and I'm reluctant to have to reboot and come out of shadow mode to keep EAM and MBAM updated.

It's nice having the option to do so, however, at the click of a mouse.
__________________
Blues

Real-Time: ★ Emsisoft Internet Security ★ Sandboxie ★

On-Demand: ★ Drive Snapshot / Macrium Reflect ★ Shadow Defender ★
  #6  
Old April 2nd, 2012, 04:33 PM
kjdemuth's Avatar
kjdemuth kjdemuth is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Boston, MA
Posts: 2,340
Default Re: Sandboxie with Shadow Defender

Yeah I hear you. It was a problem for me too. Thats why I moved away from database AV. I have panda pro and Ccmodo firewall running real time. Nothing really needs updating other than Comodo firewall occasionally. By itself SD, sandboxie and comodo firewall should be enough. I wanted something that didn't need updating and was light. PCAV pro fit the bill nicely. I'm one of those folks that are on the fence about going AV free. I hear that there is a support group for people like me.
__________________
Realtime:
WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS.
On-Demand:
MBAM+EAM
Hitman pro (Scans daily)
  #7  
Old April 2nd, 2012, 04:47 PM
Blues7's Avatar
Blues7 Blues7 is offline
Frequent Poster
 
Join Date: May 2009
Location: Blue Ridge Mountains
Posts: 639
Default Re: Sandboxie with Shadow Defender

Quote:
Originally Posted by kjdemuth
I'm one of those folks that are on the fence about going AV free. I hear that there is a support group for people like me.

I've done it for months at a time, then I find that I just can't help myself and get addicted to certain apps...When you find that group let me know. Maybe you can be my sponsor.
__________________
Blues

Real-Time: ★ Emsisoft Internet Security ★ Sandboxie ★

On-Demand: ★ Drive Snapshot / Macrium Reflect ★ Shadow Defender ★
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:00 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums