Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 20th, 2012, 06:39 PM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Is this a Sandboxie error / bug?

Not sure really, but if I understand the way Sandboxie works, the following scenario shouldn't have taken place.

1. Start your browser via a sandbox which has auto recovery disabled. Set the only recovery directory to your desktop. Start your browser inside that sandbox.

2. Download any file from the internet, doesn't matter which. Save it to your desktop, but do not recover the file.

3. Go to VirusTotal.com (would probably work for other websites as well, but I haven't tested) and click "Choose File" to browse for a file from your drive to scan. Navigate to your desktop.

I can both view and upload the sandbox-downloaded file for scanning via VirusTotal.

Any idea why?

EDIT: using Sandboxie 3.68
__________________
My setup

Last edited by syncmaster913n : April 20th, 2012 at 06:50 PM.
  #2  
Old April 20th, 2012, 06:53 PM
3x0gR13N 3x0gR13N is offline
Frequent Poster
 
Join Date: May 2008
Posts: 580
Default Re: Is this a Sandboxie error / bug?

It's normal. The file is still located in the sandbox- that's where the sandboxed browser reads it from. Nothing to do with recovery.
  #3  
Old April 20th, 2012, 06:55 PM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Is this a Sandboxie error / bug?

Ahh, got it, thanks.
__________________
My setup
  #4  
Old April 20th, 2012, 07:03 PM
chris1341's Avatar
chris1341 chris1341 is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Scotland
Posts: 624
Default Re: Is this a Sandboxie error / bug?

Quote:
Originally Posted by syncmaster913n
Not sure really, but if I understand the way Sandboxie works, the following scenario shouldn't have taken place.

1. Start your browser via a sandbox which has auto recovery disabled. Set the only recovery directory to your desktop. Start your browser inside that sandbox.

2. Download any file from the internet, doesn't matter which. Save it to your desktop, but do not recover the file.

3. Go to VirusTotal.com (would probably work for other websites as well, but I haven't tested) and click "Choose File" to browse for a file from your drive to scan. Navigate to your desktop.

I can both view and upload the sandbox-downloaded file for scanning via VirusTotal.

Any idea why?
First off I've assumed the file has not actually been recovered.

Somethings to consider. When you download to your desktop in a sanboxed browser but don't recover SBIE will create a copy of the desktop folder inside the sandbox with the downloaded file in it. If you then visit VirusTotal with the browser still sandboxed the navigation will take you to the file stored in the sandbox. The download still exists its just in the sandbox not the real system.

Remember sandboxie redirects activity spawned from a sandboxed app to the sandbox container but the apps themselves still think the sandboxed environment is the real system.

Try downloading the file. Close the browser. Empty the sandbox and then go to VirusTotal and see if its still there.

Cheers

Edit: I see you already got a reply. Sorry for the duplication!
__________________
Chris
  #5  
Old April 21st, 2012, 10:11 AM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Is this a Sandboxie error / bug?

Yeah I was aware of that but it somehow eluded me that when browsing for a file through a sandboxed browser, the desktop file contents will be those of the sandbox. thanks for the further explanation.
__________________
My setup
  #6  
Old April 21st, 2012, 10:15 AM
Ranget's Avatar
Ranget Ranget is offline
Frequent Poster
 
Join Date: Mar 2011
Location: Not Really Sure :/
Posts: 832
Default Re: Is this a Sandboxie error / bug?

because you are running VIrustotal from the sandbox it's normal
__________________
Spyshelter Premuim + MBAM Pro +Avast Free + Hardend FireFox + Secunia Update Checker
"Uncommon sense will increase your privacy; common sense will just make you common."
"The Worst Thing in the World is To look and not be able to Help "
  #7  
Old May 4th, 2012, 07:12 AM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Is this a Sandboxie error / bug?

At the risk of sounding ignorant I will press the subject a little further.

We've established that when browsing to, say, VirustTotal.com, with a sandboxed browser, and then attempting to select a file from from the desktop or wherever, what I will see are the files contained within the virtualized, sandboxie version of the desktop (meaning any files that have not been recovered will be seen there).

However, after I have recovered the file to the real desktop, and then navigate to Virustotal from within the sandboxed browser and attempt to find the file on my desktop, I can actually find it - even though it is no longer inside the sandbox.

Does this mean that when browsing for a file from within a sandboxed browser, that I will see both the contents of the sandbox, as well as those outside the sandbox, simultaneously? Or am I missing something?
__________________
My setup
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:34 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums