Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old September 21st, 2012, 03:02 PM
noone_particular noone_particular is offline
Very Frequent Poster
 
Join Date: Aug 2008
Posts: 1,876
Default Re: Does Sandboxie have self-protection?

Sully,
It was just a quick test, not a "proper" experiment by any means. The closest real world equivalent would be seeing what's possible should malicious code escape the sandbox and attack it from the outside.
Quote:
I would be very curious to see though, if the sandbox were terminated from within, if the sandboxed processes were also terminated. They aren't, as you state, when you terminate it from the host.
I'm suspecting that they won't be terminated. If an app that has built in resistance to termination can be made to run inside the sandbox, it could make for some very interesting experiments.

IMO, a layered approach in which a separate app protects the Sandboxie processes and files, plus restricts the allowed activities in the sandbox itself is the way to go. No matter how well an app is coded, it's not bulletproof. Just because there isn't a publicly known way to attack and defeat it doesn't mean it's impossible. A means might not be found or it may be found tomorrow. For all we know, just such an attack might have been found and sold to those who collect these things (government agencies and the private sector companies that do the dirty work for instance). When your security policy and package acknowledge possibilities like this and proactively address them, unpatched and zero day exploits against the protected apps are often mitigated or defeated outright. I haven't seen and am not aware of any attacks that can terminate my firewall or SSM, but both are watched and will be restarted if something does terminate one of them. Sandboxie is good and may be able to stand alone, but why should it when it doesn't have to?
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come.
  #27  
Old September 21st, 2012, 04:23 PM
bo elam bo elam is offline
Very Frequent Poster
 
Join Date: Jun 2010
Posts: 1,041
Default Re: Does Sandboxie have self-protection?

Quote:
Originally Posted by jasonbourne
Nothing will happen especially if you have Drop My Rights enabled. SBIE will contain it inside the sandbox unless you recover it or set Delete Invocation to "Automatically delete contents of the sandbox".
If you exit SBIE, even if the sandbox is set to have the contents deleted automatically, the contents of the sandbox will not be deleted until you restart Sandboxie and click on delete the sandbox.

Bo
  #28  
Old September 21st, 2012, 07:18 PM
chris1341's Avatar
chris1341 chris1341 is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Scotland
Posts: 624
Default Re: Does Sandboxie have self-protection?

This thread has started from a fairly unfortunate premise in my view. I understand the concern but it is based on a misunderstanding on how SBIE works in my view.

Sully has, as always, laid out the fundamentals on which SBIE works. I wonder at times if it is so simple that it confuses things and we see SBIE through the prism that we use for traditional security apps. SBIE is part of a different paradigm than that associated with traditional AV/HIPS or similar.

Other apps work similarly. Take Defensewall for example. An trusted programme can kill it easily. That's the point. Only untrusted apps are restricted. With AppGuard un-guarded apps can do what they like. In SBIE anything unsandboxed will be able to kill SBIE processes, albeit needing privilege elevation at times. Trying similar tactics within the Sandbox would be pointless as if you kill SBIE you kill the app undertaking the malicious activities. Not to mention SBIE restricts many activities by default and when configured with start/run restrictions would prevent malicious/unauthorised execution anyway.

For it to be a genuine concern for me someone is going to have to prove a malicious app can escape SBIE control and write to the host, execute and kill SBIE from outside the sandbox. Until I see that I know anything running unsandboxed might be able to attack SBIE. The whole point of SBIE is to keep such things safely locked away. If you let that stuff out of the sandbox without a strategy to confirm it is safe or further restrict it, well you deserve what you get.

Cheers
__________________
Chris
  #29  
Old September 22nd, 2012, 01:38 AM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,805
Default Re: Does Sandboxie have self-protection?

Quote:
Originally Posted by bo elam
If you exit SBIE, even if the sandbox is set to have the contents deleted automatically, the contents of the sandbox will not be deleted until you restart Sandboxie and click on delete the sandbox.

Bo


That isn't correct. If the sandbox is set to delete on exit, which I do, then when I close my browser, the sandbox is terminated, and the deletion of the sandbox happens immediately at that point. I never have to delete the contents manually.

Pete
  #30  
Old September 22nd, 2012, 05:10 AM
pegr pegr is offline
Very Frequent Poster
 
Join Date: Apr 2008
Location: UK
Posts: 1,608
Default Re: Does Sandboxie have self-protection?

Quote:
Originally Posted by chris1341
This thread has started from a fairly unfortunate premise in my view. I understand the concern but it is based on a misunderstanding on how SBIE works in my view.

Sully has, as always, laid out the fundamentals on which SBIE works. I wonder at times if it is so simple that it confuses things and we see SBIE through the prism that we use for traditional security apps. SBIE is part of a different paradigm than that associated with traditional AV/HIPS or similar.

Other apps work similarly. Take Defensewall for example. An trusted programme can kill it easily. That's the point. Only untrusted apps are restricted. With AppGuard un-guarded apps can do what they like. In SBIE anything unsandboxed will be able to kill SBIE processes, albeit needing privilege elevation at times. Trying similar tactics within the Sandbox would be pointless as if you kill SBIE you kill the app undertaking the malicious activities. Not to mention SBIE restricts many activities by default and when configured with start/run restrictions would prevent malicious/unauthorised execution anyway.

For it to be a genuine concern for me someone is going to have to prove a malicious app can escape SBIE control and write to the host, execute and kill SBIE from outside the sandbox. Until I see that I know anything running unsandboxed might be able to attack SBIE. The whole point of SBIE is to keep such things safely locked away. If you let that stuff out of the sandbox without a strategy to confirm it is safe or further restrict it, well you deserve what you get.
Excellent post!
__________________
Windows Firewall - avast! Free Antivirus - AppGuard - Shadow Defender - Sandboxie - Acronis True Image
  #31  
Old September 22nd, 2012, 12:58 PM
bo elam bo elam is offline
Very Frequent Poster
 
Join Date: Jun 2010
Posts: 1,041
Default Re: Does Sandboxie have self-protection?

Quote:
Originally Posted by Peter2150
That isn't correct. If the sandbox is set to delete on exit, which I do, then when I close my browser, the sandbox is terminated, and the deletion of the sandbox happens immediately at that point. I never have to delete the contents manually.

Pete
If you close or exit the browser, of course the sandbox is deleted automatically. On my previous post, I said "Exit Sandboxie". If you exit SBIE, killing SBIE processes, the contents of the sandbox dont delete automatically. The contents wont escape the sandbox but they have to be deleted after restarting Sandboxie.

Pete, check it out and you ll see what I mean. Open your browser sandboxed, exit Sandboxie, close Firefox and after you ll restart SBIE, you ll see that the contents of the sandbox was not deleted on closing.

Bo
  #32  
Old September 22nd, 2012, 10:37 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,805
Default Re: Does Sandboxie have self-protection?

Quote:
Originally Posted by bo elam
If you close or exit the browser, of course the sandbox is deleted automatically. On my previous post, I said "Exit Sandboxie". If you exit SBIE, killing SBIE processes, the contents of the sandbox dont delete automatically. The contents wont escape the sandbox but they have to be deleted after restarting Sandboxie.

Pete, check it out and you ll see what I mean. Open your browser sandboxed, exit Sandboxie, close Firefox and after you ll restart SBIE, you ll see that the contents of the sandbox was not deleted on closing.

Bo

Hi Bo

Your are absolutely correct. I remember testing on real nasty, and you couldn't even kill anything. Had to power reset the system. System was clean, but indeed the sandbox still had all the junk in it. It was an easy clean up though.

Pete
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:57 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums