Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 25th, 2007, 11:06 AM
Monkey_Feces Monkey_Feces is offline
Regular Poster
 
Join Date: Aug 2006
Posts: 52
Default Sandboxie question

I tend to think that I have adequate zero day protection w/ Prevx1 in ABC mode, antivir guard, and SSM free. Therefore, I'm pretty sure I'm covered when it comes to attacks from programs of questionable origin (cough* filesharing *cough). What are the chances that something bad might leak out of the sandbox? Am I being extremely paranoid by running anything other than an internet browser via sandboxie ;considering many other people find a simple anti virus + only downloading material with lots of comments and seeds/leechers adequate safety precautions?
  #2  
Old March 25th, 2007, 01:51 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Sandboxie question

See this thread about P2P misconceptions.
I wouldn´t download executable content from P2P networks.
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #3  
Old March 25th, 2007, 02:12 PM
Monkey_Feces Monkey_Feces is offline
Regular Poster
 
Join Date: Aug 2006
Posts: 52
Default Re: Sandboxie question

Thanks, the link was really informative and your tip was sound advice. However, I'm a cheap ass idiot, so I still want to know what the chances are that malicious content may leak from the sandbox. Also, I would like to know if it is even necessary to sandbox with my 3 real time protection apps.

On a somewhat related note, is the avira premium background, realtime scanner any better than the free one? I acquired a nag free version of winrar and avira only alerted me of a rootkit after I installed it.
  #4  
Old March 25th, 2007, 02:39 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: Sandboxie question

- I wouldn´t sandbox P2P apps. If you are really worried, run them in a virtual or spare machine. Also, SSM should intercept the execution of files.
- There´s the possibility that malware can leak from the sandbox. Remember that 100 % security does not exist.
- Antivir PE Premiun adds ad/spyware detection, MailGuard, better update servers, etc.
- That rootkit detection could be a FP.
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #5  
Old March 25th, 2007, 03:00 PM
Peter2150's Avatar
Peter2150 Peter2150 is online now
Global Moderator
 
Join Date: Sep 2003
Posts: 11,805
Default Re: Sandboxie question

Ran a little test with Sandboxie v 2.8 myself. First I did a sandboxed install of Cryptosuite. It is fairly non intrusive only installng a couple of dll's. Stayed totally in the sandbox, and ran their, but I couldn't acess files outside of the sandbox to archive. Deleted the sandbox and it was gone. Next I tried KAV. I had to run the windows installer startup in sandboxie. Then I tried the kAV install. It failed and rolled back the install. Deleted sandbox and it was gone. Finally I tried an install of OA inside the sandbox. It installed okay, but couldn't start it's service. Again a sandbox delete and it was gone.

So I am fairly comfortable with Sanboxie doing it's job. However as recommended if I know I am going risky, I will actually run Sandboxie inside a VM machine.
  #6  
Old March 25th, 2007, 06:29 PM
Monkey_Feces Monkey_Feces is offline
Regular Poster
 
Join Date: Aug 2006
Posts: 52
Default Re: Sandboxie question

Thanks for bringing up VMs. I did some research on the castlecops wiki because I initially had no idea what a VM was. I have a few questions about it now. If I do adopt a VM for security measures, is VMware the best free program for setting up? Will emulating my hardware make my system any slower (I need as many hardware resources as possible since those executables I (*ahem*) acquire are game installers)?
  #7  
Old March 25th, 2007, 07:17 PM
Peter2150's Avatar
Peter2150 Peter2150 is online now
Global Moderator
 
Join Date: Sep 2003
Posts: 11,805
Default Re: Sandboxie question

Quote:
Originally Posted by Monkey_Feces
Thanks for bringing up VMs. I did some research on the castlecops wiki because I initially had no idea what a VM was. I have a few questions about it now. If I do adopt a VM for security measures, is VMware the best free program for setting up? Will emulating my hardware make my system any slower (I need as many hardware resources as possible since those executables I (*ahem*) acquire are game installers)?

There are a couple of threads in the Software and Services thread about the free vm machines. I bought VMware Workstation and it has worked well. I don't see an impact, but I am running on a machine that has excess resources so I don't see an impact.


Pete
  #8  
Old March 30th, 2007, 07:11 PM
Monkey_Feces Monkey_Feces is offline
Regular Poster
 
Join Date: Aug 2006
Posts: 52
Default Re: Sandboxie question

I'm starting to think sandboxie/VMmachines are entirely unnecessary.

Would my combination of real time Avira, Prevx1 ABC, SSM, and Comodo PF catch nasty malicious installations or compromised apps phoning home? Are my on demand scanners via Avira + AVG AS capable of catching all major executed threats? If they are, won't my chances of running backdoors or rootkits be pretty much nill as long as my p2p selections are reliable (good comments/high seeds)?
  #9  
Old March 30th, 2007, 08:09 PM
besafe besafe is offline
Frequent Poster
 
Join Date: Mar 2007
Posts: 222
Default Re: Sandboxie question

Quote:
Originally Posted by Monkey_Feces
I'm starting to think sandboxie/VMmachines are entirely unnecessary.

Would my combination of real time Avira, Prevx1 ABC, SSM, and Comodo PF catch nasty malicious installations or compromised apps phoning home? Are my on demand scanners via Avira + AVG AS capable of catching all major executed threats? If they are, won't my chances of running backdoors or rootkits be pretty much nill as long as my p2p selections are reliable (good comments/high seeds)?

Bottom line is that even with your current system, you may still be put in the position to make the wrong or right decision. For example: you go to install a new game, it's infected with malware, both Comodo and SSM alert you, and you allow the alert because you are installing a game. Bam...you're infected. Now hopefully Avira or Prevx1 will compensate for your bad decision. But they might not. So from that aspect, sandboxing adds another layer of security and makes sense.

What are the odds? I think your current system even without a virtual application is excellent and the chances of you getting infected are extremely low.
  #10  
Old March 31st, 2007, 12:50 AM
Jarmo P Jarmo P is offline
Frequent Poster
 
Join Date: Aug 2005
Posts: 473
Default Re: Sandboxie question

I think "monkey" you may have had a wrong idea about what a Sandboxie is. It is not made against malicious information passing out to internet from your possibly infected sandbox content. For that you have your firewall, behaviour hips, classical hips, AV.

Sandboxie is about protecting your Windows install, original program installs, your system, keeping it clean from what ever baddies you might play with inside the sandbox. The programs having their vulnerabilities and also Windows ones restricted to a virtualized sandbox while they are running in it, preventing them escalating malware infections into your system.To get a better idea is to visit Ronen Tzur's web site in here:
http://www.sandboxie.com/
He is a very outspoken developer and also replies what I have seen to most rational queries in his forum.
Jarmo
__________________
Avast free, Firefox NoScript extension and internet applications "inside" Sandboxie.

Last edited by Jarmo P : March 31st, 2007 at 01:08 PM.
  #11  
Old March 31st, 2007, 03:24 PM
Monkey_Feces Monkey_Feces is offline
Regular Poster
 
Join Date: Aug 2006
Posts: 52
Default Re: Sandboxie question

It's a pain trying to run anything other than an internet browser via sandboxie. I'll probably just backup my os installation and most used, 100% uncompromised programs. I know I should do my research, but it's going to be a pain selecting which program. My questions are: Is there a way I can compress 30 gigs of files into an easily accessible and restorable partition, and if so, what program should I use? I already toyed w/ window's xp's included backup function, but I'm not sure if it's any different from just backing up my hard drive on several cds with no compression.
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:32 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums