Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 22nd, 2006, 10:57 AM
Chuck57 Chuck57 is offline
Very Frequent Poster
 
Join Date: Sep 2002
Location: New Mexico, USA
Posts: 1,358
Default Sandboxie again....and won't stop grc leaktest

I tried sandboxie with the grc leaktest 1.2 last night. Downloaded it, ran it in the sandboxie folder, and it showed responding to grc.com. At that time, I had only windows firewall, so no outbound protection.

My understanding was that Sandboxie stopped all that stuff, or did I misunderstand.

I installed my old version of ZA 6.1.xxx and ran it again. ZA caught the test and stopped it.

So, is Sandboxie at fault, or should I not worry that this one particular program got out? This stuff is all new to me, and not criticizing Sandboxie. It's a great little program
__________________
"If guns are outlawed, only the government will have guns. Only the police, the secret police and the military.... Only the government - and the outlaws. I intend to be among the outlaws." - Edward Abbey
  #2  
Old November 22nd, 2006, 11:15 AM
WSFuser WSFuser is offline
Incredibly Massive Poster
 
Join Date: Oct 2004
Location: California, USA
Posts: 10,324
Default Re: Sandboxie again....and won't stop grc leaktest

sandboxie does nothing to stop network connections and its not meant to.
__________________
  #3  
Old November 22nd, 2006, 11:20 AM
Chuck57 Chuck57 is offline
Very Frequent Poster
 
Join Date: Sep 2002
Location: New Mexico, USA
Posts: 1,358
Default Re: Sandboxie again....and won't stop grc leaktest

Thanks much for that info. I figured it was a minor detail I'd overlooked in reading about this sandboxing stuff.
__________________
"If guns are outlawed, only the government will have guns. Only the police, the secret police and the military.... Only the government - and the outlaws. I intend to be among the outlaws." - Edward Abbey
  #4  
Old November 22nd, 2006, 11:35 AM
Jarmo P Jarmo P is offline
Frequent Poster
 
Join Date: Aug 2005
Posts: 473
Default Re: Sandboxie again....and won't stop grc leaktest

Sandboxie only isolates malware.

Leaktest.exe is just a normal program exe file.
Running SSM, it would be recognized as a new application (if not in learning mode) and user gets asked what to do.
If allowed, the program acts just like other normal outbound connection applications, so if a firewall protects outbound, a user gets asked again.

Sandboxie protects rather your real system of not getting infected and does not restrict what malware does in a sandbox (sure can connect to internet too ). Leaktest.exe is though also run in a Sandboxie when executed, so it can only read your real system if even that.
__________________
Avast free, Firefox NoScript extension and internet applications "inside" Sandboxie.

Last edited by Jarmo P : November 22nd, 2006 at 11:49 AM.
  #5  
Old November 22nd, 2006, 11:52 AM
Chuck57 Chuck57 is offline
Very Frequent Poster
 
Join Date: Sep 2002
Location: New Mexico, USA
Posts: 1,358
Default Re: Sandboxie again....and won't stop grc leaktest

I'm using CyberHawk. Have SSM but wanted to try CyberHawk. It did nothing in the way of warning me, but it's not exactly the same as SSM, which I think I'll return to today.
__________________
"If guns are outlawed, only the government will have guns. Only the police, the secret police and the military.... Only the government - and the outlaws. I intend to be among the outlaws." - Edward Abbey
  #6  
Old November 22nd, 2006, 12:01 PM
FastGame's Avatar
FastGame FastGame is offline
Frequent Poster
 
Join Date: Jan 2005
Location: Blasters worm farm
Posts: 677
Default Re: Sandboxie again....and won't stop grc leaktest

Hello Chuck57

If you want to take full advantage of Sandboxie here's what you do...

Lets say you want to do online banking or shopping, first you start off with a clean sandbox. After you're done do a simple clear sandbox. Now lets say you want to mess around with some porn or check the underworld out, you have a clean sandbox, visit your underworld sites and clear the sandbox when you are done. For best protection you can clear the sandbox between site visits

Clearing the sandbox is fast and simple, things can't leak when they aren't there.
  #7  
Old November 22nd, 2006, 12:02 PM
Jarmo P Jarmo P is offline
Frequent Poster
 
Join Date: Aug 2005
Posts: 473
Default Re: Sandboxie again....and won't stop grc leaktest

Quote:
I'm using CyberHawk. Have SSM but wanted to try CyberHawk. It did nothing in the way of warning me, but it's not exactly the same as SSM, which I think I'll return to today.

Leaktest.exe is a normal program, it is not malware.
It should not be detected by Cyberhawk and also SSM treats it as any other normal program.

I don't run SSM real time normally. But it is usefull when installing new software or trying to "monitor system" behaviour when in paranoid or suspicious mood.
__________________
Avast free, Firefox NoScript extension and internet applications "inside" Sandboxie.
  #8  
Old November 22nd, 2006, 12:25 PM
WSFuser WSFuser is offline
Incredibly Massive Poster
 
Join Date: Oct 2004
Location: California, USA
Posts: 10,324
Default Re: Sandboxie again....and won't stop grc leaktest

leaktest if meant to test outbound filtering, so you would need a firewall or HIPS with outbound network control (like SSM or AppDefend).
__________________
  #9  
Old November 22nd, 2006, 12:49 PM
Chuck57 Chuck57 is offline
Very Frequent Poster
 
Join Date: Sep 2002
Location: New Mexico, USA
Posts: 1,358
Default Re: Sandboxie again....and won't stop grc leaktest

I've got a lot to learn. This is a whole new area of security for me. Time to start reading and playing with software in this area.
__________________
"If guns are outlawed, only the government will have guns. Only the police, the secret police and the military.... Only the government - and the outlaws. I intend to be among the outlaws." - Edward Abbey
  #10  
Old November 22nd, 2006, 01:17 PM
Jarmo P Jarmo P is offline
Frequent Poster
 
Join Date: Aug 2005
Posts: 473
Default Re: Sandboxie again....and won't stop grc leaktest

Quite new to me too.
I don't much care about diagrams that are currently discussed in some other thread. I take rather a pragmatic viewpoint.

To me I am safe when running programs in a Sandboxie from infecting/corrupting my system.
With SSM i can control what processes/programs I allow to run. It does not protect me from infections in a same way. That is antivirus's etc. department.
I can just block realsched.exe from launching realplay.exe, so it does not have to be about malware.
Cyberhawk smells "bad behaviour" from programs and has some community list knowledge features too.
Though it often reports my Skype.exe of a trojan like behaviour when starting it too

I see a theoretical possibility of a conflict if running SSM and CH same time. Who knows these days what security programs will conflict each other etc. Sure am glad to be running a very well functioning simple packet filter like kerio 2.1.5.
Common sense more important than diagrams, lol:
http://www.wilderssecurity.com/showthread.php?t=155098
__________________
Avast free, Firefox NoScript extension and internet applications "inside" Sandboxie.

Last edited by Jarmo P : November 22nd, 2006 at 02:11 PM.
  #11  
Old November 22nd, 2006, 02:15 PM
ggf31416 ggf31416 is offline
Frequent Poster
 
Join Date: Aug 2006
Location: Uruguay
Posts: 313
Default Re: Sandboxie again....and won't stop grc leaktest

Quote:
Originally Posted by Chuck57
My understanding was that Sandboxie stopped all that stuff, or did I misunderstand.

Sandboxie prevents the sandboxed programs from changing your "actual system" but not from reading files or making outbound conections.
For example you can send the EICAR test file to VirusTotal through a sandboxed browser.
  #12  
Old November 22nd, 2006, 03:53 PM
Chuck57 Chuck57 is offline
Very Frequent Poster
 
Join Date: Sep 2002
Location: New Mexico, USA
Posts: 1,358
Default Re: Sandboxie again....and won't stop grc leaktest

Kind of off topic but regarding sandboxing, what about DefenseWall? I tried it a while back, briefly, and was completely lost. I spent more time trying to figure out the help files than actually using the program. According to the tests in another thread, it might be the best of the bunch - if it can be figured out.
__________________
"If guns are outlawed, only the government will have guns. Only the police, the secret police and the military.... Only the government - and the outlaws. I intend to be among the outlaws." - Edward Abbey
  #13  
Old November 22nd, 2006, 04:21 PM
WSFuser WSFuser is offline
Incredibly Massive Poster
 
Join Date: Oct 2004
Location: California, USA
Posts: 10,324
Default Re: Sandboxie again....and won't stop grc leaktest

heres a quote from an old defensewall thread:
Quote:
The program idea is easy and simple. All applications are divided into trusted ones and untrusted ones. Everything is allowed for the trusted applications, but there are many restrictions for the untrusted ones. The restrictions are as follows: modification of the file system sensitive folders (ex., My Documents, Windows, Program Files), registry keys (ex., autorun, browser and system application settings, etc.), and entire system (installation/changing/deleting of the drivers and services,
protection of the \\Device\\PhysicalMemory, setting of the global window hooks (against so-called keyloggers), etc.).
basically u just place browsers, email, p2p and other internet-related programs into the untrusted list and your all set.
__________________
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:39 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums