Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #26  
Old April 24th, 2007, 09:39 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Quote:
Originally Posted by Peter2150
What I really like is no complicated worries about where I save files I download, and no reboots to clean up. If I was using a frozen snapshot for just surfing, I think it would be bye bye frozen snapshot.
I'm not going to ditch my frozen snapshot. I don't trust any of my security applications, not even Sandboxie and I still have other weapons, if my frozen snapshot ever fails, which has to be proven first.
My whole security is partial based on restoration, the ultimate weapon against any infection. I only need more time to polish it.

An extreme test for FDISR, would be a honeypot and then try to clean that honeypot with a clean snapshot.
Unfortunately, none of the security people are interested to do such a test, they prefer to test scanners to prove how many infections they MISSED and how many false/positives they reported. That doesn't interest me, because I know this already.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.

Last edited by ErikAlbert : April 24th, 2007 at 10:04 AM.
  #27  
Old April 24th, 2007, 10:21 AM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Sandboxie v2.86

Quote:
Originally Posted by ErikAlbert

An extreme test for FDISR, would be a honeypot and then try to clean that honeypot with a clean snapshot.
Unfortunately, none of the security people are interested to do such a test, they prefer to test scanners to prove how many infections they MISSED and how many false/positives they reported. That doesn't interest me, because I know this already.

Isn't converting A Vista snapshot, into an XP snapshot using an FDISR archive enough of a test for you.
  #28  
Old April 24th, 2007, 10:25 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Quote:
Originally Posted by Peter2150
Isn't converting A Vista snapshot, into an XP snapshot using an FDISR archive enough of a test for you.
That test was also extreme and successful, but that's not the same as removing any kind of infection, from simple infections to the most sophisticated hidden infections.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #29  
Old April 24th, 2007, 11:11 AM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Sandboxie v2.86

Quote:
Originally Posted by ErikAlbert
That test was also extreme and successful, but that's not the same as removing any kind of infection, from simple infections to the most sophisticated hidden infections.

Same principle. Okay I will screw up my system with DFK Threat Simulator, a bit later.
  #30  
Old April 24th, 2007, 11:23 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Quote:
Originally Posted by Peter2150
Same principle. Okay I will screw up my system with DFK Threat Simulator, a bit later.
Is DFK Threat Simulator such a good collection of infections, that EACH TYPE of infection is included. ?
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #31  
Old April 24th, 2007, 11:35 AM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Sandboxie v2.86

Quote:
Originally Posted by ErikAlbert
Is DFK Threat Simulator such a good collection of infections, that EACH TYPE of infection is included. ?

Google it, and read the description. Sure makes a mess of the system, albeit with defanged stuff. Also comes with an uninstaller which I didn't bother with using.
  #32  
Old April 24th, 2007, 12:18 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Quote:
Originally Posted by Peter2150
Google it, and read the description. Sure makes a mess of the system, albeit with defanged stuff. Also comes with an uninstaller which I didn't bother with using.
I'm sure it will make a mess of your system, but this is nothing but a "good" theoretical test.
Nevertheless, I will try it myself one day, when I'm ready.

I remember the BBC Honeypot and they admitted, that this honeypot couldn't be cleaned with the classical security softwares. The honeypot had to be re-installed from scratch to clean it completely.
If FDISR is able to clean such a honeypot, I would feel more comfortable.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #33  
Old April 24th, 2007, 12:42 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Sandboxie v2.86

Quote:
Originally Posted by ErikAlbert
I'm sure it will make a mess of your system, but this is nothing but a "good" theoretical test.
Nevertheless, I will try it myself one day, when I'm ready.

I remember the BBC Honeypot and they admitted, that this honeypot couldn't be cleaned with the classical security softwares. The honeypot had to be re-installed from scratch to clean it completely.
If FDISR is able to clean such a honeypot, I would feel more comfortable.

No matter how bad it is, it is still just files. Do you have a link to the BBC Honeypot.

Pete
  #34  
Old April 24th, 2007, 12:49 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Quote:
Originally Posted by Peter2150
No matter how bad it is, it is still just files. Do you have a link to the BBC Honeypot.
I was too lazy to look it up, but here it is :
http://news.bbc.co.uk/2/hi/technology/5414502.stm
http://news.bbc.co.uk/1/hi/technology/6035455.stm
These are the threads at Wilders about the BBC Honeypot :
http://www.wilderssecurity.com/showt...light=Honeypot
http://www.wilderssecurity.com/showt...479#post854479
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.

Last edited by ErikAlbert : April 24th, 2007 at 01:06 PM.
  #35  
Old April 24th, 2007, 02:33 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Sandboxie v2.86

Quote:
Originally Posted by ErikAlbert

I found them, but since I sit behind a router, I can't really do a honeypot test. To much of a physical cabling mess to get around it. But I may play with some live malware in my VM machine.
  #36  
Old April 24th, 2007, 02:43 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Quote:
Originally Posted by Peter2150
I found them, but since I sit behind a router, I can't really do a honeypot test. To much of a physical cabling mess to get around it. But I may play with some live malware in my VM machine.
OK. Peter, it doesn't really matter, I was only trying to tell you that such a honeypot would be a very extreme test too.
Your VISTA--->XP test was also very extreme, that's why I believe it will remove any infection as well, BUT I would feel more comfortable, if it also cleaned a HEAVY INFECTED honeypot without any failure.

IBK (av-comparatives) has also an enormous test bed to test all these Anti-Virus softwares, so his test bed is also a very extreme test for FDISR. (hint)
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.

Last edited by ErikAlbert : April 24th, 2007 at 03:00 PM.
  #37  
Old April 24th, 2007, 03:32 PM
AJohn's Avatar
AJohn AJohn is offline
Frequent Poster
 
Join Date: Sep 2004
Posts: 935
Default Re: Sandboxie v2.86

A while ago I was listening to a 'Security Now!' episode about sandboxing applications over at GRC.com and I remember Steve Gibson comparing different sandboxing applications and coming to the conclusion that SandboxIE was one of his favorite in the way in which the programs were designed.

Some may find this episode interesting:

http://www.grc.com/SecurityNow.htm#55
__________________
·¤"Mash For Our Dreams"¤·
  #38  
Old April 24th, 2007, 04:00 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Sandboxie v2.86

Is he using FDISR or u want him to push this way?
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #39  
Old April 24th, 2007, 04:07 PM
AJohn's Avatar
AJohn AJohn is offline
Frequent Poster
 
Join Date: Sep 2004
Posts: 935
Default Re: Sandboxie v2.86

I think he was hinting that FDISR has yet to let down av-comparatives
__________________
·¤"Mash For Our Dreams"¤·
  #40  
Old April 24th, 2007, 04:10 PM
aigle's Avatar
aigle aigle is offline
Incredibly Massive Poster
 
Join Date: Dec 2005
Location: Saudi Arabia/ Pakistan
Posts: 10,431
Default Re: Sandboxie v2.86

lol...
__________________

Ubuntu 13.04
AX64 Time Machine, Comodo FW & Defence Plus, Sandboxie not compatible?
  #41  
Old April 24th, 2007, 04:52 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Quote:
Originally Posted by aigle
Is he using FDISR or u want him to push this way?
No why would I do that ? He only has to test FDISR, not keep it.
Maybe he will enjoy it, doing something else for a change.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #42  
Old April 24th, 2007, 06:14 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Well Sandboxie causes the first error on my computer, never had that before.
Suddenly a popup window appears on my desktop, when I want to open Firefox :

Direct OCR Error (= Popup Window Title)

An error with Direct OCR caused a memory conflict in your open applications. Please restart Windows.


It happened several times today.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #43  
Old April 24th, 2007, 07:37 PM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Sandboxie v2.86

OCR, is that Optical Character Recognition and relating to a document scanner software?

Had a look around SB's forum and couldn't find anything related.
  #44  
Old April 24th, 2007, 07:49 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Quote:
Originally Posted by Franklin
OCR, is that Optical Character Recognition and relating to a document scanner software?

Had a look around SB's forum and couldn't find anything related.
I posted the problem at SB's forum. I wait for an answer, if I ever get one.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #45  
Old April 24th, 2007, 08:54 PM
Meriadoc's Avatar
Meriadoc Meriadoc is offline
Very Frequent Poster
 
Join Date: Mar 2006
Location: Cymru
Posts: 2,642
Default Re: Sandboxie v2.86

Quote:
...Security Now!' episode about sandboxing applications over at GRC.com...
I think if i remember he said you cannot trust Sandboxie for security only privacy and that you could leave no trace behind on a machine when using it.
True, for one Sandboxie can hold browser related, cache etc, so when you delete the sandbox the byproducts such as history disappears, but Sandboxie is more than that - and files can be undeleted.
__________________
Who controls the past controls the future
Who controls the present controls the past

vmworld
  #46  
Old April 25th, 2007, 09:19 AM
Bob D's Avatar
Bob D Bob D is offline
Frequent Poster
 
Join Date: Apr 2005
Location: Mass., USA
Posts: 966
Default Re: Sandboxie v2.86

Quote:
Originally Posted by ErikAlbert
:
....Direct OCR Error
An error with Direct OCR caused a memory conflict in your open applications....
Are you running Omnipage?
Quote:
I posted the problem at SB's forum. I wait for an answer, if I ever get one.
I don't think you'll have to wait long. Developer Tzuk is very active there.
  #47  
Old April 25th, 2007, 02:37 PM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Franklin and BobD,
Thanks for the info you gave me, because it did ring a bell.
I posted this problem at SB-forum in my post "Direct OCR Error" and gave them more info concerning my all-in-one printer and the software of this printer installed a bar called "Canon Easy-WebPrint" and this bar could be the problem.
Firefox doesn't have this bar, but I switched often between Firefox and MSIE, while I was running Sandboxie.
I'm waiting for a reply of Tzuk and if necessary, I'm going to uninstall this bar and see if there is an improvement. I'm almost 100% sure that this bar IS the problem.
Sandboxie is alot more important to me than this bar, which I don't use in practice.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #48  
Old April 26th, 2007, 10:32 AM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Sandboxie v2.86

I've started testing some real malware to see how well I am protected both against the malware and myself. Programs I commonly run are SSM OA, KAV and sandboxie. Then also as Erik challenged recovery.

I started with Killdisk, and this thing is about as nasty as it gets.

Both OA and SSM block it providing I am smart enough to not let it run. KAV even without PDM flat wouldn't let it run. Even when I said skip to it's alert of a virus it wouldn't let it run. I finally had to disable it.

When I ran Killdisk inside the sandbox, it failed. Sandboxie effectly protected me against it. Excellent.

THen I ran it an let it do it's evil deed to check on recovery. On reboot all I got was a fatal partition error. FDISR is out of the picture. Then I tried a simple restore with Shadow Protect and it also failed. I had to run DiskPart to delete the messed up partition that killdeed left behind. Then I was able to restore the Shadow Protect image.

This test also showed just how effective VMware machines are. I took a vm snapshot before the test, and while in the damage state of the disk, revert to the snapshot. Everything was perfect.

Pete
  #49  
Old April 26th, 2007, 10:47 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: Sandboxie v2.86

Quote:
Originally Posted by Peter2150
THen I ran it an let it do it's evil deed to check on recovery. On reboot all I got was a fatal partition error. FDISR is out of the picture. Then I tried a simple restore with Shadow Protect and it also failed. I had to run DiskPart to delete the messed up partition that killdeed left behind. Then I was able to restore the Shadow Protect image.
If I zero my harddisk instead of using DiskPart, will ShadowProtect recover my harddisk ?
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #50  
Old April 26th, 2007, 01:58 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,846
Default Re: Sandboxie v2.86

Quote:
Originally Posted by ErikAlbert
If I zero my harddisk instead of using DiskPart, will ShadowProtect recover my harddisk ?

If by zero it you mean format it no. I tried that first. I had to go in and use Diskpart to delete the partition.

BTW, neither Acronis True Image or Disk Director could do anything with until DiskPart was run. This is indeed one nasty dude.

But the bright side Sandboxie stopped it cold.
 

Wilders Security Forums > Software, Hardware and General Services > sandboxing & virtualization « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:51 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums