![]() |
|
#1
|
|||
|
|||
|
What's the use of having security software if malware can bypass it, e.g., breaking out of Sandboxie? I had Sandboxie installed for a few days, but uninstalled it after reading about how malware can break out of the sandbox. I mean, there's no sense using Sandboxie if malware is going to break out of it and infect my real system anyway. IMHO having malware that can bypass security software defeats the purpose of having security software in the first place. Security software has no real purpose unless it can guarantee 100% security. I can't help but dream of a sandbox that is impenetrable to even the most advanced malware.
|
|
#2
|
||||
|
||||
|
Nothing can guarantee 100% safety on the internet. Why? Because it is all up to the user.
If you're an extremely risky surfer you will come across those types of malware eventually. And the opposite can be said if you only visit sites you know and trust. A Sandbox or a program like DefenseWall HIPS do not guarantee 100% safety as well, they are like a safety net. The same can be said for firewalls, antivirus', etc. In order to be a risky surfer and maintain a high level of security you need a layered approach and no 1 product can do that. But even in having a layered approach something may eventually slip through And there is a purpose to security software, it protects you 99.99% of the time you are out surfing on trusted, somtimes even malicious sites...Downloading something you shouldn't be or visiting an unsafe website is another story.
__________________
Regards, Brendan. |
|
#4
|
||||
|
||||
|
Quote:
Quote:
![]()
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#5
|
|||
|
|||
|
Quote:
You just have to be prepared for anything and take nothing for granted. This is not to assume a doomsday approach to using the internet. It does assume that you are prepared in case of a mishap. ---- rich |
|
#6
|
||||
|
||||
|
Yeah, I thought I should edit my post to say that it is not 100% guaranteed to even be safe on trusted sites anymore. But you do have to agree - being on a trusted site is a lot safer then being on a warez site downloading random applications that catch your fancy or visiting a crack site (places I know that my friends get infected)
![]() Plus I brought up some discussion ![]()
__________________
Regards, Brendan. |
|
#7
|
|||
|
|||
|
Quote:
Sure I could use Start/Run access to keep possible malware from running. However, I would be unable to run a downloaded game to see if the game is malware-free. Is there any software out there that lets you analyze a file's behavior without messing up your system? |
|
#8
|
||||
|
||||
|
What's the use of wearing seat belts and crash helmets, when people continue to die in road accidents?
What's the use of having a police force, since they've never managed to eliminate crime? Seriously, is this question even worth asking? |
|
#9
|
||||
|
||||
|
A VM and Zsoft Uninstaller and besides you could create another sandbox to install the game and monitor with Zsoft?
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#11
|
||||
|
||||
|
Quote:
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#13
|
||||
|
||||
|
Quote:
Nice sentence Eice ![]() |
|
#14
|
||||
|
||||
|
Quote:
Hi Badget I know why you posted this. you have been reading the other thread http://www.wilderssecurity.com/showthread.php?t=239942 Don't let it put you off using sandboxie. Using sandboxie is much better than using nothing at all. Even tho it is possible for malware to bypass sandboxie and cause permanent damage, the fact remains that no one knows of any such malware which indicates that there is very few malware samples out there if not any atm. Quote:
Franklin when I post about sandboxie its nothing personal, so don't take it as attack, its just my opinions. This start run access setting in Sandboxie which every one Raves on about is nothing new. Even a very Basic hips program can achieve this. If you are only using Sanboxie to prevent executables from launching in the first place then why use sandboxie?? all you really need is a simple anti executable hips program. One of the main reasons why you use a sandbox program like sandboxie is so u can run things in it without the things inside affecting the rest of your system. Which Sandboxie is unable to do, Well not properly any way... Last edited by arran : May 1st, 2009 at 05:07 AM. |
|
#15
|
|||
|
|||
|
Quote:
When we bought our last house (11 years ago), I got a free service to check your 'resistance' against burglary. The time it took to break into our house varied from 2 to 6 minutes. Especially the door between the garage and our house was vulnarable (wrong lock plating on a very strong lock, made it easy to penetrate). I took counter measures, so it would last at all possible entries at least 6 minutes and one easy to access room at the first floor 8 minutes. Also placed auto switch lights with movement sensors at the most likely places. According to the Dutch police a burglar on average wants to spend no more than 4 - 5 minutes to open an entry. So with the 'hunt' theory in mind (to survive an attack of a lion, you do not have to outrun the lion, only other people chased by the lion), we have settled for an assuring level of security (in our mind). We live in a reasonable safe area, so the specialist said, we did not need 10 minutes resillience time (my wife first asked this to him), because our neighbours problably did not take these additional counter measures. PC security is about the same, determine some base line of protection level to ensure a minimum threshold for intrusions. Depending of your knowledge you choose the security applications suited for that expertise level. Also the mix of applications to use depends on your behaviour on the digital highway. So when you have removed the locks of your house, because nothing is 100% safe, I would say YES (it is useless). In all other circumstances, I would say NO (it is usefull). Sandboxie is one the most efficient ways of reducing the attack surface of your PC, I would re-install it. Regards Kees Last edited by Kees1958 : May 1st, 2009 at 04:56 AM. |
|
#17
|
|||
|
|||
|
I think malware that infects the system via browser without user intervention is almost impossible to escape from sandbox.
If you're talking about downloaded files that you have downloaded from a warez site and you run it sandboxed...then yes...there is a possibility. But if you know that you have downloaded a file from an untrusted site, then i think that you should take all possible measures. Personally when I want to run such a file...I enable shadow mode with shadow defender...there are other similar products...and then run the file sandboxed (sandboxie)( having always the latest image made with paragon around ). You never know and since nobody can provide 100% security...you can make it 100% damage free to run the file. As you have noticed I have not used any traditional security software. Those are for every day use. |
|
#18
|
||||
|
||||
|
Quote:
You read malware can break and and infect the real system. Where did you read it. Who was the author and what was the malware? |
|
#19
|
|||
|
|||
|
Quote:
![]() |
|
#20
|
|||
|
|||
|
Quote:
Next point/question: Why do people think that this 100% security (or as close as you can get to it) must come from one security app such as SandBoxie? No matter what a vendor might claim, no security app, suite or package does everything. Regarding Sandboxie. I'm trialling Sandboxie on one of my systems and am quite impressed with it, but there is no way I would ever expect it to stand alone and totally secure my system. There is no perfect code. Sooner or later, someone will find a way to defeat Sandboxie. The vendor will fix that problem, then we'll do it all over again. Just about every good security app has gone through that process. IMO, Sandboxie is at its best when it's used to isolate those apps that are likelly to open or make contact with malicious code (the attack surface) from the rest of the operating system. The OS itself should still be protected by the same software the user would have been running if they didn't have SandBoxie. On my system, SSM protects the OS itself while Sandboxie isolates the attack surface. If Sandboxie is somehow bypassed, any malicious code will have to defeat SSM and a default-deny security policy, extremely unlikely to happen.
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come. |
|
#21
|
|||
|
|||
|
Quote:
?you use preventative controls to as best you can vastly reduce the number of malware that can affect your system... the use in doing so is that it's a lot cheaper (in time/energy/etc) to prevent the malware affecting your system than it is to correct the problem ('an ounce of prevention is worth a pound of cure')... prevention and correction are your only options so it makes sense to use the option that costs you the least as often as possible... since nothing is perfect, you also need detective (to detect when prevention has failed) and corrective controls... you need them because your dream of an impenetrable sandbox will always be just a dream... |
|
#22
|
||||
|
||||
|
Quote:
Remember the htaaa, htaab, htaac, stop, stop2 tests from the other thread? when I tested them in sandboxie I tested them with Drop my rights and it made no difference. In regards to sandboxie blocking things from accessing the internet that has also been bypassed as well with the http://www.firewallleaktester.com/leaktest26.htm test. In regards to sandboxie emptying the sandbox and deleting malware, I agree that it is good at flushing the toilet after each browsing session. However there are better alternative methods like preventing such files from being downloaded in the first place. When I was using sandboxie before I was using firefox with no script and cslite blocking all cookies and I was using admuncher and I had the offline cache storage set to 0 mb By doing all of this nothing gets saved to hard disk no files nothing. So as a end result there was never anything there for Sandboxie to delete. Another method is by using Malware Defenders File rules. which can prevent your browser from creating files. If new files can't even be downloaded and created in the first place, then one would assume it would be Impossible to get infected by malware.
__________________
Sandboxie | Malware Defender | Admuncher | Kerio 2.15 | Macrium Reflect | Nat Router | TrueCrypt
FF Add On's | BetterPrivacy | Ghostery | Noscript | RandomUserAgent | Perspectives HARDENING TOOLS | Seconfig XP | WWDC | Security&Privacy | SafeXP | XP-Antispy | Bug Off COMMAND AND CONTROL |
|
#23
|
|||
|
|||
|
Quote:
__________________
Nick |
|
#24
|
||||
|
||||
|
Nick s How are you meant to load web pages if you are blocking internet explorer??
It is quite common for malware to access the internet using your web browser and what I am saying is that sandboxie can't prevent this. That test is also able to communicate outside of the sandbox and is able to launch your web browser if it is not running.
__________________
Sandboxie | Malware Defender | Admuncher | Kerio 2.15 | Macrium Reflect | Nat Router | TrueCrypt
FF Add On's | BetterPrivacy | Ghostery | Noscript | RandomUserAgent | Perspectives HARDENING TOOLS | Seconfig XP | WWDC | Security&Privacy | SafeXP | XP-Antispy | Bug Off COMMAND AND CONTROL |
|
#25
|
||||
|
||||
|
OP is right about Sandboxie it use to work great, but bad two files that PrevX had popped up reporting there was cloak-malware in that C:\Sandboxie folder. So the way this software is suppose to work it when you terminate it everything get destroyed but not so..
No matter what you need security software if you're going to use a browser to access the internet. You can block all bad tracker cookies, run virtual OS go remote into the box thus get on the internet. Downloading apps with embedded (malware/trojans/bots to take off) and do damage the coders are getting smarter and software can no crash security tools from trying to update their dbase or even run. I've seen it.. None can be 100% but you can come very close to it.. Maybe we should go back to the days of RAMDISK and store the internet cache on that. When you exit out the cache would clear itself.
__________________
EnGenius ESR-9850 (2) AP / Router | NAT | SPI | DoS | PoD | ICMP | WPA2 | AES | 100mbps |802.11G | 802.11N |1000mbps | Windows 7 | Ultimate | 32-bit |64-bit | Workgroup | Homegroup | 10 Clients | WF | MSE | UAC | DEP | |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|