![]() |
|
#101
|
||||
|
||||
|
After reading into this BufferZone seems like a rather good application. I grabbed a key and I think I will try this when I have some time. It may be the application I have been looking for.
__________________
Panda Security TRUSTED MOD Panda Cloud Antivirus + Rising PC Doctor + Common Sense My Security Blog: http://igl-security.blogspot.com/ |
|
#102
|
||||
|
||||
|
Quote:
I though about that but wondered if it would leave my documents open to any malware inside of bufferzone?
__________________
Shadow Defender + AppGuard |
|
#103
|
||||
|
||||
|
Quote:
I know, it's a little misleading. Probably, if malware was to run inside the bufferzone, it would be able to read those files now. I really don't give a hoot about that since I don't keep any important info in that particular directory. You basically want BZ to protect your system from getting infected. Any important stuff you need to attach via email you would have to move out of confidential files. I'm not an expert with the software by any means but it seems pretty good, along with a good free AV and you have a pretty secure setup. I also like SBIE and GeSWall which has simillar protection. Ice
__________________
Real time ....:BD Free On Demand .:MBAM |
|
#104
|
||||
|
||||
|
Bufferzone is leaking badly here and I dunno why as Boyfriend tested and has no leaks.
Uninstalled the Pro version and installed the free version and still seeing the same in files being created on the real system. If anyone else is setup for testing and willing to try out what I'm seeing then send me a pm.
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#105
|
||||
|
||||
|
I also see also the files being created in the real system like files that I download but with the extension of ".virtual". Its a small in size and you need to put this file outside the bufferzone to see the real file.
Please correct me if I'm wrong. Thank you..
__________________
Desktop (Win7 Pro x32): EMET, LUA+UAC, Returnil Laptop (Win 7 Ultimate x64): Avast Internet Security, EMET, Sandboxie Free, UAC Backup: Paragon HDM 2010 |
|
#106
|
||||
|
||||
|
I was planning on using this on a laptop but if it is leaking files then that defeats the purpose of having it. I think I'll just put Sandboxie or GeSWall on it instead.
|
|
#107
|
||||
|
||||
|
I looked up a review on YouTube and I did see it leak out what I think is a SpyEye trojan: -http://www.youtube.com/watch?v=AgWf15HsoJU-
Though it should do a rather good job teamed up with an AV/Anti-Malware
__________________
Panda Security TRUSTED MOD Panda Cloud Antivirus + Rising PC Doctor + Common Sense My Security Blog: http://igl-security.blogspot.com/ |
|
#108
|
||||
|
||||
|
Quote:
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#109
|
||||
|
||||
|
OK, I "think" I've got it sorted.
A setting under Configuration - Advanced Policy was to save all signed installers outside the BZ. Changing this setting to save all signed installers to "in Bufferzone" and no more elcrappo is being created on the real system. The third pic shows the exes that were created outside the BZ so they must have signed installers.
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
|
#110
|
||||
|
||||
|
That is good to know.
|
|
#111
|
||||
|
||||
|
Just checked the BZ Forum today. They have confirmed there is a problem with BZ, re: loss of Chrome bookmarks, extensions and preference settings when Chrome is sandboxed. Refers to latest rel of Chrome. They will have it fixed in the next release. No date given.
|
|
#112
|
||||
|
||||
|
I tried BufferZone on Windows 7 x86 and I couldn't figure out how to save files to the real system. The "help" says you only need to right-click on a file in the sandbox and select "move outside the sandbox" (or something like that), but that option did not appear on the menu. Did I miss something? I uninstalled it, but I would try it again if someone can explain this.
__________________
ut quod ego verus est maioribus quam ut quod est sanctus |
|
#113
|
||||
|
||||
|
I had a hard time working with files also. When I right clicked a chose "Move Outside BZ" it doesn't say where the file goes and I couldn't find it.
If you didn't have this on your context menu sounds like the install went wrong some where.
__________________
~Rilla927~
|
|
#114
|
||||
|
||||
|
Not sure about Chrome but in IE I had to save my bookmarks outside of BZ. Then going back into a BZ session, the bookmarks are there. I wish someone could tell me how to save the bookmarks in BZ permanetly.
About saving files, they would be in the location where you would normally save stuff in. Then going to that directory, you would see the file with a little bufferzone icon on it. Just right click and select move outside of BZ and it will remove the icon and remain in that directory. However, before doing that, I would scan the file with your AV etc.... Ice
__________________
Real time ....:BD Free On Demand .:MBAM |
|
#115
|
||||
|
||||
|
Let me try to explain
When a file is downloaded into Bufferzone a BZ-link is placed in the folder you put it, e.g. NEW_FILE.doc.virtual while the real file is put in the sandbox folder (C:\Virtual\Untrusted) with the name NEW_FILE.doc When you click on the BZ-link file and move it out of the buffezone, the real file is moved to the place where the BZ link was After download C:\User\Kees\Downloads NEW_FILE.doc.virtual C:\Virtual\Untrusted\ NEW_FILE.doc After the move out of BZ C:\User\Kees\Downloads NEW_FILE.doc C:\Virtual\Untrusted\ empty |
|
#116
|
||||
|
||||
|
Quote:
I know the cookies are allways put in BZ sandbox and I thought the favorites folder was not cleared when emptying the BZ sandbox. Not using it right now, so can't test it for you. |
|
#117
|
||||
|
||||
|
Quote:
I just tested it to be sure and it does remove it, if you select all 3 items to empty in the BZ. It's really not to much of a hassle to save the link outside of BZ and then go back into a BZ session and the link is there. Ice
__________________
Real time ....:BD Free On Demand .:MBAM |
|
#118
|
||||
|
||||
|
Quote:
Yes, under the covers this is how it's done. thanks Ice
__________________
Real time ....:BD Free On Demand .:MBAM |
|
#119
|
||||
|
||||
|
Quote:
I will have to reinstall and try this. I'm also curious about how the sandbox effects other security software. Is it possible for resident antivirus to monitor download activity in the sandbox? What about something like Zemana Antilogger - can it control key/screen logging activity? Seems to me that a sandbox could actually reduce some security functionality.
__________________
ut quod ego verus est maioribus quam ut quod est sanctus |
|
#120
|
||||
|
||||
|
Quote:
I thought the same with BZ, SBIE etc... but your AV will still see the infection and remove it regardless if it's in the sandbox or not. I just tested BZ with the eicar file and MSE removed the infections like it should. Ice
__________________
Real time ....:BD Free On Demand .:MBAM |
|
#121
|
||||
|
||||
|
I put it on a laptop and so far I like it. I also have Avira and Online Armor on it and so far there are no conflicts. BufferZone works well with the other programs.
|
|
#122
|
||||
|
||||
|
So how is it running on everyones machine?
__________________
Panda Security TRUSTED MOD Panda Cloud Antivirus + Rising PC Doctor + Common Sense My Security Blog: http://igl-security.blogspot.com/ |
|
#123
|
||||
|
||||
|
Quote:
BZ pro with MSE on win7 32 using IE 8 and it's running great so far. Ice
__________________
Real time ....:BD Free On Demand .:MBAM |
|
#124
|
||||
|
||||
|
Quote:
|
|
#125
|
||||
|
||||
|
Quote:
Even though no exes are created on the real system with that extra setting there still seems to be empty folders and dead shortcuts all over the place after emptying the bz? I run a malware sample that drops both malware and supposed legit apps and let it run for several minutes then delete the BZ and reboot. I conduct a search with Agent Ransack to show all files/folders created today and there's nearly 700 empty folders, .dat files and dead virtual shortcuts still around. Could be my setup as I'm seeing the same with Geswall but not with Sandboxie or Defensewall.
__________________
Lean, Mean and Clean! Sandboxie, Buster Sandbox Analyser, Returnil 2008, Microsoft Virtual PC 2007 SP1, Drive Snapshot
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|