Sandboxie 3.40 Released.

Discussion in 'sandboxing & virtualization' started by TheKid7, Sep 30, 2009.

Thread Status:
Not open for further replies.
  1. inka

    inka Registered Member

    Joined:
    Oct 21, 2009
    Posts:
    426
  2. nick s

    nick s Registered Member

    Joined:
    Nov 20, 2002
    Posts:
    1,430
    I don't see much Sandboxie fanboy hyperbole in this forum. Many claims of Sandboxie bypasses have been proven false...because, well, the user did not understand Sandboxie. Is it a Sandboxie flaw that I cannot run explorer.exe or Microsoft Office sandboxed? Or purposefully copy files from the sandbox to the host and not have the host notice? The true bypasses have been discussed rationally and reproduced. Since Sandboxie does application isolation, there will continue to be bugs and conflicts with new or evolving applications and malware.
     
  3. inka

    inka Registered Member

    Joined:
    Oct 21, 2009
    Posts:
    426
    Thanks nick & ssj100. As a long-time reader of the Wilder's forums, I respect that you're straight shooters. Agreed, in nearly every reported instance a perceived bypass is just user confusion. I wouldn't fault "bugs"; I appreciate that the app represents a growing/evolving project.

    Those links I pasted point to weaknesses (re OP's question) and they underscore the dev's attitude in dismissing customer wished-for hardening features. His notion of "good enough" and his apparent position "that's outside the scope of a sandboxing app" (or, "it isn't worth the bother") don't sit well with me.

    It's "just" a sandboxing app? It's an end-of-life product (no 64-bit evolution planned)? Regardless, I believe its lack of self-protection from termination is a considerable weakness, as is its lack of security by obfuscation (non-predictable ini filename/location & randomization of the launched service process name).
     
  4. arran

    arran Registered Member

    Joined:
    Feb 5, 2008
    Posts:
    1,156
    ~ Snipped as per TOS ~ there have been numerous threads and discussions in the passed on these forums about certain Pocs bypassing sandboxie.

    If no known malware can escape out of the sandbox what possible chance does malware have of terminating sandboxie?

    But I suppose malware may be able to terminate sandboxie if it was running outside of the sandbox, but thats why we also have things like malware defender for system wide protection.

    Sandboxies job is to only control the malware inside the sandbox not control the behavior of things running outside of the sandbox.
     
    Last edited by a moderator: Oct 29, 2009
  5. Doodler

    Doodler Registered Member

    Joined:
    Dec 23, 2007
    Posts:
    237
    Very true. And I, for one, am thankful for his efforts!
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.