Sandboxie: What do you sandbox, other than your browser?

Discussion in 'sandboxing & virtualization' started by Tyrizian, Jun 29, 2013.

  1. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    I think so too.:)

    Bo
     
  2. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    :D :thumb:
     
  3. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    Yes.

    Bo
     
  4. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Thank you very much, this helped out a lot :thumb:
     
  5. guest

    guest Guest

    Wouldn't it be better just to use a image program, then you do not have to worry about all this nonsense, if you get infected just re-image the drive, seems a lot simpler to me, the trick is to "KNOW" when you are infected
     
  6. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    Sounds to me like you are still getting infected. The trick or goal should not be "knowing when you are infected" in order to reimage, it should be preventing getting infected. And that's what Sandboxie is all about.

    Bo
     
  7. guest

    guest Guest

    "Sounds to me like you are still getting infected"

    Not the case, I haven't re-imaged for an infection but for one time "ever"
    and that was several years ago "if memory serves me right", I am preventing infection by the type of OS I am running, but if I do get infected it is far easier to just re-image than to deal with programs that setup "sand-boxes, Force-fields or any of the other type of _____
    but to each his own, Cheers:D
     
  8. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    The way I see it is, if you bought the software or have an interest in the software (Regardless of what you're using), that person should take advantage of every feature that they can or want to utilize, have it be Sandboxie, imaging program, both, etc..

    To me, it really doesn't matter, as long as you're truly happy with your own "Personal" setup/the way you run thing's.

    Everyone is different
     
  9. CrusherW9

    CrusherW9 Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    517
    Location:
    United States
    I have a primary sandbox for all my usual stuff. This is all of my browsers, pdf reader, torrenting program, media player, office, etc. I have start/run restrictions and internet access restrictions for everything in this sandbox and my media partition is blocked. I have a secondary sandbox with the exact same configuration in case I want to separate two programs. I have a testing sandbox that can't access the internet or my media partition. Lastly, I have a fourth sandbox for any other drive letter that cannot access the internet or my media partition.
     
  10. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    I only sandbox new or untrusted programs. Doing so for my regular programs is too much of a chore for any likely infections ([virtually] non-existent), even when compared with EMET.
     
  11. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Anyone Sandboxing Windows Live Mail (Client)?

    If so, getting errors?
     
  12. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    I dont use it, I uninstalled Windows Live on my W7 but there is a Software compatibility setting for it, make sure it is ticked. What error are you getting?

    Bo
     
  13. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    My settings:
    Sandbox Settings > Applications > Email Reader > Windows Live Mail selected
    Sandbox Settings > Program Start > Forced Programs > Added wlmail.exe
    Sandbox Settings > Restrictions > Start/Run Access > Added wlmail.exe

    With the above settings, Windows Live Mail somewhat runs in Sandboxie, but doesn't get past the loading screen.

    At that point, I get this error message.

    WLM.jpg

    It's probably one of these that's causing it:

    1. I'm missing something in my configuration file.
    2. I'm also trying to run "wlmail.exe" under EMET 4
    3. Sandboxie (Current) isn't compatible with the newer version of Windows Live Mail.
     
  14. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    If I was you, I would right click on the Windows Live mail icon and choose to run it sandboxed in a "default" settings sandbox where all programs are allowed to start and run.

    Bo
     
  15. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Did that and I get this...

    WLMSec.jpg
     
  16. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    If this is an actual problem, I'm gonna report it to tzuk ASAP.

    But, I get the feeling it might be on my end (Configuration incomplete, Windows Live Mail added under EMET, etc.)
     
  17. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    I know I'm bouncing back and forth on questions here, which I apologize.

    But, do you think it would be a good idea to select/add "Delete Invocation" to my above USB configuration?
     
  18. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    No need to apologize, I love talking about Sandboxie.:)

    Personally, I set all sandboxes to delete on closing. The only excepsion for that is when I install a program in a sandbox and want to keep it for a while.

    What happenned to this setting, "NotifyInternetAccessDenied=y". Did you remove it?

    Bo
     
  19. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    It might be a conflict with SBIE or there is a need for a workaround when you are using EMET, SBIE and Windows Live mail. I never used EMET so cant help you on that. Search in the SBIE forum about Windows live mail and afterward, post about the problem (including the picture). I am sure Tzuk will appreciate it if you do so.

    Bo
     
  20. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Ok, cool :thumb:

    Yeah, I'll add Delete Invocation then

    The setting "NotifyInternetAccessDenied=y" in my configuration is still there, I just happened to quote one of my previous posts, that didn't have that line in it at the time.
     
    Last edited: Jul 1, 2013
  21. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    I'll do that :thumb:

    Thanks
     
  22. carlito77

    carlito77 Registered Member

    Joined:
    Aug 4, 2010
    Posts:
    14
    Bbesides my browsers, under Sanboxie I set the Windows folder to read only, to limit access to my system32 host files, and Sandbox just about every program that access the Internet
     
  23. Escalader

    Escalader Registered Member

    Joined:
    Dec 12, 2005
    Posts:
    3,710
    Location:
    Land of the Mooses
    This is the most current thread I found on Sandboxie.

    Attached are 2 files:

    1) shows my FW detecting Sbie.Svc.exe attempting to intercept user key strokes. Why would it do that?

    2) the second is a list from the website showing software that has known conflicts with Sandboxie. Most have mitigations like turning off real time scanners. What do you guys think of that?

    I wanted to post this first over at their forum but they haven't got the file attachment upload feature.
     

    Attached Files:

  24. guest

    guest Guest

    I think it's good that incompatible programs are listed instead of lying and say the product is absolutely compatible with anything while it's not true. And I think it's good that the solution is as simple as turning off the AV.

    I think they need to implement that feature in the support forum.
     
  25. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    6,941
    Location:
    USA
    To be clear, 'guest' is using the term "re-image" when he should be saying "restore".
    Imaging a disk is the process of making a backup.
    Restoring a disk is the process of reverting to a healthy image.
    To re-image when you get infected would be to make a backup of an infected disk.
    HTH
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.