How to tell what a payload does

Discussion in 'other security issues & news' started by lunarlander, May 7, 2021.

  1. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    Hi,

    The last couple of days, my Edge keeps on closing by itself. I guess it was an attack of some sort. But I don't know what the payload can do. All I can do is erase Sandbox and reboot. I don't think there is any way to know what the payload can do, but I'll ask here anyways.
     
  2. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Last edited: May 7, 2021
  3. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
  4. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    What do you mean by this?
     
  5. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    I use Sandoxie. It provides a virtualized environment for your browser. Their sandbox folder is called c:\Sandbox. So when something bad happens to the browser, you are supposed to delete the sandbox and all the stuff the attacker installed ( which would be restricted to c:\Sandbox, as the attackers see it as c:\ ) will be gone.

    I also reboot the machine as their payload is also active in memory, regardless if they managed to gain persistence.
     
  6. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    Got it, thanks. I was just seeking clarification. Maybe your question should be posted in the relevant Sanboxie thread?
     
  7. roger_m

    roger_m Registered Member

    Joined:
    Jan 25, 2009
    Posts:
    8,626
    It is exceptionally unlikely that it is an attack. It will a bug of some sort or a problem with an extension.
     
  8. lunarlander

    lunarlander Registered Member

    Joined:
    Apr 30, 2011
    Posts:
    326
    "It will a bug of some sort"

    I am beginning to think so too.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.