Data Stealers and SBIE

Discussion in 'Sandboxie (SBIE Open Source) Plus & Classic' started by soccerfan, Apr 21, 2023.

  1. soccerfan

    soccerfan Registered Member

    Joined:
    Oct 15, 2007
    Posts:
    585
    A post by @cruelsister today on malwaretips.com mentions data stealers and SBIE. Link here:
    https://malwaretips.com/threads/comodo-firewall-component-being-ignored.122497/post-1036735
    This is an excerpt:
    Question for @cruelsister or @DavidXanatos or others:
    If one has proper start-run restrictions in place in a sandbox,
    how can a data stealer (downloaded into that sandbox) spawn anything,
    because it cannot run (due to those restrictions) in the first place?
     
  2. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    If it's able to run then I suppose it can spawn other processes. But if you have configured start-restrictions, it shouldn't even be able to run in the protected sandbox. No matter if it's launched by the user or exploit.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.