EQSecure V4 Beta, Morc calling Orson, come in Solcroft

Discussion in 'other anti-malware software' started by Kees1958, Mar 2, 2008.

Thread Status:
Not open for further replies.
  1. Trespasser

    Trespasser Registered Member

    Joined:
    Mar 1, 2005
    Posts:
    1,204
    Location:
    Virginia - Appalachian Mtns
    If you select your media player as a ForceProcess then any media file that you wish to play will open in a sandbox. This is according to one of the experts over at Sandboxie Forum. Personally, I've never tried it.

    Later...
     
  2. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    That is why I like policy sandboxes:
    - they allow DMR rights to be updated (e.g. mp3 files or wma files)
    - they allow media files ( e.g. mp3 or wma) downloaded with P2P programs to be run as untrusted.

    It is not an all or nothing solution. In 2006 SBIE could not do this, any members buying music and using SBIE?
     
  3. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    That is totally as expected.
     
  4. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Here is my testing.

    With latest SBIE, i used isolated IE to add 3 files in the Sandbox( Virtual HD) Desktop. One jpg, one avi and one exe. I then navigated to the sandbox> Virtual HD> Desktop and executed all one by one. jpg and avi files opened in image viewer and media player as un-isolated. Exe was isolated on execution.

    With EQS Sandbox, same testing: All( including exe) were un-isolated.

    GW, DW and SafeSpace will isolate all of them.
     
  5. Pedro

    Pedro Registered Member

    Joined:
    Nov 2, 2006
    Posts:
    3,502
    That is not ideal, but i would have to play with it for a while to see for myself. I haven't used it for a while, the new version is different.
    But aigle, although i agree, i don't know why one would navigate to the sandbox to play media files. I still agree that if that's the behavior, it's a bug or an unwelcome problem.
     
  6. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Hi, I don,t know the practical implications of it.
     
  7. Cerxes

    Cerxes Registered Member

    Joined:
    Sep 6, 2005
    Posts:
    581
    Location:
    Northern Europe
    Sandbox your imageviewer and mediaplayer?

    /C.
     
  8. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Cerxes! wat do u want to say?
     
  9. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    He means to sandbox the programs used to open the files (imgviewer and mediaplayer).
     
  10. Trespasser

    Trespasser Registered Member

    Joined:
    Mar 1, 2005
    Posts:
    1,204
    Location:
    Virginia - Appalachian Mtns
    That's what my above post suggested. In Sandboxie in Settings you have a listing called Forced Programs. There you can list programs that when executed open sandboxed. Windows Media Player if listed there in Forced Programs would open sandboxed when triggered by the media you wish to play.

    Geswall automatically lists most applications as untrusted. In Sandboxie you have to "tell" it that it's untrusted.

    Later...
     
  11. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    No, its not like this.

    Say i have a jpg image file downloaded from internet via isolated browser. I download and save it to desktop, and then double click on it to open. Now double clicking the image file will call my default image viewer to open the file. In case of GW n DW, the image viewer will be isolated automatically irrespective of the fact that u have added them in program list or not.

    I tried same with sanboxie, but here the image viewer was not isolated. But of course SBIE is different as a file downloaded on desktop goes to virtual HD desktop( so I have to navigate there manually to double click on it in order to open it).

    I think the problem here is that the file in case of SBIE is marked un-isolated as it is opened via explorer.exe that is trusted. Not sure though.

    I tried another thing. I opened a pdf file via isolated Free Commander and EQS sandbox launched foxit PDF reader as isolated.
     
  12. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    BTW isolated( sandboxed) applications have a thin blue border around, like SafeSpace etc, though the border here is not very clear and disappears many times.
     

    Attached Files:

  13. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    If EQS sandbox is the same as SBIE, I'll be more than happy.

    Anyway, there's something I found with v3.41: in the registry protection settings section, if you make a rule to monitor the startup status of all services (HKEY_LOCAL_MACHINE\SYSTEM\*ControlSet*\Services\*, Start) and try to disable a service via services.msc, eqs will show the popup and then freeze.

    http://img29.picoodle.com/img/img29/4/3/4/f_rpsm_1ab2540.png

    Anyone else able to reproduce the problem?
     
  14. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    I found some problems with reg module when I used it but I can,t be sure whether all these were actual bugs or some were juat my misunderstandings.
    Problem here is that u have no proper English forum to post about EQS and get help.
     
  15. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    It,s not the same, it,s SandboxEQS! :D Sure i am excited to see this feature.
     
  16. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    A little bit ridiculous, isn't it? Someone someday will wake up, I presume.
     
  17. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    It,s a one-man show( as I know) and is free. I really can,t expect too much from a single person and to be totally free.

    Also there are language barriers!
     
  18. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    I thought this was a team of gods :) Not just one? WOW!
     
  19. Ilya Rabinovich

    Ilya Rabinovich Developer

    Joined:
    Sep 13, 2005
    Posts:
    1,543
    Almost all the HIPS projects are one man show- there is no WOW here.
     
  20. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    BTW there is only one GOD, I believe.

    Ilya is right that most HIPS are one-man show.
     
  21. Alcyon

    Alcyon Registered Member

    Joined:
    Jan 16, 2008
    Posts:
    438
    Location:
    Montr?al, Canada
    :) Then replace the "WOW" by "I'm impressed".... and gods by elites...
     
  22. erreale

    erreale Registered Member

    Joined:
    May 2, 2004
    Posts:
    27
    Location:
    Italy

    what is it BTW?
     
  23. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    By the way:)
     
  24. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,164
    Location:
    UK / Pakistan
    Contrary to many gods!


    Edit: yep BTW= By the way
    Thanks Antarctica!
     
  25. xuesisi

    xuesisi Registered Member

    Joined:
    Mar 2, 2007
    Posts:
    71
    To there forum,you can get help...
    If you can't use chinese forum ,pls write your problems , I'll help u to ask EQS_Dev..


     
    Last edited: Mar 5, 2008
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.