Sandboxie Acquired by Invincea

Discussion in 'sandboxing & virtualization' started by ad18, Dec 16, 2013.

Thread Status:
Not open for further replies.
  1. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    I believe your thinking is right. In the Miscellaneous section, when I create a new sandbox I usually untick or leave unticked most settings there. I leave ticked the ones for lingering programs, block ports and exclusions for Immediate recovery. The only setting there that has to do with security is Block ports.

    About the browser settings. In my view, the less you check there, the better off you are. I only allow out bookmarks. But I believe users should allow out via this settings whatever is needed for them to have a comfortable and convenient browsing session.

    Bo
     
  2. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    I've only found my IE sandbox helped by [+] Default list of Lingering Programs.
    I don't Enable Immediate Recovery.
    I only allow bookmarks and NoVirusThanks.
    And, do not opt Direct Access to qWave driver since, not knowing why I need to.
    And, do not opt Default list of blocked TCP/IP ports since, not knowing why I need to, what is Improved.
    [​IMG]

    So, am I opening "hole" by not opting Default list of blocked TCP/IP ports.
    Why BlockPort=137-139,445 & BlockPort=*,80,8080
    I'll have to google > block outgoing communications on SMB/CIFS ports....and smbclient
    (smb, over-my-pay-grade). Maybe, I should [+] Default list of blocked TCP/IP ports.
     
    Last edited: May 14, 2017
  3. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    The setting is for blocking access to the Windows file sharing service. By not using the setting you are not opening a hole, the hole is already open. The setting closes the hole. I dont use that service at all, so for me, is a good restriccion to use.

    Bo
     
  4. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Ahh, blocking access to Windows file sharing.
    Yeah, I don't share with other users, or other devices.
    Okay. I hear ya'. [+] Default list of blocked TCP/IP ports.
    Thanks!

    Edit: @bo elam
    is this different block file sharing?
    350.png
     
    Last edited: May 14, 2017
  5. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    I also block file sharing via Control panel. My W7 is in Spanish but should be easy for you to figure out how to find in your PC by looking at the address bar in the picture.

    Sin título.jpg

    Bo
     
  6. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    I think your pic is activate detection of networks?
    351.png
    So, Default list of blocked TCP/IP ports is different than Block network files and folders?
     
  7. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    I don't see Network discovery in my PC, picture. Perhaps is totally disabled or didn't come with it.

    Bo
     
  8. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    my high school spanish :argh:
     
  9. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,805
    Location:
    .
    Network discovery = Detección de redes

    So both of you have equivalent pics. Bo has network discovery on, while bjm_ not.
     
  10. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    You are right. It translates totally different but I can see now they are one and the same.

    Bo
     
  11. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    I deactivated/turned off Network discovery. We are on same page now :).

    Bo
     
  12. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    and I've set [+] Default list of blocked TCP/IP ports, now :).
     
  13. guest

    guest Guest

    and you can also remove smb1.0 in Program & Features, home users don't need it.
     
  14. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Removing smb v. 1.0 and disabling services (or fileshare) is much better solution. SBIE only block outgoing network requests and only for sandboxed applications. It won't block incoming connection requests and won't protect your system from infected computers in your network.
     
  15. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Where is that section (for an existing sandbox)?
     
  16. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    @guest Can or should?
     
  17. guest

    guest Guest

    Personally, i would say "must" :D
     
  18. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,805
    Location:
    .
    By removing this protocol, wouldn't my three pcs home network will stop file sharing/network shares?

    Sorry for the OT.
     
  19. guest

    guest Guest

  20. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,644
    Location:
    USA
    SMB1.0 is a legacy feature, we we have a couple of NAS drives that won't work without it. The nice thing is if you turn it off and things don't work, you can just turn it back on.
     
  21. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    Navigate to:
    Sandbox settings>Applications>Miscellaneous

    Bo
     
  22. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,805
    Location:
    .
  23. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    Sandboxie beta 5.19.4 has been released. This beta solves the messages Sandboxie users in W8 get after installing May's Windows update KB4019215.
    http://forums.sandboxie.com/phpBB3/viewtopic.php?f=61&t=24329#p127601

    Bo
     
  24. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  25. bo elam

    bo elam Registered Member

    Joined:
    Jun 15, 2010
    Posts:
    6,147
    Location:
    Nicaragua
    You are welcome, Minimalist. Beta works great in W7 32 bits.

    Bo
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.