Sandboxie-Plus v1.3.1, v1.3.2

Discussion in 'Sandboxie (SBIE Open Source) Plus & Classic' started by DavidXanatos, Aug 20, 2022.

  1. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,335
    Location:
    Viena
    This build adds 2 new isolation mechanisms to increase security of hardened boxes, hence boxes previously designated hardened will now be downgraded in the UI to normal, and the hardened icons will be used to the new box type.
    The first isolation mechanism "SysCallLockDown=y" limits the amount of ntdll syscalls which are executed with the original process token to a list of known approved syscalls
    The second isolation mechanism "RestrictDevices=y" leverages rule specificity to limit the accessible driver/device endpoints to a list of known required endpoints plus whatever the user opens using the resource access rules.



    Download: https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.3.1
    Download: https://github.com/sandboxie-plus/Sandboxie/releases/tag/v1.3.2

    Changelog v1.3.2
    Added
    • added icons to sub tabs in the box options dialog
    • recovery and message pop-up menu options are not persisting across UI restarts any more
    • added new box color, a white box indicates that its not really a sandbox and is displayed when the user specified OpenFilePath=* or alike
    Changed
    • Sandboxie no longer issues message 1301 when forced processes are temporarily disabled
      -- the message can be re-enabled with "NotifyForceProcessDisabled=y"
    • reworked the "Open COM" checkbox mechanism in the plus UI
      -- Now it uses a template and it can also keep COM closed while OpenIpcPath=* is set
    Fixed
    • fixed compatibility issue with Proxifier #2163
    • fixed encoding issue with Korean translation #2173
    • fixed issues with update available message


    Changelog v1.3.1
    Added
    • added ability to switch fusion theme independently of the dark theme
    • added ability to download updates from the support page
    • added missing system calls to the hardened box type 88bc06a b775264 04b2377 (thanks Mr.X)
    • added search box to the Plus UI Settings and box option dialogs #2134
    • added Korean translation to the Plus UI #2133 (thanks VenusGirl)
    • added grouping to sandman tray menu #2148
    Changed
    • improved info label
    • the look of vintage mode is even more vintage
    • reloading the configuration with the Sandman command "Options -> Reload ini file" now updates the list of approved syscalls
    • made rule specificity more specific, now a rule with less wildcards overrules a rule with more wildcards
      -- Note: tailing wildcards are evaluated separately
    Fixed
    • fixed issue with displaying sandbox configuration #2111
    • fixed flashing issue when switching views #2050
    • fixed inconsistencies with various checkboxes in the Plus UI ef4ac1b 06c89e3
    • fixed a certificate validation issue 238cb44
    • fixed issue with "UseRuleSpecificity" setting #2124 file.c#L965-L966
     
    Last edited: Aug 30, 2022
  2. soccerfan

    soccerfan Registered Member

    Joined:
    Oct 15, 2007
    Posts:
    561
    Everything works smoothly so far in v1.3.1 (portable) :thumb:

    (1) Thank you for making rule specificity more specific.
    Now, privacy-box(blue) and security+privacy-box(red) can use identical added NormalFilePath lines.

    (2) I kept the following ApprovedNtSyscalls in GlobalSettings from v1.3.0 sandboxie.ini.
    Code:
    [GlobalSettings]
    .
    .
    ApproveWinNtSysCall=OpenKey
    ApproveWinNtSysCall=OpenKeyEx
    ApproveWinNtSysCall=CreateKey
    ApproveWinNtSysCall=DeleteFile
    ApproveWin32SysCall=GdiDdDDI*
    ApproveWinNtSysCall=SetInformationFile
    ApproveWinNtSysCall=TraceControl
    ApproveWinNtSysCall=NtTraceEvent
    ApproveWinNtSysCall=OpenDirectoryObject
    ApproveWinNtSysCall=OpenSymbolicLinkObject
    ApproveWinNtSysCall=CreatePrivateNamespace
    ApproveWinNtSysCall=AlpcCreateSecurityContext
    ApproveWinNtSysCall=AlpcConnectPort
    ApproveWinNtSysCall=AlpcConnectPortEx
    ApproveWinNtSysCall=AlpcAcceptConnectPort
    
    Are they now included in v1.3.1 and, if so, can these lines be deleted from my ini?
     
  3. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,121
    Location:
    UK
    What is this David ?
    Screenshot 2022-08-20 150941.jpg
     
  4. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,940
    "this" is not new, its content of used folder. turn the view off.
     
  5. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,121
    Location:
    UK
    I never turned it on.
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    BTW, I think it's so funny. Seems like yet another company has come up with the sandboxed browser concept, just like Invincea and Bromium did, they already secured $100 million in funding. Seems like Sandboxie is a much cheaper solution to me, perhaps you can build a Sandboxie Pro version for companies? :p

    https://talon-sec.com/product/
     
  7. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,940
    i had it by default when trialing the plus, maybe default for new boxes or you upgraded from a much older build where it was not available.
     
  8. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,121
    Location:
    UK
    In case anyone else comes across it, it is turned off or on by clicking on View.. show file panel.
     
  9. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Um, what does Use Fusion Theme do?
    I'm not seeing difference w/wo Use Fusion Theme?
     
  10. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,335
    Location:
    Viena
    its the generic Qt desktop theme that is used as base of the dark mode, so you only see a difference when not in dark mode.

    upload_2022-8-20_21-34-25.png


    upload_2022-8-20_21-34-41.png

    see the difference


    the normal windows theme on windows 11 RTM not 11 22H2 suxxx big times

    upload_2022-8-20_21-38-43.png

    upload_2022-8-20_21-39-24.png

    the fustion theme looks much better :D

    and windows 11 22H2 for good measure:

    upload_2022-8-20_21-43-23.png
     
    Last edited: Aug 20, 2022
  11. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    I'm not in "Dark Mode". I'm Vintage View - Qt/100 - W10
    png_15679.png
     
    Last edited: Aug 20, 2022
  12. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,335
    Location:
    Viena
    vintage view in 1.3.1 uses the old windows style thats yet an other one
     
  13. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Okay. Thanks
     
  14. algol1

    algol1 Registered Member

    Joined:
    Aug 10, 2020
    Posts:
    343
    Location:
    Vienna, Austria
    2 brief observations:
    1. Don't know exactly when this started, probably since v.1.3.0 - but when loading Sbie at bootup there will now be a short period when the tray-icon intermittently changes to full-status as if a sandbox had already been started whereas at that point my system doesn't (shouldn't) willfully open any sandboxed process.

    2. Unfortunately I see new problems with Opera coming up the horizon. Whereas "production-version" v.90 will operate flawlessly - upcoming Developer-version v.91 all of a sudden will produce "hundreds" of "immediate-recovery"-popup-messages, mostly aimed at "data"- and "cache"-subDir of Opera itself, without having intentionally downloaded one single actual file and thereby completely overwhelming the user with popups making it practically impossible to discriminate between those unintended "artefact-downloads" and real downloads by the user waiting for intentional recovery.
     
  15. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,244
    Using Sandboxie Plus 1.3.1 and still getting a 'There is a new build of Sandboxie-Plus available'.


    1.JPG
     
  16. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    see if Sandboxie update (1.2.8b) was downloaded to your AppData\Local\Temp folder.
    png_15694.png
    Also for improved reliability you can check the downloads on the project homepage: Downloads | Sandboxie-Plus where only known good builds are posted about a week or two after the GitHub release.
     
    Last edited: Aug 22, 2022
  17. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,244
    AppData\Local\Temp is empty. Downloaded v1.3.1 today from Github.
     
  18. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    try machine Restart or SandMan restart. Exit SandMan -> call SandMan.
    I reproduced There is a new build of Sandboxie-Plus available by calling 1.2.8b download.
    png_15694.png
    png_15695.png
    png_15696.png
    png_15698.png
    Maybe, There is a new build of Sandboxie-Plus available is new feature?
     
    Last edited: Aug 22, 2022
  19. deugniet

    deugniet Registered Member

    Joined:
    Nov 25, 2013
    Posts:
    1,244
  20. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Yeah, maybe... There is a new build of Sandboxie-Plus available is new feature?
    I've deleted temp files. There is a new build.... remains. ¯\_(ツ)_/¯
     
    Last edited: Aug 22, 2022
  21. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,335
    Location:
    Viena
    hmm... seams the message is not getting cleared properly, just clock on it an then chosoe cansel than it goes away
     
  22. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    Yep. Thanks
    png_15702.png
     
  23. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    24,121
    Location:
    UK
    I had to close Sbie Manager in TaskManager to delete this file in TEMP
    Screenshot 2022-08-22 182922.jpg
     
  24. DavidXanatos

    DavidXanatos Developer

    Joined:
    Sep 6, 2006
    Posts:
    2,335
    Location:
    Viena
    the QtSingleApp library uses such a temp file to make there be only one instance of sandman per user, the file is locked and in use as long as there is a sandman active, it gets delted when sandman closes
     
  25. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,458
    Location:
    .
    my process is SandMan systray icon > Exit ... to delete temp file.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.