<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
	<link rel="self" type="application/atom+xml" href="https://forums.sandboxie.com/phpBB3/app.php/feed/topic/14934" />

	<title>Sandboxie Support</title>
	<subtitle>Support Forum for Sandboxie</subtitle>
	<link href="https://forums.sandboxie.com/phpBB3/index.php" />
	<updated>2013-05-01T06:05:55-04:00</updated>

	<author><name><![CDATA[Sandboxie Support]]></name></author>
	<id>https://forums.sandboxie.com/phpBB3/app.php/feed/topic/14934</id>

		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2013-05-01T06:05:55-04:00</updated>

		<published>2013-05-01T06:05:55-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89442#p89442</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89442#p89442"/>
		<title type="html"><![CDATA[[0.7]]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89442#p89442"><![CDATA[
v4.0.1.07 works correctly. Thank you.<p>Statistics: Posted by Guest — Wed May 01, 2013 6:05 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2013-04-29T14:53:40-04:00</updated>

		<published>2013-04-29T14:53:40-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89386#p89386</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89386#p89386"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89386#p89386"><![CDATA[
<blockquote><div><cite>DR_LaRRY_PEpPeR wrote:</cite>RpcSs shouldn't be running as SYSTEM... I'm not seeing that -- it should be in its sandbox. However, it is now started <em>by</em> SbieSvc (since .05 I think), which is SYSTEM of course, so I think that's where the SANDBOX_INERT would still work (with hotfix), when SbieSvs is launching RpcSs.</div></blockquote>You're right! I mistakenly believed it was running as SYSTEM, because it's a spawned process, and I just assumed it inherited the same rights, for some reason. It runs as UNTRUSTED.  I don't know how I missed that, as I have Process Explorer configured to show the Integrity Levels column. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_redface.gif" width="15" height="15" alt=":oops:" title="Embarassed">  But, because SbieSvc.exe runs as SYSTEM, then AppLocker will ignore SandboxieRpcSs.exe. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"><p>Statistics: Posted by Guest — Mon Apr 29, 2013 2:53 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[DR_LaRRY_PEpPeR]]></name></author>
		<updated>2013-04-29T14:25:15-04:00</updated>

		<published>2013-04-29T14:25:15-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89384#p89384</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89384#p89384"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89384#p89384"><![CDATA[
<blockquote><div><cite>fanish wrote:</cite>There's some misunderstanding here. Yes, I did test it outside of Sandboxie, but not to verify if Sandboxie did something to the outside system. Hope this clears it up. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_wink.gif" width="15" height="15" alt=":wink:" title="Wink"></div></blockquote>Ooops! <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_surprised.gif" width="15" height="15" alt=":o" title="Surprised"> I totally misread that!! Sorry, got it now. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"><br><blockquote class="uncited"><div>Well, it's working for SandboxieRpcSs.exe, which runs as SYSTEM. Maybe the use of the flag SANDBOX_INERT made things work as they should with version 4. I'm not a developer per se, so just throwing it out loud. But, it's what makes most sense to me.<br><br>So, it makes sense that SandboxieRpcSs.exe, and other Sandboxie processes that run as SYSTEM ???, have no issues now.</div></blockquote>RpcSs shouldn't be running as SYSTEM... I'm not seeing that -- it should be in its sandbox. However, it is now started <em>by</em> SbieSvc (since .05 I think), which is SYSTEM of course, so I think that's where the SANDBOX_INERT would still work (with hotfix), when SbieSvs is launching RpcSs.<p>Statistics: Posted by <a href="https://forums.sandboxie.com/phpBB3/memberlist.php?mode=viewprofile&amp;u=11108">DR_LaRRY_PEpPeR</a> — Mon Apr 29, 2013 2:25 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2013-04-29T14:12:14-04:00</updated>

		<published>2013-04-29T14:12:14-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89383#p89383</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89383#p89383"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89383#p89383"><![CDATA[
<blockquote><div><cite>DR_LaRRY_PEpPeR wrote:</cite><blockquote><div><cite>fanish wrote:</cite>No, I didn't test outside the sandbox to verify whether or not Sandboxie did something outside. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_lol.gif" width="15" height="15" alt=":lol:" title="Laughing"></div></blockquote>You didn't?<blockquote><div><cite>fanish wrote:</cite>So, the result I provided is for when I ran the PoC outside of the sandbox.</div></blockquote></div></blockquote>There's some misunderstanding here. Yes, I did test it outside of Sandboxie, but not to verify if Sandboxie did something to the outside system. Hope this clears it up. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_wink.gif" width="15" height="15" alt=":wink:" title="Wink"><br><blockquote><div><cite>DR_LaRRY_PEpPeR wrote:</cite>But anyway, other than that, I'm not sure I follow 100% without testing myself... I'll have to get that VM image downloaded. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_biggrin.gif" width="15" height="15" alt=":D" title="Very Happy"><br><br>So I guess you did NOT try by temporarily removing the hotfix? (Since "those not having" could test...)</div></blockquote>No, I didn't remove the hotfix, as the system running Windows 7 is a production system, actually. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_eek.gif" width="15" height="15" alt=":shock:" title="Shocked"><br><blockquote><div><cite>DR_LaRRY_PEpPeR wrote:</cite>And you say he's right that it breaks the Sandboxie fix, yet you said previously that Sandboxie's errors are gone, even though you have the fix installed. That would suggest that it IS working still, just that perhaps the ONLY thing that needs it is either the kernel driver/SbieSvc SYSTEM process, which CAN still use SANDBOX_INERT.</div></blockquote>Well, it's working for SandboxieRpcSs.exe, which runs as SYSTEM. Maybe the use of the flag SANDBOX_INERT made things work as they should with version 4. I'm not a developer per se, so just throwing it out loud. But, it's what makes most sense to me.<br><br>So, it makes sense that SandboxieRpcSs.exe, and other Sandboxie processes that run as SYSTEM ???, have no issues now.<br><blockquote><div><cite>DR_LaRRY_PEpPeR wrote:</cite>Since if I understood right, you ARE still seeing something blocked as it should be in the sandbox? Of course, you have the fix installed, right, but just verifying. If so, yet Sandboxie is still working without errors in other parts that you had before, it would be nice if tzuk could ONLY use SANDBOX_INERT in the places where it's actually still having an effect, presumably (SYSTEM level), instead of on "all processes in the sandbox."</div></blockquote>Yes, AppLocker is still blocking things in the sandboxes. Short version: Calling program B from program A will fail. AppLocker rule must be created.<br><br>I agree that it would be nice for SANDBOX_INERT to only work for processes related to Sandboxie running as SYSTEM.<p>Statistics: Posted by Guest — Mon Apr 29, 2013 2:12 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Alex1992]]></name></author>
		<updated>2013-04-29T13:02:06-04:00</updated>

		<published>2013-04-29T13:02:06-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89382#p89382</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89382#p89382"/>
		<title type="html"><![CDATA[error rpcss]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89382#p89382"><![CDATA[
Good afternoon. When upgrading from a previous version 3.6 to 4. 06 there is an error starting rpcss. Used in conjunction with the BSA, and the configuration file inject_dll prescribing error occurs in the case of removal of these parameters is run without error on windows xp sp3. In what could be the problem?<p>Statistics: Posted by <a href="https://forums.sandboxie.com/phpBB3/memberlist.php?mode=viewprofile&amp;u=15317">Alex1992</a> — Mon Apr 29, 2013 1:02 pm</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[DR_LaRRY_PEpPeR]]></name></author>
		<updated>2013-04-29T10:04:31-04:00</updated>

		<published>2013-04-29T10:04:31-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89380#p89380</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89380#p89380"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89380#p89380"><![CDATA[
<blockquote><div><cite>fanish wrote:</cite>No, I didn't test outside the sandbox to verify whether or not Sandboxie did something outside. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_lol.gif" width="15" height="15" alt=":lol:" title="Laughing"></div></blockquote>You didn't?<blockquote><div><cite>fanish wrote:</cite>So, the result I provided is for when I ran the PoC outside of the sandbox.</div></blockquote><br>But anyway, other than that, I'm not sure I follow 100% without testing myself... I'll have to get that VM image downloaded. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_biggrin.gif" width="15" height="15" alt=":D" title="Very Happy"><br><br>So I guess you did NOT try by temporarily removing the hotfix? (Since "those not having" could test...)<br><br><br>And you say he's right that it breaks the Sandboxie fix, yet you said previously that Sandboxie's errors are gone, even though you have the fix installed. That would suggest that it IS working still, just that perhaps the ONLY thing that needs it is either the kernel driver/SbieSvc SYSTEM process, which CAN still use SANDBOX_INERT.<br><br>Since if I understood right, you ARE still seeing something blocked as it should be in the sandbox? Of course, you have the fix installed, right, but just verifying. If so, yet Sandboxie is still working without errors in other parts that you had before, it would be nice if tzuk could ONLY use SANDBOX_INERT in the places where it's actually still having an effect, presumably (SYSTEM level), instead of on "all processes in the sandbox."<br><br>That way, people that do NOT have the AppLocker hotfix installed would still have AppLocker working in the sandbox, for the most part (short of an exploit using SANDBOX_INERT). Again, that's IF it really is disabling AppLocker, without the hotfix, for regular programs, since I don't see that happening with SRP (which SANDBOX_INERT supposedly also affects).<p>Statistics: Posted by <a href="https://forums.sandboxie.com/phpBB3/memberlist.php?mode=viewprofile&amp;u=11108">DR_LaRRY_PEpPeR</a> — Mon Apr 29, 2013 10:04 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2013-04-29T09:32:27-04:00</updated>

		<published>2013-04-29T09:32:27-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89379#p89379</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89379#p89379"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89379#p89379"><![CDATA[
<blockquote><div><cite>DR_LaRRY_PEpPeR wrote:</cite>Wow BSOD, oops! <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_eek.gif" width="15" height="15" alt=":shock:" title="Shocked"> And BTW, yeah, these Sandboxie changes should not affect AppLocker/SRP outside of the sandbox -- that would be extreme if it somehow affected everything. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_surprised.gif" width="15" height="15" alt=":o" title="Surprised"></div></blockquote>No, I didn't test outside the sandbox to verify whether or not Sandboxie did something outside. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_lol.gif" width="15" height="15" alt=":lol:" title="Laughing"><br><br>According to Tzuk, he mistakenly believed the hotfix was installed already in all Windows 7 versions with AppLocker. He updated his previous post. His second assumption is correct. AppLocker's hotfix does break the fix he implemented. And, the reason I say this, comes in the line of his first assumption, that the flag SANDBOX_INERT would apply to all sandboxed processes. With this in mind, it made sense to execute of one of the apps I have in a sandbox, which does call another app. I removed the AppLocker rule for this other app, and called it from the main app. It's blocked.<br><br>Those not having the hotfix already installed, could easily test Sandboxie's fix this way. I hope that's accurate way of testing it. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"><p>Statistics: Posted by Guest — Mon Apr 29, 2013 9:32 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[DR_LaRRY_PEpPeR]]></name></author>
		<updated>2013-04-29T07:54:39-04:00</updated>

		<published>2013-04-29T07:54:39-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89377#p89377</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89377#p89377"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89377#p89377"><![CDATA[
Wow BSOD, oops! <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_eek.gif" width="15" height="15" alt=":shock:" title="Shocked"> And BTW, yeah, these Sandboxie changes should not affect AppLocker/SRP outside of the sandbox -- that would be extreme if it somehow affected everything. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_surprised.gif" width="15" height="15" alt=":o" title="Surprised"><p>Statistics: Posted by <a href="https://forums.sandboxie.com/phpBB3/memberlist.php?mode=viewprofile&amp;u=11108">DR_LaRRY_PEpPeR</a> — Mon Apr 29, 2013 7:54 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2013-04-29T07:49:11-04:00</updated>

		<published>2013-04-29T07:49:11-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89376#p89376</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89376#p89376"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89376#p89376"><![CDATA[
<blockquote><div><cite>DR_LaRRY_PEpPeR wrote:</cite>You tried it in a sandbox I assume? <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"> I'm actually curious what happens <em>without</em> the hotfix now. Is it hard to uninstall/reinstall? I guess it requires a restart? Oh well, if nothing else I'll wait and check myself!</div></blockquote>I was going to test both outside and inside of the sandbox, to see the results. But, when I ran Word.exe in the sandbox, AppLocker blocked something related to office in the user profile, and then I got BSOD. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_eek.gif" width="15" height="15" alt=":shock:" title="Shocked"><br><br>Will have to create temp rules and see what happens.<br><br>So, the result I provided is for when I ran the PoC outside of the sandbox.<p>Statistics: Posted by Guest — Mon Apr 29, 2013 7:49 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[DR_LaRRY_PEpPeR]]></name></author>
		<updated>2013-04-29T07:24:26-04:00</updated>

		<published>2013-04-29T07:24:26-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89373#p89373</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89373#p89373"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89373#p89373"><![CDATA[
You tried it in a sandbox I assume? <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_smile.gif" width="15" height="15" alt=":)" title="Smile"> I'm actually curious what happens <em>without</em> the hotfix now. Is it hard to uninstall/reinstall? I guess it requires a restart? Oh well, if nothing else I'll wait and check myself!<p>Statistics: Posted by <a href="https://forums.sandboxie.com/phpBB3/memberlist.php?mode=viewprofile&amp;u=11108">DR_LaRRY_PEpPeR</a> — Mon Apr 29, 2013 7:24 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2013-04-29T07:16:06-04:00</updated>

		<published>2013-04-29T07:16:06-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89371#p89371</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89371#p89371"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89371#p89371"><![CDATA[
Yes, I missed that part. It does mention LocalSystem/TrustedInstaller.<br><br>I tried another PoC (hxxp://<a href="http://www.mountknowledge.nl/2011/01/28/bypassing-windows-applocker-using-vb-script-in-word-and-excel/" class="postlink">www.mountknowledge.nl/2011/01/28/bypass ... and-excel/</a>), based on Didider's one, and AppLocker did block it. So, the hotfix is working... for processes not running as LocalSystem/TrustedInstaller.<p>Statistics: Posted by Guest — Mon Apr 29, 2013 7:16 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[tzuk]]></name></author>
		<updated>2013-04-29T07:13:37-04:00</updated>

		<published>2013-04-29T07:13:37-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89370#p89370</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89370#p89370"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89370#p89370"><![CDATA[
<blockquote><div><cite>DR_LaRRY_PEpPeR wrote:</cite>I don't quite get how tzuk says the flag is enabled by kernel-mode code (meaning SYSTEM SbieSvc I assume)</div></blockquote>I mean the driver component of Sandboxie.<p>Statistics: Posted by <a href="https://forums.sandboxie.com/phpBB3/memberlist.php?mode=viewprofile&amp;u=3">tzuk</a> — Mon Apr 29, 2013 7:13 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[DR_LaRRY_PEpPeR]]></name></author>
		<updated>2013-04-29T07:06:17-04:00</updated>

		<published>2013-04-29T07:06:17-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89368#p89368</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89368#p89368"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89368#p89368"><![CDATA[
fanish, as I said, I also wondered about the patch like you. But look at the description of SANDBOX_INERT on the <a href="http://msdn.microsoft.com/en-us/library/aa446583%28v=vs.85%29.aspx" class="postlink">CreateRestrictedToken</a> page. "On systems with KB2532445 installed," it says the system ignores SANDBOX_INERT <em>unless</em> the process is running as SYSTEM (LocalSystem).<br><br>I said how SRP, without any patch, already was not supposed to apply to SYSTEM processes, but I guess the same is not true for AppLocker...<br><br>Yes, I may be trying Didier's code soon (against my own fix, below)... or maybe NOT: to determine exactly what restrictions may not apply for sandboxed processes. I guess I'll have to run one of those 7 Enterprise VM images to play with AppLocker.<br><br><br>I don't quite get how tzuk says the flag is enabled by kernel-mode code (meaning SYSTEM SbieSvc I assume), but yet it's also "enabled for all processes in the sandbox," which would seem to suggest that normal, user-mode sandboxed processes could bypass restrictions, yet I don't see that with simple SRP -- that page suggests SANDBOX_INERT also applies to SRP and not only AppLocker. *shrug* Although IF AppLocker/SRP could be bypassed, having that fix installed should correct it for "normal, user-mode" processes.<br><br>BTW, I will hopefully soon create a DLL that should fix the "SRP bypass hole" on XP/Vista (8??) as well. I just need to check which lowest level functions to hook... It may be only for within Sandboxie first (if it works and is simpler), but hopefully system wide as well (or for folks without Sandboxie). Hopefully these Sandboxie changes don't screw each other up. <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_biggrin.gif" width="15" height="15" alt=":D" title="Very Happy"> A simple SBIE DLL I tried awhile ago to fix the <a href="http://blog.didierstevens.com/2011/01/24/circumventing-srp-and-applocker-by-design/" class="postlink">LoadLibraryEx hole</a> still works fine.<p>Statistics: Posted by <a href="https://forums.sandboxie.com/phpBB3/memberlist.php?mode=viewprofile&amp;u=11108">DR_LaRRY_PEpPeR</a> — Mon Apr 29, 2013 7:06 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[tzuk]]></name></author>
		<updated>2013-04-29T07:01:34-04:00</updated>

		<published>2013-04-29T07:01:34-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89365#p89365</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89365#p89365"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89365#p89365"><![CDATA[
Ah, so this KB isn't actually a mandatory update.  I assumed the update was already installed (on your systems and mine) so that if turning the sandbox inert flag works then evidently it works with this KB applied.  Which I now understand was an incorrect assumption.<br><br>So then it is possible I guess that having this KB would break this AppLocker fix in Sandboxie.  In that case I don't think I would be able to find another solution to the problem.  On the other hand it is possible the KB would not interfere with kernel mode code that turns on this bit.<p>Statistics: Posted by <a href="https://forums.sandboxie.com/phpBB3/memberlist.php?mode=viewprofile&amp;u=3">tzuk</a> — Mon Apr 29, 2013 7:01 am</p><hr />
]]></content>
	</entry>
		<entry>
		<author><name><![CDATA[Anonymous]]></name></author>
		<updated>2013-04-29T06:30:40-04:00</updated>

		<published>2013-04-29T06:30:40-04:00</published>
		<id>https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89361#p89361</id>
		<link href="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89361#p89361"/>
		<title type="html"><![CDATA[[.06] Could not execute SandboxieRpcSs.exe]]></title>

		
		<content type="html" xml:base="https://forums.sandboxie.com/phpBB3/viewtopic.php?t=14934&amp;p=89361#p89361"><![CDATA[
<blockquote><div><cite>tzuk wrote:</cite>That sandbox inert flag is enabled by kernel mode code so I don't think that KB update makes a difference.  I mean, evidently it works, right?..<br><br>The flag is enabled for all processes in the sandbox regardless of version or edition of Windows.</div></blockquote>Evidently, what you did is working. But, according to security researcher Didier Stevens, the actions his PoC performs were blocked by AppLocker, once he applied the patch. See: hxxp://blog.didierstevens.com/2011/11/17/hotfix-for-srpapplocker-bypass/<br><br>There's a comment by him where he states it.<br><br>Everything is so odd, indeed. So, apparently this hotfix is nothing but placebo? <img class="smilies" src="./../../.https://forums.sandboxie.com/phpBB3/images/smilies/icon_evil.gif" width="15" height="15" alt=":evil:" title="Evil or Very Mad"><br><br>Can anyone compile this code in his blog and see what happens?<br><br>Code is here hxxp://blog.didierstevens.com/2011/01/25/circumventing-srp-and-applocker-to-create-a-new-process-by-design/<br><br>It would, for sure, be interesting to see what results you'll find.<p>Statistics: Posted by Guest — Mon Apr 29, 2013 6:30 am</p><hr />
]]></content>
	</entry>
	</feed>
