Stopping "cmd.exe" from running sandboxed

If it doesn't fit elsewhere, it goes here
Post Reply
Newbeak
Posts: 59
Joined: Sun Jul 29, 2007 5:33 pm
Location: Canada

Stopping "cmd.exe" from running sandboxed

Post by Newbeak » Thu Feb 10, 2011 10:43 pm

I found a website where a poster suggested that Sandboxie users edit Sandboxie to prevent "cmd.exe" from running,but didn't spell out how to do it. Is this a good thing to do? Here is the link to the page I found it on ( bottom of comment #16) :http://forums.anandtech.com/showthread.php?t=206173
I am not very computer literate,but would like the thoughts of other forum members more knowledgeable in this area. :?:

Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Post by Guest10 » Fri Feb 11, 2011 10:49 am

I've seen screen prints from malware writer's sites, in which they show how effective their program is - in infecting, or stealing information from users.
java seems to be high on the list of infection vectors, but I'm not sure that running cmd.exe on a users' computer was even listed.
There would have to already be an existing program for cmd.exe to run, since simply running cmd.exe on it's own doesn't do anything.
So are they talking about placing a program on your computer, and then starting cmd.exe to run it?
Someone more knowledgeable about malware than me would have to say whether anyone does that, or not.

Anyway, I can't think of a way to black-list cmd.exe from running in the sandbox.
What I do is to use Sandboxie's Start/Run Restrictions in 2 of my sandboxes, to white-list programs that are allowed to start and run.
Merely leaving cmd.exe off of the list of white-listed programs is enough to keep it from running sandboxed.

I don't intentionally visit any known malware sites, and then see if I would be infected.
But in my most used Firefox sandbox, I use Start/Run Restrictions - and use the default selection in which I am notified if any non-white-listed program tries to run - and I've never been notified that cmd.exe has tried to run in the sandbox while browsing.
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

Mike
Posts: 592
Joined: Mon Nov 16, 2009 1:27 pm

Post by Mike » Fri Feb 11, 2011 12:22 pm

Guest10 wrote:Anyway, I can't think of a way to black-list cmd.exe from running in the sandbox.
I haven't tried this, but what about: ClosedFilePath=C:\Windows\System32\cmd.exe

Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Post by Guest10 » Fri Feb 11, 2011 1:31 pm

Mike wrote:I haven't tried this, but what about: ClosedFilePath=C:\Windows\System32\cmd.exe
Yes, that should work. The system won't be able to find cmd.exe, so it can't run it either.
Sandbox Settings > Resource Access > File Access > Blocked Access
Click on "Add" and navigate to, and select, cmd.exe in the Windows\System32 folder
OK

I would also like to hear what others think, about keeping cmd.exe from running in the sandbox.
Does that add anything of real value to the user?
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

Mike
Posts: 592
Joined: Mon Nov 16, 2009 1:27 pm

Post by Mike » Fri Feb 11, 2011 1:57 pm

Guest10 wrote:I would also like to hear what others think, about keeping cmd.exe from running in the sandbox.
Does that add anything of real value to the user?
For people like you and me, who don't intentionally visit malware sites, maybe the value is more theoretical. But as you know, you can do a lot from cmd.exe - start any program, delete directory trees, create or host scripts, etc. It may or may not matter, depending on whether you have anything important in the sandbox, or if you have any OpenFilePaths. I was going to create a thread which touched on this... will do so in a couple days when I have time.

Ruhe
Posts: 803
Joined: Thu Jul 03, 2008 8:56 am
Location: Germany
Contact:

Post by Ruhe » Fri Feb 11, 2011 3:13 pm

As all my sandboxes have Start/Run Access in action there is in general no need for this cmd tweak.

Mike
Posts: 592
Joined: Mon Nov 16, 2009 1:27 pm

Post by Mike » Fri Feb 11, 2011 3:28 pm

Ruhe wrote:As all my sandboxes have Start/Run Access in action there is in general no need for this cmd tweak.
Agreed, Start/Run whitelists are the way to go since they're more complete. If you were addressing Guest10's question though, I think it was more about the value of preventing cmd.exe from running sandboxed in general.

Newbeak
Posts: 59
Joined: Sun Jul 29, 2007 5:33 pm
Location: Canada

Post by Newbeak » Fri Feb 11, 2011 6:15 pm

Thanks,guys.I was looking at that Start/Run whitelist feature,and whether it was what to use to prevent cmd.exe from running.I am not a techie,so what I would do is list all the programs that are white listed in this box,such as my browser,email client,etc,and that would prevent things like cmd.exe from running in the sandbox?

Mike
Posts: 592
Joined: Mon Nov 16, 2009 1:27 pm

Post by Mike » Fri Feb 11, 2011 6:32 pm

Newbeak wrote:I am not a techie,so what I would do is list all the programs that are white listed in this box,such as my browser,email client,etc,and that would prevent things like cmd.exe from running in the sandbox?
Correct, any program not explicitly listed will not be able to run in that sandbox. Note that, with Start/Run restrictions, no program installed inside the sandbox will be allowed to run - presumably, this is a safety precaution.

For your reference, the help page is here: http://www.sandboxie.com/index.php?Rest ... s#startrun

Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Post by Guest10 » Sat Feb 12, 2011 8:20 am

It will take you some time to develop a Start/Run list for the sandbox.
You will quickly find that there will be programs that you need to add to the list.
If you are using a recent version of Sandboxie, when it notifies you that a program cannot run due to the restrictions, you don't have to end the sandboxed programs and then revise the list.

You should be able to just open the Sandboxie Control icon, and add the program from:
Sandbox Settings > Restrictions > Start/Run Access > "Add Program" button
and look for the program's name in the lists that are there.
Add it, and the change takes effect immediately.

You will likely find yourself adding things like: Windows Media Player, your pdf viewer, a download manager (if used), unzip utility, Firefox's Plugin-Container.exe, etc.
I also had to add some print spooler .exe's, for a seldom used ink jet printer.
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

Blues
Posts: 214
Joined: Sun May 10, 2009 7:37 pm
Location: Blue Ridge Mtns

Post by Blues » Sat Feb 12, 2011 9:41 am

Guest10 wrote:If you are using a recent version of Sandboxie, when it notifies you that a program cannot run due to the restrictions, you don't have to end the sandboxed programs and then revise the list.

You should be able to just open the Sandboxie Control icon, and add the program from:
Sandbox Settings > Restrictions > Start/Run Access > "Add Program" button
and look for the program's name in the lists that are there.
Add it, and the change takes effect immediately.
When I discovered that change (a while back), it was a most welcome new feature (not having to interrupt the then current session). 8)
Blues

Real-Time: Sandboxie (Lifetime), Online Armor Premium, Webroot SecureAnywhere AV

On Demand: Shadow Defender, MBAM Pro, HitmanPro, Drive Snapshot / Macrium Reflect

Guest10
Posts: 5124
Joined: Sun Apr 27, 2008 5:24 pm
Location: Ohio, USA

Post by Guest10 » Sat Feb 12, 2011 11:37 am

Blues wrote:When I discovered that change (a while back), it was a most welcome new feature (not having to interrupt the then current session).
It's not quite as nice as it could be, if you could just add the program to the Start/Run Restriction list when the SBIE1308 message is generated.
Paul
Win 10 Home 64-bit (w/admin rights) - Zone Alarm Pro Firewall, MalwareBytes Premium A/V, Cyberfox, Thunderbird
Sandboxie user since March 2007

Blues
Posts: 214
Joined: Sun May 10, 2009 7:37 pm
Location: Blue Ridge Mtns

Post by Blues » Sat Feb 12, 2011 11:44 am

Guest10 wrote:
Blues wrote:When I discovered that change (a while back), it was a most welcome new feature (not having to interrupt the then current session).
It's not quite as nice as it could be, if you could just add the program to the Start/Run Restriction list when the SBIE1308 message is generated.
Well, yeah, but I'm not complaining... :lol:
Blues

Real-Time: Sandboxie (Lifetime), Online Armor Premium, Webroot SecureAnywhere AV

On Demand: Shadow Defender, MBAM Pro, HitmanPro, Drive Snapshot / Macrium Reflect

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest