html file capable of deleting all sandbox contents.

Please post your problem description here

Moderator: Barb@Invincea

Post Reply
ViolentTactics
Posts: 1
Joined: Mon Jun 03, 2013 10:32 pm

html file capable of deleting all sandbox contents.

Post by ViolentTactics » Mon Jun 03, 2013 10:35 pm

I was messing with sandboxie and I found a specially crafted HTML code that bypasses sandboxie completely and it also bypasses whatever protection you are using for example Firefoxes no script is useless against this file. Once the said html file is clicked and loaded it destroys the sandbox. I wont post the code here but I will give it to a programmer so they can check it out.

nicknomo
Posts: 89
Joined: Mon Aug 02, 2010 3:15 am

Post by nicknomo » Tue Jun 04, 2013 12:31 am

Well, if I understand you correctly, it would sound like Sandboxie is working as intended. The sandbox virtualizes writes to your file system. If something is wiping the sandbox, then it would potentially wipe data on parts of your drive if it ran unsandboxed. The fact that nothing outside the sandbox was touched would be the desired effect.

Sandboxie, by default, doesn't proactively end a process based on signatures or heuristics. Its really more about containing the damage done by a process into a small area of little significance.

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest