Sandboxie and Reflective Memory Injection [SOLVED]

If it's not about a problem in the program
Post Reply
Der Moloch
Posts: 82
Joined: Sun Jun 23, 2013 11:22 am

Sandboxie and Reflective Memory Injection [SOLVED]

Post by Der Moloch » Sun Apr 17, 2016 4:08 pm

Here's the thing.

There is a person on another forum who is postulating that Sandboxie doesn't protect a process running outside Sandboxie from reflective memory injection from a process running inside Sandboxie. He also said that Sandboxie would have to detect the reflective memory injection in order to block it.

My answer was that this wouldn't work by default and that no detection would be necessary due to the way that Sandboxie applies Windows security features like integrity levels, where a process with integrity level untrusted cannot alter the memory of a process with a higher integrity level, like svchost.exe.

Still it would be nice if Invincea could clarify on this matter.
One hour of FleischmannTV saves one square kilometre of precious peble wasteland.

Syrinx
Sandboxie Guru
Sandboxie Guru
Posts: 620
Joined: Fri Nov 13, 2015 4:11 pm

Re: Sandboxie and Reflective Memory Injection

Post by Syrinx » Sun Apr 17, 2016 6:07 pm

I already commented over there but basically the end assumption is totally mis-formed. The lack of preventing it within the box does not mean it would let it do the same out of the box. After all that supposed 'testing' it wouldn't have been much to actually try it and find out instead of making a wildly incorrect guess. :-/ My guess is the person who wrote it doesn't know enough about how sandboxie or windows works in general and isn't qualified to to preform such tests for anyone but themselves or they were trying to pull something off intentionally.... I had missed that they tested it in XP but even so programs can't modify the memory of programs outside unless the user opens a hole allowing it.
Goo.gl/p8qFCf

Curt@invincea
Sandboxie Lead Developer
Sandboxie Lead Developer
Posts: 1638
Joined: Fri Jan 17, 2014 5:21 pm
Contact:

Re: Sandboxie and Reflective Memory Injection

Post by Curt@invincea » Mon Apr 18, 2016 7:12 pm

As Syrinx stated, sandboxed applications cannot write to the address space of a process outside the sandbox.

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest