Exclude Apps from Internet Access

If it's not about a problem in the program
Post Reply
DocMAX
Posts: 28
Joined: Tue Oct 29, 2013 4:07 am
Location: Deutschland

Exclude Apps from Internet Access

Post by DocMAX » Tue May 27, 2014 4:56 pm

Hi,

i see i can block ALL programs from internet access and make some exceptions.
But i want the opposide, allow ALL programs with some exceptions.

How can I do it?
I don't see how to do it with latest version 4.10.

Regards,
DocMAX

Curt@invincea
Sandboxie Lead Developer
Sandboxie Lead Developer
Posts: 1638
Joined: Fri Jan 17, 2014 5:21 pm
Contact:

Re: Exclude Apps from Internet Access

Post by Curt@invincea » Fri May 30, 2014 6:27 pm

Can you give me an example of an app you want to disallow? I'm not sure how much demand there is for such a feature.

DocMAX
Posts: 28
Joined: Tue Oct 29, 2013 4:07 am
Location: Deutschland

Re: Exclude Apps from Internet Access

Post by DocMAX » Sat May 31, 2014 4:22 am

Why you need an example app? I want to do it with any app I want.

Domochevsky
Posts: 125
Joined: Wed Jun 05, 2013 7:04 pm

Re: Exclude Apps from Internet Access

Post by Domochevsky » Sun Jun 01, 2014 1:01 pm

Hm, for what it's worth, I do support the notion of having a feature like this.
Ideally a "per application" prompt would be useful. Eg, the program tries to access the internet and subsequently SB asks whether or not that is ok. (No -> add to Excluded Applications)

Curt@invincea
Sandboxie Lead Developer
Sandboxie Lead Developer
Posts: 1638
Joined: Fri Jan 17, 2014 5:21 pm
Contact:

Re: Exclude Apps from Internet Access

Post by Curt@invincea » Tue Jun 03, 2014 4:25 pm

DocMAX wrote:Why you need an example app? I want to do it with any app I want.
So if you block ParentApp.exe, what happens if it starts ChildApp.exe and communicates through that?

westes
Posts: 29
Joined: Fri Jun 06, 2014 6:24 pm

Re: Exclude Apps from Internet Access

Post by westes » Fri Jun 06, 2014 8:19 pm

Curt@invincea wrote:Can you give me an example of an app you want to disallow? I'm not sure how much demand there is for such a feature.
What he is requesting is an application level firewall, which is something I have wanted for ages. I'll give an example: Lotus Notes client talks to Lotus Notes server on destination TCP port 1352. If you don't want that application to do anything more than communicate to the Notes server, you create a rule that restricts outgoing TCP traffic for this specific application to destination TCP port 1352. All other connections are rejected. You might want to further restrict on IP address, or on combinations of UDP/TCP, target IP, and target port.

Basically anything that Checkpoint Firewall can do you might want to do targeting a specific application. There might be firewall rules that apply to entire groups of applications, and there might be rules that are specific to specific applications.

It doesn't take much imagination to come up with other use cases, and it's an extremely useful idea.

Curt@invincea
Sandboxie Lead Developer
Sandboxie Lead Developer
Posts: 1638
Joined: Fri Jan 17, 2014 5:21 pm
Contact:

Re: Exclude Apps from Internet Access

Post by Curt@invincea » Fri Jun 06, 2014 11:41 pm

westes wrote: It doesn't take much imagination to come up with other use cases, and it's an extremely useful idea.
And that's probably why there are so many application firewalls already out there.

westes
Posts: 29
Joined: Fri Jun 06, 2014 6:24 pm

Re: Exclude Apps from Internet Access

Post by westes » Sat Jun 07, 2014 12:36 am

Curt@invincea wrote:
westes wrote: It doesn't take much imagination to come up with other use cases, and it's an extremely useful idea.
And that's probably why there are so many application firewalls already out there.
The only way to guarantee the integrity of an application firewall is to have it run from the sandbox manager. No system-level firewall can ever properly constrain the isolated behavior of a particular application.

Which products did you have in mind?

westes
Posts: 29
Joined: Fri Jun 06, 2014 6:24 pm

Re: Exclude Apps from Internet Access

Post by westes » Mon Jun 09, 2014 11:36 pm

Curt@invincea wrote:
westes wrote: It doesn't take much imagination to come up with other use cases, and it's an extremely useful idea.
And that's probably why there are so many application firewalls already out there.
If you have the application installed in Sandboxie, the host OS does not even see the application!! So your host level application firewall won't have any ability to set rules against that process.

If we modify Windows Firewall rules specific to the program we install in a Sandbox *inside* the Sandbox, will Windows Firewall actually execute a custom ruleset just inside of the Sandbox?

Curt@invincea
Sandboxie Lead Developer
Sandboxie Lead Developer
Posts: 1638
Joined: Fri Jan 17, 2014 5:21 pm
Contact:

Re: Exclude Apps from Internet Access

Post by Curt@invincea » Tue Jun 10, 2014 12:28 am

Windows sees everything running in the sandbox. Start task manager. You'll see all the sandboxed processes listed. All IP from the sandbox goes through any firewall.

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest