Yes i found some troubling information about rats that can get around the sandbox with coding.
This link shows you can patch a server but not sandboxie itself.
https://www.youtube.com/watch?v=vhBooSrRtnc
I am concerned with this considering I am seeing cmd.exe launch whenever chrome is launched. And it is attached to sandboxie. So bottom line is this issue been dealt with or are we still at risk?
The Anti-Sandboxie Rats use. Was this patched?
-
- Posts: 2
- Joined: Sun Jan 11, 2015 6:44 pm
Re: The Anti-Sandboxie Rats use. Was this patched?
The link seems to be showing someone modding the sub7 rat so that it (sub7) doesn't detect sandboxie (by changing the check for SbieDll.dll), it's not in any way getting around sandboxie, sandboxie is doing it's job and protecting the system.ericprince811 wrote: ↑Thu Jun 15, 2017 12:09 pmYes i found some troubling information about rats that can get around the sandbox with coding.
This link shows you can patch a server but not sandboxie itself.
https://www.youtube.com/watch?v=vhBooSrRtnc
I am concerned with this considering I am seeing cmd.exe launch whenever chrome is launched. And it is attached to sandboxie. So bottom line is this issue been dealt with or are we still at risk?
Malware often checks if it is being executed in a sandbox in order to avoid analysis by security researchers; In the example you provided for instance it's sub7 that's stopping it's own execution in the first example, not sandboxie closing it. This is just showing how you can modify the sub7 sandbox check in order to run the program in sandboxie (presumably to analyse sub7), sandboxie will still sandbox the program.
-
- Posts: 2
- Joined: Sun Jan 11, 2015 6:44 pm
Re: The Anti-Sandboxie Rats use. Was this patched?
But for this it shows that it was able to re-open itself after termination. If that is the case can it re-write itself even after the contents are deleted.
-
- Sandboxie Support
- Posts: 2337
- Joined: Mon Nov 07, 2016 3:10 pm
Re: The Anti-Sandboxie Rats use. Was this patched?
Hello ericprince811 ,
Once you delete the contents of the Sandbox, all the applications that were inside it will be gone from your system.
There is also a way to do a Secure Delete, you can find more info here:
https://www.sandboxie.com/index.php?SecureDeleteSandbox
Regards,
Barb.-
Once you delete the contents of the Sandbox, all the applications that were inside it will be gone from your system.
There is also a way to do a Secure Delete, you can find more info here:
https://www.sandboxie.com/index.php?SecureDeleteSandbox
Regards,
Barb.-
Re: The Anti-Sandboxie Rats use. Was this patched?
No, it doesn't re-open itself after termination. Every time it starts it is executed by the user who drags the exe into sandboxie.ericprince811 wrote: ↑Fri Jun 16, 2017 5:45 pmBut for this it shows that it was able to re-open itself after termination. If that is the case can it re-write itself even after the contents are deleted.
-
- Posts: 35
- Joined: Thu Aug 23, 2012 11:00 am
Re: The Anti-Sandboxie Rats use. Was this patched?
I run my sandbox in a ram drive, that should terminate everything once you shut down or restart the computer. I also set Sandboxie to "delete all contents at close alsoBarb@Invincea wrote: ↑Mon Jun 19, 2017 11:40 amHello ericprince811 ,
Once you delete the contents of the Sandbox, all the applications that were inside it will be gone from your system.
There is also a way to do a Secure Delete, you can find more info here:
https://www.sandboxie.com/index.php?SecureDeleteSandbox
Regards,
Barb.-
Thanks
Dan
Dan
Re: The Anti-Sandboxie Rats use. Was this patched?
Me too, although I have auto-delete and non-delete sandboxes; until system close of course when all disappears.Dan_Br0673 wrote: ↑Sun Jul 30, 2017 10:02 amI run my sandbox in a ram drive, that should terminate everything once you shut down or restart the computer. I also set Sandboxie to "delete all contents at close also
Henry
Who is online
Users browsing this forum: No registered users and 1 guest