"Sandboxied" malware the rest of the system

If it doesn't fit elsewhere, it goes here
Post Reply
Centron

"Sandboxied" malware the rest of the system

Post by Centron » Fri Sep 08, 2006 8:22 am

Hello ,

I know that the advantage of having a program running under Sandboxie is that Sandboxie will not write anything outside its enviroment. I was wondering what would happen if a malware trapped into Sandboxie would ask to *read* files (f.ex. containing personal information): isn't there the risk that Sandboxie reads the content of the HD (believing the malware did a legitimate query) and passes the info to the malware that will communicate the content via the internet to its server?
I know that an "healthy" browser wouldn't allow such an operation in normal conditions, but what if the Sandboxied browser (or any other program with internet access) would be hacked (f.ex. forced with a .dll injection) so to retrieve in real-time info from HD: does Sandboxie provide any defence against that?

Thank for the reply and for the efforts you are providing in your product.

tzuk
Sandboxie Founder
Sandboxie Founder
Posts: 16076
Joined: Tue Jun 22, 2004 12:57 pm

Post by tzuk » Fri Sep 08, 2006 3:16 pm

Please see this post.

I guess I should update the FAQ to explain stuff like that. :) It's still very slim, too much stuff is hidden deep in the forum.
tzuk

Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest