html file capable of deleting all sandbox contents.
Moderator: Barb@Invincea
-
- Posts: 1
- Joined: Mon Jun 03, 2013 10:32 pm
html file capable of deleting all sandbox contents.
I was messing with sandboxie and I found a specially crafted HTML code that bypasses sandboxie completely and it also bypasses whatever protection you are using for example Firefoxes no script is useless against this file. Once the said html file is clicked and loaded it destroys the sandbox. I wont post the code here but I will give it to a programmer so they can check it out.
Well, if I understand you correctly, it would sound like Sandboxie is working as intended. The sandbox virtualizes writes to your file system. If something is wiping the sandbox, then it would potentially wipe data on parts of your drive if it ran unsandboxed. The fact that nothing outside the sandbox was touched would be the desired effect.
Sandboxie, by default, doesn't proactively end a process based on signatures or heuristics. Its really more about containing the damage done by a process into a small area of little significance.
Sandboxie, by default, doesn't proactively end a process based on signatures or heuristics. Its really more about containing the damage done by a process into a small area of little significance.
Who is online
Users browsing this forum: No registered users and 1 guest