I remember reading that due to microsoft 64 bit patch guard Sandboxie is no longer able to block Kernel exploits is this true?
like this
https://labs.bromium.com/2013/07/23/app ... rspective/
and this recent attack
http://arstechnica.com/security/2016/11 ... d-in-2013/
What about using file folder rules to block access to the kernel32.dll file?
Does Sandboxie Protect Kernel ?
-
- Sandboxie Lead Developer
- Posts: 1638
- Joined: Fri Jan 17, 2014 5:21 pm
- Contact:
Re: Does Sandboxie Protect Kernel ?
This has been discussed quite extensively. http://forums.sandboxie.com/phpBB3/view ... 3&p=103163
And, no, you cannot block the kernel with Sbie. At any rate, kernel32.dll is not part of the kernel. It contains the user mode APIs that interface to the kernel.
And, no, you cannot block the kernel with Sbie. At any rate, kernel32.dll is not part of the kernel. It contains the user mode APIs that interface to the kernel.
Re: Does Sandboxie Protect Kernel ?
Where does the arstechnica article say Sandboxie was bypassed?
-
- Sandboxie Lead Developer
- Posts: 1638
- Joined: Fri Jan 17, 2014 5:21 pm
- Contact:
Re: Does Sandboxie Protect Kernel ?
It didn't. And that wasn't even a kernel exploit.Peter2150 wrote:Where does the arstechnica article say Sandboxie was bypassed?
Re: Does Sandboxie Protect Kernel ?
I didn't think so. Don't see why OP linked that article
Who is online
Users browsing this forum: No registered users and 1 guest