MalwareTips.com
Current time: 05-20-2013, 03:22 AM
Hello,is this your first visit?! If NOT use this login panel!
Nick:  
Password:     
If YES, you should join
our amazing community!
Create an account!
Follow us
Facebook MalwareTips.com Twitter MalwareTips.com Google Plus  MalwareTips.com
  • Portal
    Home
  • News
    Headlines
  • Forums
    Community
  • Tutorials
    How-to's
  • Malware Help
    Assistance
    • Removal assistance
    • Malware removal guides
    • Security wizard
  • Reviews
    Products review
    • Video reviews
    • Written reviews
  • Giveaways
    Free stuff
    • Giveaways and promo
    • Discounts
    • Desktop enhancements
  • Malware Hub
    Virus Pipe
    • Virus Exchange
    • Virus List
  • Blogs
    Research

User Control Panel View New Posts View Today's Posts House Rules

MalwareTips.com / Security Discussions / Security Products / Sandboxie v
1 2 Next »
/ [How To] Use Sandboxie
Pages (6): 1 2 3 4 5 6 Next »
Tweet
Post Reply 
Threaded Mode | Linear Mode
[How To] Use Sandboxie
10-29-2011, 11:35 PM
Post: #1
Nathan Wootton Offline
Advanced Member (Level 5)
Posts: 282
Joined: May 2011
Kudos 168
Question [How To] Use Sandboxie
Ino many of you know how to use Sandboxie so this is aimed for the people who are new to it Biggrin

What is Sandboxie?

Sandboxie is very useful to check whether or not a program is infected, you can also use it to test out your botnet. Sandboxie runs your programs in an isolated space which prevents them from making permanent changes to other programs and data in your computer.



1. Download
HTML:
http://www.sandboxie.com/index.php?DownloadSandboxie
(Proceed through the installation)

2. Using Sandboxie
Open Sandboxie : Start > All Programs > Sandboxie > Sandboxie Control


Run File : Right-Click Suspected File > Run Sandboxed


Change Display : View > Files and Folders


Observe Folders : Sandbox DefaultBox > All files and Folders

3. Analysing Output

Now that you've ran your program you're probably wondering What does this all this mean? Now is when you analyze Sandboxie to check if the program has dropped any files. In the All files and Folder sub-menu you can observe the exact location of dropped files.

How do I know if my program's infected?

To decide whether or not a program is infected you have to think. Should this program drop files? For example : I've downloaded a crypter and decided to check it out in Sandboxie. Now immediately after I run it, I get a file dropped :


Settings :
To prevent against stealers acquiring your firefox passwords while using Sandboxie go to :
Sandbox>Default Box>Sandbox settings> Resource Access>File Access>Blocked Access>Edit/Add
and copy paste the following lines : (one by one)

%Local AppData%\Mozilla\
%AppData%\Mozilla\
\Device\Mup\


The same for Chrome and Opera

You can also disable the program from accessing the internet, this option is also found in Sandbox settings.

NEW! To bypass the Anti-Sandboxie that some malware uses, you need to disable the Sandboxie indicator that is in the titles of windows running in Sandboxie "#".

To do this go to Sandboxie>Rick-click on your sandbox>Sandbox Settings>Appearance>check "Don't show Sandboxie indicator...". (This method of detecting sandboxie isn't used by all malware however.)
Extra Info.

Keep in mind that if you receive an error, and your program is unable to run in Sandboxie, it is most likely that it's a virus and has implemented Anti-Sandboxie. DO NOT RUN IT OUTSIDE SANDBOXIE! (see 'Settings' spoiler to know how to bypass anti-sandboxie)

Once you are done with Sandboxie, Right-Click on the Sandbox and chose Terminate Programs. Also, remember to empty your SandBox after every use by Right-clicking>Delete Contents.

When you see [#] [#] around the title on the window, you know it's Sandboxed. Unless you have these indicators disabled (see 'Settings')

Well i hope this helps new people to sanboxie Angel

Bitdefender Total Security 2013

[Image: NathanGWootton.jpg]
Visit this user's website Find all posts by this user
Quote this message in a reply
 Kudos from: NathanF1(+1) , Jack(+5) , Littlebits(+2) , Wisdom(+1)
10-30-2011, 09:57 AM
Post: #2
AyeAyeCaptain Offline
Advanced Member (Level 5)
Posts: 494
Joined: Feb 2011
Kudos 100
RE: [How To] Use Sandboxie
Not a bad effort at all, nice one for taking the time to create it... About the whole password stealing though, using Lastpass or other variations would also combat this. I think you have explained it well enough though for all users to understand so top marks for that.

Don't use Sandboxie myself even though it's one of a few things that is worth paying for, but currently stick to CIS Bundled effort (cannot wait for v6 with full virtual... ).

Would rep + but thumbs up/down does not seem to be visible for me still?? Jack?? lol.
Find all posts by this user
Quote this message in a reply
10-31-2011, 05:18 AM
Post: #3
McLovin Offline
Gold Member (Level 7)
Posts: 7,647
Joined: Apr 2011
Kudos 1270
RE: [How To] Use Sandboxie
Thanks for the guide Nathan. I don't really use SandBoxie because when I had Avast I used their one.

McLovins' Configuration
Visit this user's website Find all posts by this user
Quote this message in a reply
10-31-2011, 07:35 AM
Post: #4
Exorcizm Offline
Hardcore Computer Tech
Posts: 496
Joined: Oct 2011
Kudos 46
RE: [How To] Use Sandboxie
Good Guide Nathan! I'm sure many people using that sandbox will find it useful! Smile
Find all posts by this user
Quote this message in a reply
04-26-2012, 02:41 PM
Post: #5
Overkill Offline
Advanced Member (Level 5)
Posts: 1,582
Joined: Feb 2012
Kudos 189
RE: [How To] Use Sandboxie
If I allow direct access to everything within my browser can malicious content slip through the sandbox?

In the browser settings what is NOT recommended to tick for direct access?

My Real-Time Protection
Windows Firewall Control | ESET NOD32 Antivirus | Mamutu
My Complete Config
Find all posts by this user
Quote this message in a reply
04-26-2012, 10:56 PM
Post: #6
McLovin Offline
Gold Member (Level 7)
Posts: 7,647
Joined: Apr 2011
Kudos 1270
RE: [How To] Use Sandboxie
(04-26-2012 02:41 PM)MRF71 wrote:  If I allow direct access to everything within my browser can malicious content slip through the sandbox?

In the browser settings what is NOT recommended to tick for direct access?

Your reply to a topic that was started in October last year.

McLovins' Configuration
Visit this user's website Find all posts by this user
Quote this message in a reply
04-27-2012, 12:06 AM
Post: #7
Littlebits Offline
Community Leader
Posts: 1,955
Joined: May 2011
Kudos 1682
RE: [How To] Use Sandboxie
Nice guide, I don't use Sandboxie on a daily basis, only when I want to run a suspicious program. I see no need to run trusted programs inside of a sandbox.

Thanks.Big Grin

Security Software Updater
My Config
No I don't change my config as often as some people change their underwear.
Visit this user's website Find all posts by this user
Quote this message in a reply
04-27-2012, 01:49 AM (This post was last modified: 04-27-2012 01:57 AM by bo.elam.)
Post: #8
bo.elam Offline
Silver Member (Level 6)
Posts: 829
Joined: May 2011
Kudos 443
RE: [How To] Use Sandboxie
(04-26-2012 02:41 PM)MRF71 wrote:  If I allow direct access to everything within my browser can malicious content slip through the sandbox?

In the browser settings what is NOT recommended to tick for direct access?
Every time that you allow direct access to something, you are opening a hole. That increases the chances that something could infect your machine. Personally, I only allow direct access to the phishing database and bookmarks. I allow that because it would be extremely inconvenient not to be able to save bookmarks and updating the phishing database would take a long time if direct access was not allowed. I do this on Firefox, on IE I only allow favorites.

I wont allow nothing else but most likely you would be OK allowing cookies, passwords or something like that but there is always a chance that something can hurt you when you allow direct access to something or if you recover a file and execute it.

Those are the only times that you can get hurt when you use Sandboxie and it is why I ALWAYS open up all my files in a sandbox, the only exceptions are when I install something or update a program.

Bo
Find all posts by this user
Quote this message in a reply
 Kudos from: McLovin(+3) , Earth(+1)
04-27-2012, 02:17 AM
Post: #9
HeffeD Offline
Community Leader
Posts: 1,664
Joined: Feb 2011
Kudos 851
RE: [How To] Use Sandboxie
(04-27-2012 01:49 AM)bo.elam wrote:  I only allow direct access to the phishing database and bookmarks.

This is what I do as well.

I also gave direct access to AdBlock Plus' extension folder so it is able to update the subscription blocklist databases. Otherwise you'll be downloading a new one each browsing session. Not a big deal bandwidth-wise because they are a small .txt file, but it puts unnecessary strain on the subscription servers.

I don't allow access to cookies, because it's nice to have those wiped along with everything else when I close the browser. (Yes, I'm aware you can set the browser to do this as well) If there is a persistent cookie I'd like to keep, I just start the browser outside the sandbox, set the cookie, then close the browser and restart in the sandbox.
Find all posts by this user
Quote this message in a reply
04-27-2012, 03:29 AM
Post: #10
bo.elam Offline
Silver Member (Level 6)
Posts: 829
Joined: May 2011
Kudos 443
RE: [How To] Use Sandboxie
(04-27-2012 02:17 AM)HeffeD wrote:  I also gave direct access to AdBlock Plus' extension folder so it is able to update the subscription blocklist databases.
You don't need to allow the whole Adblock folder in order for ABP updates to remain after deleting the sandbox, allowing the file "patterns" found inside the ABP folder is enough.

Bo
Find all posts by this user
Quote this message in a reply
 Kudos from: HeffeD(+2)
« Next Oldest | Next Newest »
Pages (6): 1 2 3 4 5 6 Next »
Post Reply 


Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  Does Sandboxie 4.01 need Drop Rights Enabled? ad18 12 538 04-25-2013 01:04 PM
Last Post: ad18
  Sandboxie Tip Gnosis 5 449 04-06-2013 02:06 PM
Last Post: blues
  Sandboxie Firefox freeze cptredsox 13 630 03-24-2013 02:05 AM
Last Post: Umbra Polaris
  Sandboxie Beta Latest Version 4.01 jamescv7 5 371 03-20-2013 02:33 AM
Last Post: Umbra Polaris
  Sandboxie "maybe" bypassed Umbra Polaris 1 242 03-15-2013 04:00 AM
Last Post: rebel4life

  • View a Printable Version
  • Send this Thread to a Friend
  • Subscribe to this thread


User(s) browsing this thread: 1 Guest(s)

 


Proudly powered by MyBB.
Copyright - MalwareTips.com © 2012. All rights reserved. | Webdesign by End Soft Design
Contact Us | Privacy policy | Return to Top | Return to Content | Lite (Archive) Mode | RSS Syndication | Members List | Forum Team

MalwareTips.com is an independent website.All trademarks mentioned on this page are the property of their respective owners.