[News] 0 day discovered in Sandboxie

Status
Not open for further replies.

Aura

Level 20
Thread author
Verified
Jul 29, 2014
966
Hey guys Aura here,

I was just wondering if you were aware that there's a 0-day in every version of Sandboxie right now. As it been reported it already or not ? If not, I'll add more information to it. If it is, just close this thread please.

It's a 0-day that have been discovered by one of my friend on HF. He reported it to Sandboxie but didn't get a reply for it yet. He made 2-3 videos showing it and even Teamviewed into one of my Windows 7 Professional SP1 64-bits VM to show me it and it worked flawlessly.

What do you think ?
 

WinXPert

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Jan 9, 2013
1,457
You mean the changes bleeding out of Sandboxie?
 

Aura

Level 20
Thread author
Verified
Jul 29, 2014
966
I saw a malware which displays windows outside the sandbox. It was uploaded in one of the packs.

Yes this one.
You can bypass Sandboxie and open a command prompt console (or any other programs I guess) outside of the Sandboxie environment, with Admin Rights too. IcYSeptember reported it on HF, I can link the thread or quote it here if needed for more information as well as link the videos (Youtube) ?
 

Malware1

Level 76
Sep 28, 2011
6,545
Yes this one.
You can bypass Sandboxie and open a command prompt console (or any other programs I guess) outside of the Sandboxie environment, with Admin Rights too. IcYSeptember reported it on HF, I can link the thread or quote it here if needed for more information as well as link the videos (Youtube) ?
Can you send me the thread link in a PM ?
 
D

Deleted member 178

Sbie with default setting let the process run but contain the changes to the system.

@Aura : what you mean by "a zero day in every version" , more details will be appreciated ^^
 

Aura

Level 20
Thread author
Verified
Jul 29, 2014
966
Sbie with default setting let the process run but contain the changes to the system.

@Aura : what you mean by "a zero day in every version" , more details will be appreciated ^^

Apparently, this vulnerability is present in the latest version of Sandboxie (that IcY used) and applies in all the ones prior to it.
He managed to create files directly on my desktop, not the desktop inside Sandboxie.

Can you PM me the link too @Aura ?

Yeah sure give me a few seconds.
 
  • Like
Reactions: WinXPert

cruelsister

Level 43
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 13, 2013
3,224
M!- if you find the sample discussed please let me know in which pack to find it.
 

Malware1

Level 76
Sep 28, 2011
6,545
Yeah sire, go ahead and post it here, it'll help.
I'll add IcY's videos too.
Ok, I'll have to find a good screen recorder that records UAC alerts (some display black screen, the video would look fake then).
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top