Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Software
Security Apps
Other security for Windows, Mac, Linux
Why does Sandboxie sometimes require admin permissions when running something that requires it?
Message
<blockquote data-quote="Andy Ful" data-source="post: 928348" data-attributes="member: 32260"><p>If you execute an application installer via Sandboxie ("Run sandboxed") and the installer requires Admin rights, then before executing the installer, the Sandboxie process asks for Admin rights (Sandboxie alert + UAC prompt). The Sandboxie alert disappears very quickly and looks like:</p><p>[ATTACH=full]253703[/ATTACH]</p><p></p><p>The UAC prompt is also triggered by Sandboxie process (not by the installer). </p><p>Next, the application installer itself does not ask for elevation any more (no additional UAC prompt), because it thinks that it has been run by the parent process with Admin rights.</p><p>Default Sandbox allows thinking applications that they can run with Admin rights so they can write to the virtualized HKLM registry hive and virtualized Program Files folder. In fact, they are running with an Untrusted Integrity level into the sandbox. <img src="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" class="smilie smilie--sprite smilie--sprite130" alt="(y)" title="Thumbs up (y)" loading="lazy" data-shortname="(y)" /></p><p></p><p>Usually, Sandboxie is not used to run installers sandboxed, but the installer installs the application into the real system. Next, the already installed application is run sandboxed (usually without asking Admin rights).</p><p></p><p>Edit.</p><p>Many application installers do not require Admin rights. In such cases, they are usually installed in the ProgramData folder or user Appdata folder.</p></blockquote><p></p>
[QUOTE="Andy Ful, post: 928348, member: 32260"] If you execute an application installer via Sandboxie ("Run sandboxed") and the installer requires Admin rights, then before executing the installer, the Sandboxie process asks for Admin rights (Sandboxie alert + UAC prompt). The Sandboxie alert disappears very quickly and looks like: [ATTACH type="full"]253703[/ATTACH] The UAC prompt is also triggered by Sandboxie process (not by the installer). Next, the application installer itself does not ask for elevation any more (no additional UAC prompt), because it thinks that it has been run by the parent process with Admin rights. Default Sandbox allows thinking applications that they can run with Admin rights so they can write to the virtualized HKLM registry hive and virtualized Program Files folder. In fact, they are running with an Untrusted Integrity level into the sandbox. (y) Usually, Sandboxie is not used to run installers sandboxed, but the installer installs the application into the real system. Next, the already installed application is run sandboxed (usually without asking Admin rights). Edit. Many application installers do not require Admin rights. In such cases, they are usually installed in the ProgramData folder or user Appdata folder. [/QUOTE]
Insert quotes…
Verification
Post reply
Top