Help - Search - Members - Calendar
Full Version: DW, Sandboxiw, Windows 7 conflict.
Gladiator Security Forum > SoftSphere Technologies Support Forums > DefenseWall HIPS
hawkwind
Hi, i posted this at sandboxies forum.

QUOTE
I have just started using Windows 7.
Using the latest beta .23.
I use defensewall 2.56.
If i download anything when sandboxed, then defensewall does not flag the download as untrusted when the files are recovered from the sandbox.

The two programs seem to work perfectly together in XP.

I have tried adding C:\sandboxie to defensewalls untrusted list but still all downloads are not flagged as untrusted once recovered.
Browsers/download managers are also running as untrusted in defensewall.


tzuk replied
QUOTE
Tony, the Sandboxie Control problem is a "normal" application, as it is not operating within the sandbox. When it moves files from one location to another, it's just like your Windows Explorer moving files from one location to another. Therefore, I think you should bring this problem to the attention of the developer of DefenseWall rather than to me.


Defensewall works just fine by itself, problems only occur when run alongside sandboxie.

One thing i have noticed is that the files i download when using SB appear in file and registry tracks but they do not appear in the untrusted list, nor do they run as untrusted.
Ilya Rabinovich
Do you running DW in the Expert or normal mode? I just installed SBIE under Win7 and have had no issues with running both and keeping the untrusted status.
hawkwind
No Ilya, not running as expert mode
hawkwind
I have just uninstalled ersasing all settings.
Reinstalled
Problem still exists, the download does not show in untrusted applications and runs as trusted.
Ilya Rabinovich
This case I need step by step guide on how to reproduce the issue.
hawkwind
I am not doing anything out of the ordinary to make this happen Ilya.
In fact current i am running the same configuration in Windows 7 as i am in XP and Vista for both Sandboxie and Defensewall.
The only difference is i am using the latest beta version of sandboxie as the 3.38 version does not support windows 7.
hawkwind
I have quick recovery set to my downloads folder.
Immediate recovery is enabled.

Web browser opens sandboxed and untrusted by DW.
I download a file, quick recovery box pops up and i save it to my downloads folder.

Now if i run the file it runs trusted and it does not show in my untrusted list.
Ilya Rabinovich
What's the file you download or it doesn't matter?
hawkwind
It does not matter which file or type of file, exe, zip, rar etc.
Ilya Rabinovich
OK, one thing I still missing- what's your Win7 build?
hawkwind
Windows 7 Ultimate build 7600
Ilya Rabinovich
OK, I did download Win7 build 7600 and install both the latest SBIE and DW under it. Have had no single issue with this setup, untrusted attribute inherition is fine.

So, the only thing I can advise you here is to wait until the official V3 beta is out.
hawkwind
Ok thanks Ilya.
I dont suppose there is any chance of trying the Version 3 now is there?
I understand if you dont want me to though :)
Ilya Rabinovich
Just wait a bit until I'll make skinning.
hawkwind
ok good.gif
hawkwind
One thing i have found.

I always save my downloads to partion (D) that is seperate from my operating system ©

I have just out of curiosity placed some downloads on my desktop(C Drive) and all downloads are flagged as untrusted.
I then downloaded the same files to my D Drive and all files are trusted?
Ilya Rabinovich
Interesting. This case I need more information- where exactly on D you did download files? What this drive is- non-removable or anything else?
hawkwind
C and D are on the same hard drive, i have partitioned the drive 110 gb C partition and 80 gb D partition.
The D partition is soley kept for photographs, games, work related files/documents, downloaded files e.g Programs pictures etc all kept in seperate folders.
I will plug in a usb hard drive now download to it and post back the results.
hawkwind
I have just downloaded files to a usb hard drive which is again split into two partitions, from an untrusted and sandboxed browser (Firefox)
Once again The files downloaded to both partitions do not show in the untrusted list.

So it would appear that only files downloaded to my C drive/partition are saved as untrusted when Defensewall and Sandboxie are used together on Windows 7.
Ilya Rabinovich
It's OK for the external hard drives as, if "automatically run from removable sources as untrusted" is set, the drive is untrusted by default.

Will try to reproduce the issue with one more hard drive emulation.
hawkwind
Ok thanks Ilya.
Ilya Rabinovich
Thank you for your report. The issue is reproduced, isolated and fixed. The version improved will be v3.00. Just wait a bit, I still not feel good after I was ill recently.
hawkwind
Thanks Ilya :)
Looking forward to version 3.00.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.