is this a hole in sandboxie?

Discussion in 'sandboxing & virtualization' started by Konata Izumi, Sep 30, 2011.

Thread Status:
Not open for further replies.
  1. AvinashR

    AvinashR Registered Member

    Joined:
    Dec 26, 2009
    Posts:
    2,063
    Location:
    New Delhi Metallo β-Lactamase 1
    Thanks m00nbl00d. I was not aware of Tzuk's comment! :)
     
  2. Konata Izumi

    Konata Izumi Registered Member

    Joined:
    Nov 23, 2008
    Posts:
    1,563
    just additional info:

    if you create the long path folder inside Sandbox container folder (C:\Sandbox\User\Default\longfoldernameHERE\myPOC.pdf)

    it won't execute for some reason, so I think it's not critical.

    -----------------------

    the "file-running-unsandboxed" hole only happens if the file-to-be-executed is placed on a long path directory anywhere outside Sandboxie container folder.

    EXE files will give SBIE2205 Service not Implemented: LoadedModules message from Sandboxie.

    affected feature(s):
    Forced Folders
     
    Last edited: Oct 7, 2011
  3. soccerfan

    soccerfan Registered Member

    Joined:
    Oct 15, 2007
    Posts:
    585
    A couple of questions:

    1. Re sbie problem: What foldername length (how many characters) must one exceed for the problem to appear?

    2. Generally: Is there a way (a registry fix?) in XP/win7 to have windows limit the number of characters in naming a folder?

    Thanks
     
  4. RJK3

    RJK3 Registered Member

    Joined:
    Apr 4, 2011
    Posts:
    862
    Thanks for that quote moonblood.

    Interesting discussion, but I must say I've instinctively never relied on the 'forced folders' for non executables either. It seemed too indirect.

    All the major media/document file extensions other than images have their programs running in a Sandbox so it's not much of an issue for me. Good on whomever for identifying the weakness though.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.