

{"id":3788,"date":"2011-12-23T10:42:57","date_gmt":"2011-12-23T15:42:57","guid":{"rendered":"http:\/\/streamingradioguide.com\/startingover\/?p=3788"},"modified":"2011-12-23T10:46:13","modified_gmt":"2011-12-23T15:46:13","slug":"sandboxies-first-real-threat","status":"publish","type":"post","link":"https:\/\/streamingradioguide.com\/startingover\/?p=3788","title":{"rendered":"SandBoxie&#8217;s first real threat"},"content":{"rendered":"<p><a href=\"http:\/\/streamingradioguide.com\/startingover\/wp-content\/uploads\/2011\/12\/sandboxie11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3790\" title=\"sandboxie1\" src=\"http:\/\/streamingradioguide.com\/startingover\/wp-content\/uploads\/2011\/12\/sandboxie11.png\" alt=\"\" width=\"805\" height=\"562\" srcset=\"https:\/\/streamingradioguide.com\/startingover\/wp-content\/uploads\/2011\/12\/sandboxie11.png 805w, https:\/\/streamingradioguide.com\/startingover\/wp-content\/uploads\/2011\/12\/sandboxie11-300x209.png 300w\" sizes=\"auto, (max-width: 805px) 100vw, 805px\" \/><\/a><\/p>\n<p>For those playing along at home, I&#8217;ve been struggling with trying to find a reasonable way to protect my computer from random trojan \/ virus attacks as I wander bravely out onto the internet.<\/p>\n<p>Initiaully I started to use Fedora Linux for &#8220;dangerous&#8221; stuff &#8211; but now that disk drive is running the web site.\u00a0\u00a0 I still might go back to doing that.<\/p>\n<p>In the interim, I downloaded a program called SandboxIE<\/p>\n<p>http:\/\/www.sandboxie.com\/<\/p>\n<p>It&#8217;s apparently been around a while &#8211; it&#8217;s basically close to a rootkit, but that term carries a lot of baggage \ud83d\ude42\u00a0\u00a0\u00a0 What SandboxIE does is lets you start up any process inside the &#8220;Sandbox&#8221; &#8211; anything that process (or anything that process creates) stays stuck inside the sandbox.\u00a0\u00a0 It is blissfully unaware it it lives inside a fake Windows.\u00a0\u00a0 For you Linux fans, it&#8217;s roughly similar to a jailed chroot, but more thorough.\u00a0\u00a0 It&#8217;s watching updates to the registry, use of named pipes, probably many things I haven&#8217;t found het.\u00a0\u00a0\u00a0 When a program attempts to open a file with write access, the existing file is copied into the sandbox, so it looks &#8220;real&#8221;, but the original file is left protected outside the sandbox.<\/p>\n<p>Today, it got its first real test.\u00a0\u00a0\u00a0 While looking at a radio station web site (not hijacked, just hacked), Microsoft Security Essentials alerted to the thing up above&#8230;.\u00a0 okay, here we go&#8230;\u00a0\u00a0 I told MSE to &#8220;clean&#8221; the system, which it did, then looked at the history of the attack up above.<\/p>\n<p>Look carefully at the filename of the location of the trojan and you&#8217;ll see the magic of sandboxie &#8211; MSE still alerts because it caught the trojan as it was being writtne to the sandbox &#8211; the fake C: drive within the C: drive<\/p>\n<p>Anything that happened from that point on (had MSE not caught it) would still be operating under the control of Sandboxie.\u00a0\u00a0 Any &#8220;damage&#8221; it did or attempts to modify the registry would still just be modifying the sandbox.<\/p>\n<p>http:\/\/www.stopbadware.org\/<\/p>\n<p>reports this site was first reported to them by Google almost a month ago, and apparently is still not secured.<\/p>\n<p>So, in conclusion it passed the first real test.\u00a0\u00a0\u00a0\u00a0 It&#8217;s free, it&#8217;s pretty easy to use, and so far hasn&#8217;t broken anything.\u00a0\u00a0\u00a0 If you are running Windows, it&#8217;s worth giving a try.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For those playing along at home, I&#8217;ve been struggling with trying to find a reasonable way to protect my computer from random trojan \/ virus attacks as I wander bravely out onto the internet. Initiaully I started to use Fedora &hellip; <a href=\"https:\/\/streamingradioguide.com\/startingover\/?p=3788\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19,107],"tags":[],"class_list":["post-3788","post","type-post","status-publish","format-standard","hentry","category-about-the-guide","category-technology"],"_links":{"self":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts\/3788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3788"}],"version-history":[{"count":4,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts\/3788\/revisions"}],"predecessor-version":[{"id":3794,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts\/3788\/revisions\/3794"}],"wp:attachment":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}