| Sandboxie: Stay free of malwares |
|
|
|
| Thursday, 06 July 2006 | ||||||
|
We enabled Sandboxie and entered in a famous crackers website in order to verify how the software works, then in the main page of the visited website, a popup in JavaScript appeared as soon as the execution of a application in JAVA had begun. When Java was enabled by sandbox, it thent created an archive of log of normal java routines and a temporary archives inside the subfolders of "sandbox". After this, the website started trying to install a Trojan downloader in the system through a buffer overflow. Since it was not possible, because Sandboxie doesn't use COM calls from windows, two programs : SandboxieRpcSs and SandboxieDcomLaunch were used to provide a sample of sandbox COM framework. So, in case the installation of the Trojan wasn't successful, a window would have appeared requiring to make the download of that application. We downloaded it on the folder called "My Documents" - that was also a special folder of sandbox. This type of archive is very common among crackers to get remote access across a computer that is not patched for Windows security issues. And when it is successfully installed, it opens a specific door that allows a cracker to control computer remotely. We allowed the execution of this archive for testing purpose only, and it happened exactly what we foresaw. It was blocked because it made Windows COM Framework calls functions but it didn't work because software calls were under the environment created by sandbox COM function. We tested a common Trojan Horse in many computers around the world known as TROJ_VB.AU and a key logger PROAGENT V2.0, a world famous tool used by carders and bankers to create keyloggers servers to send bank numbers and card numbers to crackers, and the viruses that had been downloaded in this crackers site. When we tryed executing server.exe , a virus attempted to install itself into the register and to create a default folder inside SYSTEM32 directory and to place its inflected files. But all these attempts had been automatically blocked hindering the execution of virus and the infestation of the machine. The sofware contains an application called start.exe, that can be use like that "C:\Program Files\Sandboxie\Start" "path-and-name-of-program-to-invoke.exe" that can be used by an administrator . Starting any application through the command line, likes browser or mail software, will determine a sufficiently useful software inside of those corporations that will sufficiently have related incidence of virus. Sandiboxie can be download here Normal software function: Crackers site buffer overflow window: Process list:
Powered by a Zone-H(ified) version of AkoComment 3.0! DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice. |
||||||
| < Prev | Next > |
|---|




Zone-H successfully tested a software named Sandboxie that helps the users to prevent the attacks of digital malwares as virus, worms and trojans.










