Trust No Program
This topic is locked: you cannot edit posts or make replies.
Can't run K-Meleon 1.5.1 sandboxed :(
PiCo


Joined: 09 Jun 2008
Posts: 63
Reply with quote
I'm on Vista Business 32-bit. I installed K-meleon. When I right click on it and choose "Run Sandboxed" CPU usage spikes at 100% and nothing happens, no error messages, the cpu just works and works with no result.

I opened Sandboxie control to view what was happening. I went to view -> programms and I noticed that every second a new K-meleon process was being created with a different PID replacing the old one!

What does this mean? It's like sandboxie tries and tries to run K-meleon and K-meleon.exe keeps crashing!

Can anyone confirm this?

Thank you very mmuch!
Mike
View user's profileSend private message
perplexed


Joined: 19 Oct 2008
Posts: 3
Location: 3rd rock from sol
Reply with quote
Confirmed. No problems with K-Meleon v1.5.0.

K-Meleon v1.5.1
Sandboxie v3.30
Windows Xp Pro SP2 fully patched
Both Admin and Limited-User Accounts

Heres output from my HIPS:

13:07:59 [EXECUTION] "c:\program files\sandboxie\start.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [2032]
[EXECUTION] Commandline - [ "c:\program files\sandboxie\start.exe" /box:__ask__ "c:\program files\k-meleon\k-meleon.exe" ]
13:07:59 [EXECUTION] "c:\program files\sandboxie\sbiectrl.exe" was allowed to run
[EXECUTION] Started by "c:\program files\sandboxie\start.exe" [1648]
[EXECUTION] Commandline - [ "c:\program files\sandboxie\sbiectrl.exe" ]
13:08:02 [EXECUTION] "c:\program files\k-meleon\k-meleon.exe" was allowed to run
[EXECUTION] Started by "c:\program files\sandboxie\start.exe" [1648]
[EXECUTION] Commandline - [ "c:\program files\k-meleon\k-meleon.exe" ]
13:08:04 [EXECUTION] "c:\program files\k-meleon\k-meleon.exe" was allowed to run
[EXECUTION] Started by "Unknown Process" [1528]
[EXECUTION] Commandline - [ "c:\program files\k-meleon\k-meleon.exe" ]
13:08:04 [EXECUTION] "c:\program files\k-meleon\k-meleon.exe" was allowed to run
[EXECUTION] Started by "Unknown Process" [1772]
[EXECUTION] Commandline - [ "c:\program files\k-meleon\k-meleon.exe" ]
13:08:04 [EXECUTION] "c:\program files\k-meleon\k-meleon.exe" was allowed to run
[EXECUTION] Started by "Unknown Process" [1636]
[EXECUTION] Commandline - [ "c:\program files\k-meleon\k-meleon.exe" ]
13:08:05 [EXECUTION] "c:\program files\k-meleon\k-meleon.exe" was allowed to run
[EXECUTION] Started by "Unknown Process" [772]
[EXECUTION] Commandline - [ "c:\program files\k-meleon\k-meleon.exe" ]
13:08:05 [EXECUTION] "c:\program files\k-meleon\k-meleon.exe" was allowed to run
[EXECUTION] Started by "Unknown Process" [768]
[EXECUTION] Commandline - [ "c:\program files\k-meleon\k-meleon.exe" ]
...

Oh yeah, here's HIPS output for K-Meleon v1.5.0:

07:10:34 [EXECUTION] "c:\program files\sandboxie\start.exe" was allowed to run
[EXECUTION] Started by "c:\windows\explorer.exe" [1664]
[EXECUTION] Commandline - [ "c:\program files\sandboxie\start.exe" /box:__ask__ "c:\program files\k-meleon\k-meleon.exe" ]
07:10:34 [EXECUTION] "c:\program files\sandboxie\sbiectrl.exe" was allowed to run
[EXECUTION] Started by "c:\program files\sandboxie\start.exe" [132]
[EXECUTION] Commandline - [ "c:\program files\sandboxie\sbiectrl.exe" ]
07:10:38 [EXECUTION] "c:\program files\k-meleon\k-meleon.exe" was allowed to run
[EXECUTION] Started by "c:\program files\sandboxie\start.exe" [132]
[EXECUTION] Commandline - [ "c:\program files\k-meleon\k-meleon.exe" ]
07:10:41 [EXECUTION] "c:\program files\sandboxie\sandboxierpcss.exe" was allowed to run
[EXECUTION] Started by "c:\program files\k-meleon\k-meleon.exe" [200]
[EXECUTION] Commandline - [ "c:\program files\sandboxie\sandboxierpcss.exe" ]
07:10:41 [EXECUTION] "c:\program files\sandboxie\sandboxiedcomlaunch.exe" was allowed to run
[EXECUTION] Started by "c:\program files\sandboxie\sandboxierpcss.exe" [216]
[EXECUTION] Commandline - [ "c:\program files\sandboxie\sandboxiedcomlaunch.exe" ]

One last piece of information. For K-Meleon v1.5.1, the sandbox folder contains files 'RegHive.LOG' and 'RegHive' and folder 'user', but no 'Application Data' (e.g., bookmarks) under 'user'.


Last edited by perplexed on Sun Oct 19, 2008 8:51 pm; edited 1 time in total
View user's profileSend private message
Guest10


Joined: 27 Apr 2008
Posts: 4340
Location: Ohio, USA
Reply with quote
K-Meleon used to work when installed in a sandbox. Now it doesn't work for me, either,
K-M v1.5.1, SB 3.31.06, XP Pro SP3

[Edit] I've tried it with SB 3.28 and 3.30, and K-Meleon doesn't work when installed in a sandbox with either one. Previously I had K-Meleon v1.1.6 working in a sandbox, but not this version.[/Edit]


Last edited by Guest10 on Sun Oct 19, 2008 9:20 pm; edited 1 time in total

_________________
Paul
XP Pro SP3 (Admin rights), Zone Alarm Pro Firewall, Malwarebytes Pro, Firefox 21, Thunderbird 17
View user's profileSend private message
SnDPhoenix


Joined: 26 Dec 2006
Posts: 2694
Location: West Florida
Reply with quote
Yeah strange, I had k-meleon installed in a sandbox along with "TheWorld" browser and k-meleon worked fine before, now it doesn't here either... Confused
View user's profileSend private message
Guest10


Joined: 27 Apr 2008
Posts: 4340
Location: Ohio, USA
Reply with quote
I had a heck of a time terminating K-M this time. I had the Resource Access Monitor running, when I started K-M:
(Drive) \Device\CdRom0
(Drive) \Device\CdRom1
(Drive) \Device\Floppy0
(Drive) \Device\HarddiskVolume1
(Drive) \Device\RVDISKVolumeY
(Unk) 00000022 \Device\SandboxieDriverApi
(Unk) 00000039 \Device\KsecDD
Clsid -------------------------------
Ipc -------------------------------
Ipc \BaseNamedObjects\K-Meleon Instance Mutex
Ipc \BaseNamedObjects\SbieDllDummyEvent_1184
Ipc \BaseNamedObjects\SbieDllDummyEvent_1208
Ipc \BaseNamedObjects\SbieDllDummyEvent_1228
Ipc \BaseNamedObjects\SbieDllDummyEvent_1348
Ipc \BaseNamedObjects\SbieDllDummyEvent_1488
Ipc \BaseNamedObjects\SbieDllDummyEvent_1556
Ipc \BaseNamedObjects\SbieDllDummyEvent_1596
Ipc \BaseNamedObjects\SbieDllDummyEvent_1680
Ipc \BaseNamedObjects\SbieDllDummyEvent_1780
Ipc \BaseNamedObjects\SbieDllDummyEvent_1832
Ipc \BaseNamedObjects\SbieDllDummyEvent_1856
Ipc \BaseNamedObjects\SbieDllDummyEvent_1876
Ipc \BaseNamedObjects\SbieDllDummyEvent_188
Ipc \BaseNamedObjects\SbieDllDummyEvent_1880
Ipc \BaseNamedObjects\SbieDllDummyEvent_1884
Ipc \BaseNamedObjects\SbieDllDummyEvent_2036
Ipc \BaseNamedObjects\SbieDllDummyEvent_2060
Ipc \BaseNamedObjects\SbieDllDummyEvent_2088
Ipc \BaseNamedObjects\SbieDllDummyEvent_2160
Ipc \BaseNamedObjects\SbieDllDummyEvent_2168
Ipc \BaseNamedObjects\SbieDllDummyEvent_2176
Ipc \BaseNamedObjects\SbieDllDummyEvent_2220
Ipc \BaseNamedObjects\SbieDllDummyEvent_2244
Ipc \BaseNamedObjects\SbieDllDummyEvent_2272
Ipc \BaseNamedObjects\SbieDllDummyEvent_2304
Ipc \BaseNamedObjects\SbieDllDummyEvent_2308
Ipc \BaseNamedObjects\SbieDllDummyEvent_2320
Ipc \BaseNamedObjects\SbieDllDummyEvent_2368
Ipc \BaseNamedObjects\SbieDllDummyEvent_2376
Ipc \BaseNamedObjects\SbieDllDummyEvent_244
Ipc \BaseNamedObjects\SbieDllDummyEvent_248
Ipc \BaseNamedObjects\SbieDllDummyEvent_2576
Ipc \BaseNamedObjects\SbieDllDummyEvent_2600
Ipc \BaseNamedObjects\SbieDllDummyEvent_2608
Ipc \BaseNamedObjects\SbieDllDummyEvent_2652
Ipc \BaseNamedObjects\SbieDllDummyEvent_2684
Ipc \BaseNamedObjects\SbieDllDummyEvent_2700
Ipc \BaseNamedObjects\SbieDllDummyEvent_2724
Ipc \BaseNamedObjects\SbieDllDummyEvent_2732
Ipc \BaseNamedObjects\SbieDllDummyEvent_2736
Ipc \BaseNamedObjects\SbieDllDummyEvent_2740
Ipc \BaseNamedObjects\SbieDllDummyEvent_2752
Ipc \BaseNamedObjects\SbieDllDummyEvent_2804
Ipc \BaseNamedObjects\SbieDllDummyEvent_2940
Ipc \BaseNamedObjects\SbieDllDummyEvent_2948
Ipc \BaseNamedObjects\SbieDllDummyEvent_2988
Ipc \BaseNamedObjects\SbieDllDummyEvent_2992
Ipc \BaseNamedObjects\SbieDllDummyEvent_300
Ipc \BaseNamedObjects\SbieDllDummyEvent_3000
Ipc \BaseNamedObjects\SbieDllDummyEvent_3004
Ipc \BaseNamedObjects\SbieDllDummyEvent_3056
Ipc \BaseNamedObjects\SbieDllDummyEvent_3064
Ipc \BaseNamedObjects\SbieDllDummyEvent_3080
Ipc \BaseNamedObjects\SbieDllDummyEvent_3144
Ipc \BaseNamedObjects\SbieDllDummyEvent_3156
Ipc \BaseNamedObjects\SbieDllDummyEvent_3248
Ipc \BaseNamedObjects\SbieDllDummyEvent_3388
Ipc \BaseNamedObjects\SbieDllDummyEvent_3400
Ipc \BaseNamedObjects\SbieDllDummyEvent_3412
Ipc \BaseNamedObjects\SbieDllDummyEvent_3448
Ipc \BaseNamedObjects\SbieDllDummyEvent_3472
Ipc \BaseNamedObjects\SbieDllDummyEvent_3480
Ipc \BaseNamedObjects\SbieDllDummyEvent_3484
Ipc \BaseNamedObjects\SbieDllDummyEvent_3552
Ipc \BaseNamedObjects\SbieDllDummyEvent_3568
Ipc \BaseNamedObjects\SbieDllDummyEvent_3620
Ipc \BaseNamedObjects\SbieDllDummyEvent_3632
Ipc \BaseNamedObjects\SbieDllDummyEvent_3692
Ipc \BaseNamedObjects\SbieDllDummyEvent_3700
Ipc \BaseNamedObjects\SbieDllDummyEvent_3704
Ipc \BaseNamedObjects\SbieDllDummyEvent_3732
Ipc \BaseNamedObjects\SbieDllDummyEvent_3740
Ipc \BaseNamedObjects\SbieDllDummyEvent_3752
Ipc \BaseNamedObjects\SbieDllDummyEvent_3776
Ipc \BaseNamedObjects\SbieDllDummyEvent_3792
Ipc \BaseNamedObjects\SbieDllDummyEvent_3812
Ipc \BaseNamedObjects\SbieDllDummyEvent_3816
Ipc \BaseNamedObjects\SbieDllDummyEvent_3852
Ipc \BaseNamedObjects\SbieDllDummyEvent_3856
Ipc \BaseNamedObjects\SbieDllDummyEvent_3860
Ipc \BaseNamedObjects\SbieDllDummyEvent_3892
Ipc \BaseNamedObjects\SbieDllDummyEvent_3900
Ipc \BaseNamedObjects\SbieDllDummyEvent_3936
Ipc \BaseNamedObjects\SbieDllDummyEvent_4048
Ipc \BaseNamedObjects\SbieDllDummyEvent_4064
Ipc \BaseNamedObjects\SbieDllDummyEvent_4084
Ipc \BaseNamedObjects\SbieDllDummyEvent_516
Ipc \BaseNamedObjects\SbieDllDummyEvent_668
Ipc \BaseNamedObjects\SbieDllDummyEvent_712
Ipc \BaseNamedObjects\SbieDllDummyEvent_720
Ipc \BaseNamedObjects\SbieDllDummyEvent_768
Ipc \BaseNamedObjects\SbieDllDummyEvent_864
Ipc \BaseNamedObjects\SbieDllDummyEvent_872
Ipc \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
Ipc O \BaseNamedObjects\ShimCacheMutex
Ipc O \BaseNamedObjects\ShimSharedMemory
Ipc O \KnownDlls\advapi32.dll
Ipc O \KnownDlls\comdlg32.dll
Ipc O \KnownDlls\gdi32.dll
Ipc O \KnownDlls\kernel32.dll
Ipc O \KnownDlls\msvcrt.dll
Ipc O \KnownDlls\ole32.dll
Ipc O \KnownDlls\oleaut32.dll
Ipc O \KnownDlls\rpcrt4.dll
Ipc O \KnownDlls\Secur32.dll
Ipc O \KnownDlls\shell32.dll
Ipc O \KnownDlls\SHLWAPI.dll
Ipc O \KnownDlls\user32.dll
Ipc O \KnownDlls\version.dll
Ipc O \NLS\NlsSectionCType
Ipc O \NLS\NlsSectionLocale
Ipc O \NLS\NlsSectionSortkey
Ipc O \NLS\NlsSectionSortTbls
Ipc O \NLS\NlsSectionUnicode
Ipc O \ThemeApiPort
Ipc O \Windows\ApiPort
Pipe -------------------------------
WinCls -------------------------------
WinCls X Progman
View user's profileSend private message
soccerfan


Joined: 25 Sep 2007
Posts: 421
Reply with quote
I can also confirm the problems with km 1.5.1 in this thread.
KM hangs and sometimes is difficult to terminate.
I have no problems using km 1.5 and 1.1.3 (portable).

I've tried v 3.31.04 and also the latest beta 3.31.06.
I tried it on XP SP1 (my desktop) and XP SP2 (new laptop).

Edit: I just posted a link to this thread in the kmeleon forum too
because it may be a km1.5.1 bug rather that a sandboxie problem.

http://kmeleon.sourceforge.net/forum/read.php?3,84752


Last edited by soccerfan on Sun Oct 19, 2008 10:58 pm; edited 1 time in total

_________________
soccerfan
View user's profileSend private message
perplexed


Joined: 19 Oct 2008
Posts: 3
Location: 3rd rock from sol
Reply with quote
K-Meleon runs "just fine" outside of Sandboxie, but has great problems running inside Sandboxie.

From the K-Meleon forum:
http://kmeleon.sourceforge.net/forum/read.php?1,84647
Import 1.5.0 profile to 1.5.1 installtion
Posted by: caktus
Date: October 18, 2008 09:39AM
"I do have a question regarding unknown traffic perhaps some one can help me with. I just finished saving about two dozen tabs to a folder. Although all tabs had completely loaded, saved and had been closed, Zone Alarm Firewall and the Internet connection icon as well as connection Status indicated constant incoming and outgoing traffic. I do not believe I have ever seen this happen before. Zone Alarm indicated "K-Meleon listening to port(s): 3944, 3946." Constant incoming and outgoing traffic was indicated for about two minutes when I finally disconnected from the Internet. I perform ALL updating manually and to the best of my knowledge, nothing should have been running in the background. Does it sound like this may be a problem?

Disquieting?!
View user's profileSend private message
djg05


Joined: 01 Dec 2007
Posts: 27
Reply with quote
I am also having problems with the latest K Melon. It was fine before upgrading, now with the upgrade and SB it goes into an enless loop and the only way out is to reboot. As others have said, there is no problem outside SB 3.30

_________________
Regards

David
View user's profileSend private message
perplexed


Joined: 19 Oct 2008
Posts: 3
Location: 3rd rock from sol
Reply with quote
Ran k-meleon directly, without invoking sandboxie. Have to reboot to stop k-meleon.exe if invoked with sandboxie.

--------------------------------
Sysinternal Process Monitor 2.01
--------------------------------

Admin Account
-------------
12:21:37.6713465 PM k-meleon.exe 972 Process Start SUCCESS Parent PID: 1880
12:21:37.6713515 PM k-meleon.exe 972 Thread Create SUCCESS Thread ID: 372
12:21:37.6892957 PM k-meleon.exe 972 QueryNameInformationFile C:\Program Files\K-Meleon\k-meleon.exe SUCCESS Name: \Program Files\K-Meleon\k-meleon.exe
12:21:37.6894301 PM k-meleon.exe 972 RegOpenKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders SUCCESS Desired Access: Read, Maximum Allowed
12:21:37.6894971 PM k-meleon.exe 972 RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData SUCCESS Type: REG_EXPAND_SZ, Length: 62, Data: %USERPROFILE%\Application Data
12:21:37.6895295 PM k-meleon.exe 972 RegCloseKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders SUCCESS
12:21:37.6895471 PM k-meleon.exe 972 RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004 SUCCESS Desired Access: Read, Maximum Allowed
12:21:37.6895879 PM k-meleon.exe 972 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath BUFFER OVERFLOW Length: 130
12:21:37.6896052 PM k-meleon.exe 972 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath SUCCESS Type: REG_EXPAND_SZ, Length: 86, Data: %SystemDrive%\Documents and Settings\owner
12:21:37.6896251 PM k-meleon.exe 972 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004 SUCCESS
12:21:37.6896407 PM k-meleon.exe 972 RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion SUCCESS Desired Access: Read, Maximum Allowed
12:21:37.6896717 PM k-meleon.exe 972 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot SUCCESS Type: REG_SZ, Length: 22, Data: C:\WINDOWS
12:21:37.6896935 PM k-meleon.exe 972 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion SUCCESS
12:21:37.6897910 PM k-meleon.exe 972 RegOpenKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders SUCCESS Desired Access: Read, Maximum Allowed
12:21:37.6898290 PM k-meleon.exe 972 RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData SUCCESS Type: REG_EXPAND_SZ, Length: 62, Data: %USERPROFILE%\Application Data
12:21:37.6898528 PM k-meleon.exe 972 RegCloseKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders SUCCESS
12:21:37.6898687 PM k-meleon.exe 972 RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004 SUCCESS Desired Access: Read, Maximum Allowed
12:21:37.6899019 PM k-meleon.exe 972 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath BUFFER OVERFLOW Length: 130
12:21:37.6899176 PM k-meleon.exe 972 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath SUCCESS Type: REG_EXPAND_SZ, Length: 86, Data: %SystemDrive%\Documents and Settings\owner
12:21:37.6899366 PM k-meleon.exe 972 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004 SUCCESS
12:21:37.6899514 PM k-meleon.exe 972 RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion SUCCESS Desired Access: Read, Maximum Allowed
12:21:37.6899804 PM k-meleon.exe 972 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot SUCCESS Type: REG_SZ, Length: 22, Data: C:\WINDOWS
12:21:37.6899997 PM k-meleon.exe 972 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion SUCCESS
...
12:21:37.7233590 PM k-meleon.exe 972 CreateFile C:\SANDBOX NAME NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
12:21:37.7234285 PM k-meleon.exe 972 CreateFile C:\SANDBOX\USERNAME\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
12:21:37.7234875 PM k-meleon.exe 972 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
12:21:37.7235459 PM k-meleon.exe 972 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
12:21:37.7236045 PM k-meleon.exe 972 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
12:21:37.7236892 PM k-meleon.exe 972 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\APPLICATION DATA\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
12:21:37.7237490 PM k-meleon.exe 972 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\APPLICATION DATA\K-MELEON\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
12:21:37.7238166 PM k-meleon.exe 972 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\APPLICATION DATA\K-MELEON\DEFAULT\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
12:21:37.7238769 PM k-meleon.exe 972 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\APPLICATION DATA\K-MELEON\DEFAULT\U5OZXR2M.SLT\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
...

Excerpt (Buffer Overflow):
12:21:37.6895879 PM k-meleon.exe 972 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath BUFFER OVERFLOW Length: 130

Admin Account using DropMyRights
--------------------------------
11:56:28.8653609 AM k-meleon.exe 1356 Process Start SUCCESS Parent PID: 1344
11:56:28.8653660 AM k-meleon.exe 1356 Thread Create SUCCESS Thread ID: 1448
11:56:28.8868086 AM k-meleon.exe 1356 QueryNameInformationFile C:\Program Files\K-Meleon\k-meleon.exe SUCCESS Name: \Program Files\K-Meleon\k-meleon.exe
11:56:28.8869248 AM k-meleon.exe 1356 RegOpenKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders SUCCESS Desired Access: Read, Maximum Allowed
11:56:28.8869941 AM k-meleon.exe 1356 RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData SUCCESS Type: REG_EXPAND_SZ, Length: 62, Data: %USERPROFILE%\Application Data
11:56:28.8870265 AM k-meleon.exe 1356 RegCloseKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders SUCCESS
11:56:28.8870441 AM k-meleon.exe 1356 RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004 SUCCESS Desired Access: Read, Maximum Allowed
11:56:28.8870863 AM k-meleon.exe 1356 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath BUFFER OVERFLOW Length: 130
11:56:28.8871034 AM k-meleon.exe 1356 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath SUCCESS Type: REG_EXPAND_SZ, Length: 86, Data: %SystemDrive%\Documents and Settings\owner
11:56:28.8871240 AM k-meleon.exe 1356 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004 SUCCESS
11:56:28.8871397 AM k-meleon.exe 1356 RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion SUCCESS Desired Access: Read, Maximum Allowed
11:56:28.8871704 AM k-meleon.exe 1356 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot SUCCESS Type: REG_SZ, Length: 22, Data: C:\WINDOWS
11:56:28.8871925 AM k-meleon.exe 1356 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion SUCCESS
11:56:28.8872877 AM k-meleon.exe 1356 RegOpenKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders SUCCESS Desired Access: Read, Maximum Allowed
11:56:28.8873255 AM k-meleon.exe 1356 RegQueryValue HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData SUCCESS Type: REG_EXPAND_SZ, Length: 62, Data: %USERPROFILE%\Application Data
11:56:28.8873489 AM k-meleon.exe 1356 RegCloseKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders SUCCESS
11:56:28.8873651 AM k-meleon.exe 1356 RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004 SUCCESS Desired Access: Read, Maximum Allowed
11:56:28.8873981 AM k-meleon.exe 1356 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath BUFFER OVERFLOW Length: 130
11:56:28.8874135 AM k-meleon.exe 1356 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath SUCCESS Type: REG_EXPAND_SZ, Length: 86, Data: %SystemDrive%\Documents and Settings\owner
11:56:28.8874325 AM k-meleon.exe 1356 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004 SUCCESS
11:56:28.8874475 AM k-meleon.exe 1356 RegOpenKey HKLM\Software\Microsoft\Windows NT\CurrentVersion SUCCESS Desired Access: Read, Maximum Allowed
11:56:28.8874766 AM k-meleon.exe 1356 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot SUCCESS Type: REG_SZ, Length: 22, Data: C:\WINDOWS
11:56:28.8874959 AM k-meleon.exe 1356 RegCloseKey HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion SUCCESS
...
11:56:28.9175486 AM k-meleon.exe 1356 CreateFile C:\SANDBOX NAME NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
11:56:28.9176159 AM k-meleon.exe 1356 CreateFile C:\SANDBOX\USERNAME\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
11:56:28.9176729 AM k-meleon.exe 1356 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
11:56:28.9177296 AM k-meleon.exe 1356 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
11:56:28.9177860 AM k-meleon.exe 1356 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
11:56:28.9178433 AM k-meleon.exe 1356 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\APPLICATION DATA\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
11:56:28.9179025 AM k-meleon.exe 1356 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\APPLICATION DATA\K-MELEON\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
11:56:28.9179612 AM k-meleon.exe 1356 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\APPLICATION DATA\K-MELEON\DEFAULT\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
11:56:28.9180201 AM k-meleon.exe 1356 CreateFile C:\SANDBOX\USERNAME\SANDBOXNAME\USER\CURRENT\APPLICATION DATA\K-MELEON\DEFAULT\U5OZXR2M.SLT\ PATH NOT FOUND Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Directory, Synchronous IO Non-Alert, Open For Backup, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a
...

Excerpt (Buffer Overflow):
11:56:28.8870863 AM k-meleon.exe 1356 RegQueryValue HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1708537768-436374069-839522115-1004\ProfileImagePath BUFFER OVERFLOW Length: 130

Issues:
(1) Buffer Overflow?
(2) Sandbox location C:\SANDBOX\...
Why is k-meleon.exe searching for this?
My sandboxie.ini file (first 5 lines):

[GlobalSettings]

ConfigLevel=99
BoxRootFolder=%AppData%

My container file is set to %AppData%\Sandbox
View user's profileSend private message
soccerfan


Joined: 25 Sep 2007
Posts: 421
Reply with quote
Over in the kmeleon forum (http://kmeleon.sourceforge.net/forum/read.php?3,84752,84824#msg-84824),
Dorian (one of the lead developers of kmeleon) had this to say:
Quote:
kmeleon 1.5.1 try to run itself with lower privilege by default, and probably conflicting with sandboxie. But I didn't add an option for that. Maybe in the next version.

I'm not sure how to interpret the first sentence.
Does it imply that if sandboxie were run with a lower privilege, then a sandboxed km1.5.1 would run ok?
Maybe others (including tzuk) can chime in.
View user's profileSend private message
SnDPhoenix


Joined: 26 Dec 2006
Posts: 2694
Location: West Florida
Reply with quote
Idk, it sounds silly to me, why is a simple browser dependent upon permissions?
So if someone wants to use the new KM, one must modify all their permissions throughout the whole OS, just to run that browser? Confused

Anyways, either way, Sandboxie can be run with admin privs and also (starting with one of the betas), according to the release notes, doesn't require admin privs to run anymore, so it should be possible to run it with lower privs/on a limited user account.

Maybe someone here can test this out?
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
I haven't commented here yet but that doesn't mean I haven't seen the problem report, just been too busy with other problems. I'll try to look into this one soon.

_________________
tzuk
View user's profileSend private message
Guest


Reply with quote
I couldn't get K-Meleon V1.5.1 to work either with Sandboxie. But it's not a Sandboxie problem.
It's a bug in the new V1.5.1 of K-Meleon. I ininstalled KM v1.5.1 and installed KM v1.5.0
and it works fine with Sandboxie. Had some difficulties with the bookmarks but nothing
is ever easy.
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
K-Meleon 1.5.1 should work fine in the sandbox.
Just to be clear, it certainly was a problem in Sandboxie.
View user's profileSend private message
Guest1
Guest

Reply with quote
tzuk wrote:
K-Meleon 1.5.1 should work fine in the sandbox.
Just to be clear, it certainly was a problem in Sandboxie.


i used my HIPS to run k-m in sandboxie, i first removed any km rule in the hips, than start km sandboxed, now the hips asked: alow k-meleon excute k-meleon.exe? i denied it, and than other questions allow, after that, km started smoothly in a sandbox.
Can't run K-Meleon 1.5.1 sandboxed :(
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 2  

Use the RSS feed to watch this topic for replies
  
  
 This topic is locked: you cannot edit posts or make replies.  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 207,976,472 times since June 2004