Trust No Program
Reply to topic
Soupnutzy


Joined: 18 Sep 2010
Posts: 17
Reply with quote
Buster wrote:
The way to compare API log to other users logs of same .exe or whatever is sharing the logs.

What might be an efficient medium for this to occur? email, forum, Database server website similar to VT?

Another issue popped up. The first time it occurred I failed to recognize it.

After using BSA the browser now gives a 302 redirect from search engines on Firefox and Opera.
Previous to using BSA, starting the browsers in Sandboxie produced no 302 redirect.

What could be causing this?

_________________
And the PC User said, The Cracker beguiled me, and I did execute.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Soupnutzy wrote:
What might be an efficient medium for this to occur? email, forum, Database server website similar to VT?


I guess the most efficient would be a database server website

Soupnutzy wrote:
Another issue popped up. The first time it occurred I failed to recognize it.

After using BSA the browser now gives a 302 redirect from search engines on Firefox and Opera.
Previous to using BSA, starting the browsers in Sandboxie produced no 302 redirect.

What could be causing this?


Browser running sandboxed or unsandboxed?
View user's profileSend private message
Soupnutzy


Joined: 18 Sep 2010
Posts: 17
Reply with quote
Buster wrote:
Browser running sandboxed or unsandboxed?


The browser is running sandboxed.

In my Google quest I found some discussion on 302 redirects involving javascript, ajax and JSON.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Soupnutzy wrote:
Buster wrote:
Browser running sandboxed or unsandboxed?


The browser is running sandboxed.

In my Google quest I found some discussion on 302 redirects involving javascript, ajax and JSON.


Does happen the same when you sandbox FireFox but donīt run BSA?
View user's profileSend private message
Soupnutzy


Joined: 18 Sep 2010
Posts: 17
Reply with quote
Buster wrote:
Does happen the same when you sandbox FireFox but donīt run BSA?


If I had never run BSA and sandbox Firefox or Opera I would never see 302 redirect.
They only occurred after the use of BSA with Sandboxie.

First time I used BSA I got the multiprocess firefox issue and the 302 redirect issue in Opera.

I didn't bring it to your attention because I didn't know it was related to BSA.
After updating Firefox to 3.6.10 the multiprocess issue disappeared but I can't say it was a result of the upgrade because I hadn't given it a run just before the upgrade either, many days apart.

302 redirects have stopped on their own with out my intervention. I don't know how they began nor how it solved itself. I have updated absolutely nothing since FF upgrade.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Soupnutzy wrote:
302 redirects have stopped on their own with out my intervention. I don't know how they began nor how it solved itself. I have updated absolutely nothing since FF upgrade.


302 redirections were not related to BSA because it doesnīt change any registry value or anything that may cause such effect.

Maybe you got some malware inside the sandbox folder and it was gone when you deleted sandbox folder contents.
View user's profileSend private message
Sandboxie not found! by BSA 1.23
Alan Baxter


Joined: 11 Apr 2009
Posts: 23
Location: Colorado, USA
Reply with quote
Whenever I click the Start Analysis button, "Sandboxie not found!" is displayed in the BSA status bar. The Start Analysis button stays highlighted. I'm expecting the highlight to change to the Stop Analysis button, but that doesn't happen . I'm unable to use this new version of BSA. Sandboxie is currently running. BSA 1.13 still works.

BSA 1.23
Sandboxie 3.46 and 3.48 (registered)
WinPcap 4.1.2
Windows XP SP3
SbieCtrl.exe and SbieSvc.exe both appear in Task Manager > Processes

Edit: Didn't realize there was a Sandboxie update. Problem persists with version 3.48
View user's profileSend private message
Re: Sandboxie not found! by BSA 1.23
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Alan Baxter wrote:
Whenever I click the Start Analysis button, "Sandboxie not found!" is displayed in the BSA status bar.


Tell me the value of the next registry key:

HKEY_CLASSES_ROOT\*\shell\sandbox\command
View user's profileSend private message
Re: Sandboxie not found! by BSA 1.23
Alan Baxter


Joined: 11 Apr 2009
Posts: 23
Location: Colorado, USA
Reply with quote
Buster wrote:
Alan Baxter wrote:
Whenever I click the Start Analysis button, "Sandboxie not found!" is displayed in the BSA status bar.


Tell me the value of the next registry key:

HKEY_CLASSES_ROOT\*\shell\sandbox\command

The key "HKEY_CLASSES_ROOT\*\shell\sandbox\command" is present, but has no name/value pairs in it.
View user's profileSend private message
Re: Sandboxie not found! by BSA 1.23
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Alan Baxter wrote:
The key "HKEY_CLASSES_ROOT\*\shell\sandbox\command" is present, but has no name/value pairs in it.


Thatīs the problem. That key should contain a value.

I suggest you reinstall Sandboxie to fix the problem.
View user's profileSend private message
Re: Sandboxie not found! by BSA 1.23
Alan Baxter


Joined: 11 Apr 2009
Posts: 23
Location: Colorado, USA
Reply with quote
Buster wrote:
Alan Baxter wrote:
The key "HKEY_CLASSES_ROOT\*\shell\sandbox\command" is present, but has no name/value pairs in it.

Thatīs the problem. That key should contain a value.

I suggest you reinstall Sandboxie to fix the problem.

Thanks. It turns out a reinstall wasn't necessary. All I had to do was check Add right-click action "Run Sandboxed" to files and folders to get Sandboxie to add that key. I had unchecked that a long time ago to reduce context menu clutter and didn't realize that recent versions of BSA now require it to be checked.
View user's profileSend private message
Re: Sandboxie not found! by BSA 1.23
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Alan Baxter wrote:
Thanks. It turns out a reinstall wasn't necessary. All I had to do was check Add right-click action "Run Sandboxed" to files and folders to get Sandboxie to add that key. I had unchecked that a long time ago to reduce context menu clutter and didn't realize that recent versions of BSA now require it to be checked.


Thanks for the information!

I thought that key was always present when Sandboxie is installed.

Next time other user reports the same problem I know the solution. Wink
View user's profileSend private message
Re: Sandboxie not found! by BSA 1.23
Alan Baxter


Joined: 11 Apr 2009
Posts: 23
Location: Colorado, USA
Reply with quote
Buster wrote:
Thanks for the information!

I thought that key was always present when Sandboxie is installed.

Next time other user reports the same problem I know the solution. Wink

I figured it was something like that. I'm glad to help out. It's the least I can do to show my appreciation for BSA.
View user's profileSend private message
Re: Sandboxie not found! by BSA 1.23
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Alan Baxter wrote:
I figured it was something like that. I'm glad to help out. It's the least I can do to show my appreciation for BSA.


Put your review here after you test it. Wink
View user's profileSend private message
Soupnutzy


Joined: 18 Sep 2010
Posts: 17
Reply with quote
Buster wrote:
302 redirections were not related to BSA because it doesnīt change any registry value or anything that may cause such effect.

I figured as much.

Buster wrote:
Maybe you got some malware inside the sandbox folder and it was gone when you deleted sandbox folder contents.

It didn't disappear across sandbox deletions previously.

When I use Virus Total, it goes outside the sandbox to get files for upload, like the sandbox isn't there.

When I run BSA to analyze FF, just start then stop, I have keylogger and backdoor detections in the analysis.
I will have to try with a connection and without a connection to see if there is a difference.
View user's profileSend private message
Buster Sandbox Analyzer
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 18 of 60  

Use the RSS feed to watch this topic for replies
  
  
 Reply to topic  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 208,564,526 times since June 2004