Trust No Program
Reply to topic
Better logout protection
Guest


Reply with quote
I was playing with the matousec leaktests for firewalls and found sss.exe able to logout from sandbox. Please check:

http://www.matousec.com/downloads/ssts.zip - bin\level 4\sss.exe
tzuk


Joined: 22 Jun 2004
Posts: 15008
Reply with quote
I checked. The logoff is permitted because unlike poweroff/shutdown/reboot requests, Windows does not consider logoff a privileged (or administrative) operation. That's very reasonable -- you would not expect to have to be administrator just to logoff your session.

I could possibly add more system hooks to prevent this, but that would be new code in Sandboxie, because the poweroff/shutdown/reboot protection at this time is done by simply discarding the needed privilege, not by hooking anything.

_________________
tzuk
View user's profileSend private message
Guest


Reply with quote
Thanks for answer. I though the log out protection is already implemented just not perfect,
because when i ran shutdown -l or logoff from sandboxed cmd i got "denied attempt" message from Sandboxie.
Better logout protection
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

Use the RSS feed to watch this topic for replies
  
  
 Reply to topic  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 208,666,685 times since June 2004