Release v0.9.3 / 5.51.3 #1085
Replies: 3 comments 3 replies
-
Besides not running as Administrator on Windows 8.1 (I don't have another account), how do I get rid of the "Administrator Mode Detected" dialog box that pops up every time Edge is run starting with v0.9.3 / 5.51.3? Checking "Don't show me this message again" doesn't help -- it still comes up every time Edge is started. This does not occur with Sandboxie-Classic-x64-v5.50.9.exe and prior versions. Thanks! |
Beta Was this translation helpful? Give feedback.
-
The only thing I did was run Sandboxie-Classic-x64-v5.51.3.exe to upgrade from Sandboxie-Classic-x64-v5.50.9.exe. I've been a Sandboxie user for many many years, but I don't set up additional sandboxes or use special settings. It's a very simple installation. I've gone back to v5.50.9 and the problem goes away. |
Beta Was this translation helpful? Give feedback.
-
Does simply translating Is there a warning or error if
|
Beta Was this translation helpful? Give feedback.
-
This build adds a new functionality to use Windows Filtering Platform (WFP) to implement a per sandbox firewall.
This functionality needs to be enabled in the global Sandboxie settings, and the driver needs to be reloaded (or the PC rebooted) for the feature to be activated. Once this is done the firewall rules which can be configured in the network options of each sandbox, will be enforced by the driver.
If the WFP support is not enabled the same rules still can be set and are used, but will be applied only by a set of user mode hooks, unlike the WFP implementation they will apply only to outgoing connections and there are no enforcement guarantees as user mode hooks can be bypassed or disabled by a malicious application.
The rational behind implementing this functionality in user and kernel mode (driver) instead of driver only is twofold for once it allows for debugging of the rule processing code as booth modes use the same code to make decisions based on the preset rules. Second the WFP callouts are global i.e. they are triggered for any process on the system whether its sandboxed or not, in the lather case they don't do anything and the use of a hash map to identify sandboxed programs that require action should provide optimal performance. That said users who run a 3rd party firewall which they may prefer may not want to many firewalls being active at once, while still wanting to use some per sandbox network rules for compatibility and not security reasons.
Also please note that with this build the old "BlockPort=..." functionality is completely dropped, the default port block rules are now implemented by the new user mode firewall component, if you have custom BlockPort entries in your sandboxie ini they will need to be updated by hand to the new format, for example "BlockPort=137,138,139,445" -> "NetworkAccess=*,Block;Port=137,138,139,445"
The rules are applied based on a specific decision priority:
2a. A rule with ip and port trums a rule with ip or port only
2b. A rule with one ip trumps a rule with an ip range that is besides that on the same level
The rule editing UI allows for testing rules, in the row below the rule list one can enter program name, port, ip and protocol to see which rules are in play and which rule will be applied in the end.
When configuring per process network access restrictions and WFP is enabled it is possible to choose between a WFP based approach and the old sandboxie way of blocking the network device end points. The later approach is more absolute, but is know for causing some application to crash.
If you have issues with an update installation, just uninstall the previous version keeping the sandboxie.ini and reinstall the new build.
You can support the project through donations, any help will be greatly appreciated.
Changelog
[0.9.3 / 5.51.3] - 2021-08-08
added
Fixed
[0.9.2 / 5.51.2] - 2021-08-07
Added
Changed
Fixed
removed
[0.9.1 / 5.51.1] - 2021-07-31
Added
Changed
Fixed
[0.9.0 / 5.51.0] - 2021-07-29
Added
-- to enable this support, add 'NetworkEnableWFP=y' to the global section and reboot or reload the driver
-- to use WFP for a specific sandbox, add 'AllowNetworkAccess=n'
-- you can allow certain processes by using 'AllowNetworkAccess=program.exe,y'
-- you can also enable this policy globally by adding 'AllowNetworkAccess=n' to the global section
-- in this case you can exempt entire sandboxes by adding 'AllowNetworkAccess=y' to specific boxes
-- you can block certain processes by using 'AllowNetworkAccess=program.exe,n'
-- Note: WFP is less absolute than the old approach, using WFP will filter only TCP/UDP communication
-- restricted boxed processes will still be able to resolve domain names using the system service
-- however, they will not be able to send or receive data packets directly
-- the advantages of WFP is that filter rules can be implemented by restricting communication only to specified addresses or selected ports using "NetworkAccess=..."
-- the mechanism replaces the old "BlockPort=..." functionality
-- Note: this filter applies only to outgoing connections/traffic, for incoming traffic either the WFP mode or a third-party firewall is needed
-- like the old user mode based mechanism, malicious applications can bypass it by unhooking certain functions
-- hence it's recommended to use the kernel mode WFP-based mechanism when reliable isolation is required
-- please note that the driver only trace logs the kernel debug output, use DbgView.exe to log
-- Note: this capability is used by TaskExplorer to allow inspecting sandbox-internal tokens
-- Note: a process must have administrative privileges to be able to use this API
-- just in case a future Windows build breaks something in the systemless mode
-- Note: these options are for testing only and disable core parts of the sandbox isolation
Changed
Fixed
This discussion was created from the release Release v0.9.3 / 5.51.3.
Beta Was this translation helpful? Give feedback.
All reactions