Sandboxie Plus (open source fork of Sandboxie)
#16
Information 
Quote:Urgent security fixes (thanks @diversenok)

Build 5.46.0 resolves many box isolation issues some of them critical that could allow rogue applications to escape the sandbox. It is highly advised to upgrade quickly to the new builds. For further details please review the change log below.

If you have issues with an update installation, just uninstall the previous version keeping the sandboxie.ini and reinstall the new build.

Hotfix Changelog

Added
  • added "RunServiceAsSystem=..." allows specific named services to be ran as system
Changed
  • refactored some code around SCM access
Fixed
  • fixed a crash issue in SbieSvc.exe introduced with the last build
  • fixed issue with sandman ui update check
Removed
  • removed "ProtectRpcSs=y" due to incompatybility with new isolation defaults
Release Changelog

Added
  • Sandboxie now strips particularly problematic privileges from sandboxed system tokens
    -- with those a process could atempt to bypass the sandbox isolation (thanks Diversenok)
    -- old legacy behavior can be enabled with "StripSystemPrivileges=n" (absolutely NOT Recommended)
  • added new isolation options "ClosePrintSpooler=y" and "OpenSmartCard=n"
    -- those resources are open by default but for a hardened box its desired to close them
  • added print spooler filter to prevent printers from being set up outside the sandbox
    -- the filter can be disabled with "OpenPrintSpooler=y"
  • added overwrite prompt when recovering an already existing file
  • added "StartProgram=", "StartService=" and "AutoExec=" options to the SandMan UI
  • added more compatybility templates (thanks isaak654)
Changed
  • Changed Emulated SCM behavior, boxed services are no longer by default started as boxed system
    -- use "RunServicesAsSystem=y" to enable the old legacy behavior
    -- Note: sandboxed services with a system token are still sandboxed and restricted
    -- However not granting them a system token in the first place removes possible exploit vectors
    -- Note: this option is not compatible with "ProtectRpcSs=y" and takes precedence!
  • Reworked dynamic IPC port handling
  • Improved Resource Monitor status strings
Fixed
  • fixed a critical issue that allowed to create processes outside the sandbox (thanks Diversenok)
  • fixed issues with dynamic IPC port handling that allowed to bypass IPC isolation
  • fixed issue with ipc tracing
  • fixed CVE-2019-13502 "\RPC Control\LSARPC_ENDPOINT" is now filtered by the driver (thanks Diversenok)
    -- this allowed some system options to be changed, to disable filtering use "OpenLsaEndpoint=y"
  • fixed hooking issues SBIE2303 with chrome, edge and possibly others
  • fixed failed check for running processes when performing snapshot operations
  • fixed some box option checkboxes were not properly initialized
  • fixed unavailable options are not properly disabled when sandman is not connected to the driver
  • fixed MSI instalelr issue, not being able to create "C:\Config.Msi" folder on windows 20H2
  • added missing localization to generic list commands
  • fixed issue with "iconcache_*" when runngin sandboxed explorer
  • fixed more issues with groups
Download
[-] The following 2 users say Thank You to harlan4096 for this post:
  • Decimuss, silversurfer
Reply


Messages In This Thread
Sandboxie 5.41.0 - by harlan4096 - 10 June 20, 08:01
Sandboxie Plus 5.41.2 - by harlan4096 - 21 June 20, 06:23
Sandboxie Plus 5.42 - by harlan4096 - 05 July 20, 06:10
Sandboxie Plus 5.42.1 - by harlan4096 - 20 July 20, 16:43
Sandboxie Plus 5.43 - by harlan4096 - 06 September 20, 08:03
Sandboxie Plus 5.43.5 - by harlan4096 - 15 September 20, 07:10
Sandboxie Plus 5.43.6 - by harlan4096 - 11 October 20, 06:33
Sandboxie Plus 5.43.7 - by harlan4096 - 04 November 20, 06:51
Sandboxie Plus 5.44.1 - by harlan4096 - 17 November 20, 07:55
Sandboxie Plus 5.45.0 - by harlan4096 - 08 December 20, 10:27
Sandboxie Plus 5.45.1 - by harlan4096 - 24 December 20, 18:29
Sandboxie Plus 5.45.2 - by harlan4096 - 30 December 20, 07:25
Sandboxie Plus v0.5.3 / 5.45.3 - by harlan4096 - 03 January 21, 14:03
Sandboxie Release v0.5.4 / 5.46.1 - Hotfix - by harlan4096 - 09 January 21, 08:28
Sandboxie v0.5.5 / 5.46.4 - by harlan4096 - 20 January 21, 06:58
Sandboxie v0.6.0 / 5.46.5 - by harlan4096 - 27 January 21, 06:52
Sandboxie v0.7.0 / 5.48.0 - by harlan4096 - 16 February 21, 06:46
Sandboxie v0.7.3 / 5.49.5 - by harlan4096 - 31 March 21, 07:23
Sandboxie+ v0.9.0a / 5.51.0 - by harlan4096 - 30 July 21, 06:52
Sandboxie+ v0.9.1 / 5.51.1 - by harlan4096 - 02 August 21, 06:56
Sandboxie+ v0.9.2 / 5.51.2 - by harlan4096 - 07 August 21, 10:28
Sandboxie+ v0.9.4 / 5.51.4 - by harlan4096 - 23 August 21, 07:22
Sandboxie+ v0.9.5 / 5.51.5 - by harlan4096 - 31 August 21, 07:03
Sandboxie+ Release v1.3.3 / 5.58.3 - by harlan4096 - 13 September 22, 10:32
Sandboxie+ Release v1.3.4 / 5.58.4 - by harlan4096 - 20 September 22, 06:08
Sandboxie+ Release v1.3.5 / 5.58.5 - by harlan4096 - 27 September 22, 06:28
Sandboxie+ Release v1.5.3 / 5.60.3 - by harlan4096 - 08 November 22, 08:25
Sandboxie Plus 1.6.3 / 5.61.3 - by harlan4096 - 23 December 22, 05:45
Sandboxie Plus v1.6.4 / 5.61.4 - by harlan4096 - 01 January 23, 08:27
Sandboxie Plus v1.6.5 / 5.61.5 - by harlan4096 - 11 January 23, 06:05
Sandboxie Plus 1.6.6 / 5.61.6 - by harlan4096 - 17 January 23, 07:20
Sandboxie Plus v1.6.7 / 5.61.7 - by harlan4096 - 25 January 23, 07:20
Sandboxie Plus v1.7.2 / 5.62.2 - by harlan4096 - 06 February 23, 09:27
Sandboxie v1.8.0 / 5.63.0 - by harlan4096 - 28 February 23, 09:26
Sandboxie 1.8.2 / 5.63.2 - by harlan4096 - 03 April 23, 10:13
Sandboxie-Plus v1.9.0 - by harlan4096 - 17 April 23, 08:35
Sandboxie Plus 1.9.1 / 5.64.1 - by harlan4096 - 24 April 23, 08:19
Sandboxie Plus 1.9.7 / 5.64.7 - by harlan4096 - 09 June 23, 08:47
Sandboxie Plus 1.9.8 / 5.64.8 - by harlan4096 - 22 June 23, 08:57
Sandboxie 1.11.2 / 5.66.2 - by harlan4096 - 10 September 23, 07:49
Sandboxie 1.11.3 / 5.66.3 - by harlan4096 - 28 September 23, 07:42
Sandboxie 1.11.4 / 5.66.4 - by harlan4096 - 07 October 23, 06:23
Sandboxie Plus 1.12.8 / 5.67.8 - by harlan4096 - 01 February 24, 10:18
Sandboxie-Plus 1.13.3 - by harlan4096 - 16 March 24, 07:56
Sandboxie-Plus 1.14.3 - by harlan4096 - 02 July 24, 08:38
Sandboxie-Plus 1.14.7 - by harlan4096 - 06 September 24, 06:41
Sandboxie-Plus 1.14.7, 1.14.8 - by harlan4096 - 09 September 24, 06:38
Sandboxie-Plus 1.14.9 - by harlan4096 - 19 September 24, 07:55
Sandboxie Plus 5.41.1 - by harlan4096 - 19 June 20, 06:38

Forum Jump:


Users browsing this thread: 26 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
UltraSearch 4.6.0.1091
UltraSearch 4.6.0....harlan4096 — 10:38
Brave 1.73.91
Release Channel 1....harlan4096 — 10:11
AdGuard Browser Extension 5.0.169 (MV3)
AdGuard Browser Ex...harlan4096 — 10:10
uBOLite_2024.11.20.858
uBOLite_2024.11.20...harlan4096 — 10:09
CrystalDiskInfo 9.5.0 [2024/11/20]
9.5.0 ​ Added D...harlan4096 — 10:08

[-]
Birthdays
Today's Birthdays
avatar (56)Stefanos
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>