| Author |
Message |
| Buster |
|
 |
| Gantron |
Posted: Tue Aug 03, 2010 3:36 am Post subject: Download link doesn't work |
|
| The download link doesn't work. |
|
 |
| Buster |
|
 |
| Buster |
Posted: Fri Oct 30, 2009 9:29 am Post subject: |
|
| Ruhe wrote: |
| Buster wrote: |
| Also I plan renaming the tool so people donīt confuse SandDiff with SandboxDiff. |
Send me a PM if I have to change the subdomain accordingly. |
I will do, thanks! |
|
 |
| Ruhe |
Posted: Fri Oct 30, 2009 9:03 am Post subject: |
|
| Buster wrote: |
| Also I plan renaming the tool so people donīt confuse SandDiff with SandboxDiff. |
Send me a PM if I have to change the subdomain accordingly. |
|
 |
| Buster |
Posted: Fri Oct 30, 2009 8:41 am Post subject: |
|
| wraithdu wrote: |
| I see. So it will function basically the same, we just have to start with an empty sandbox instead of a box that already has something in it. That's cool, that's primarily how I would use it anyway. |
Yes, itīs like you say: it will function basically the same and you will start with an empty sandbox instead of a box that already has something in it.
I decided this change because like you, I think most people will use it that way anyway.
With this change comparisions will be more accurate so I will be able to accomplish the final goal of the tool much better. The final goal is converting SandDiff in a sandbox analyzer.
Also I plan renaming the tool so people donīt confuse SandDiff with SandboxDiff. |
|
 |
| wraithdu |
Posted: Fri Oct 30, 2009 4:07 am Post subject: |
|
| I see. So it will function basically the same, we just have to start with an empty sandbox instead of a box that already has something in it. That's cool, that's primarily how I would use it anyway. |
|
 |
| Buster |
Posted: Thu Oct 29, 2009 8:33 pm Post subject: |
|
I plan removing the "before" button and keep only the "empty".
The rest will be the same, just more accurate.
Keep a copy of actual version for if you need to compare two sandboxes states. |
|
 |
| wraithdu |
Posted: Thu Oct 29, 2009 8:10 pm Post subject: |
|
So something more along the lines of RegShot or InCtrl5 then?
Sad to hear. I liked the direction this was going. It was very easy to use and fast. So now when you say 'modifications made to system', what do you mean exactly? It won't work at all with Sandboxie now, or it's just testing for leaks to the real system? |
|
 |
| Buster |
Posted: Thu Oct 29, 2009 7:22 pm Post subject: |
|
I have decided that SandDiff will not be used to compare two sandbox states. I have decided this because I can not garantee accurate results comparing two sandboxes and because the goal of SandDiff will be to act like a malware analyzer.
So next version of SandDiff will show only the modifications (file, registry and port) made to system. I think I can garantee accurate results doing that. |
|
 |
| Buster |
Posted: Thu Oct 29, 2009 11:33 am Post subject: Re: Feature Request: Save Differences in Reg Format |
|
| brahman wrote: |
thanks for this great app.
It would be very nice if it could save registry differences automatically in Windows Registry Editor Version 5 format. |
Glad you like it!
tzuk has been helping me with the registry comparision part. He told me how to correctly find when a registry or value key has been deleted.
I add your suggestion to the feature request list. If itīs possible to me I will add it. |
|
 |
| brahman |
Posted: Thu Oct 29, 2009 11:14 am Post subject: Feature Request: Save Differences in Reg Format |
|
Hi,
thanks for this great app.
It would be very nice if it could save registry differences automatically in Windows Registry Editor Version 5 format.
Thanks.
B. |
|
 |
| wraithdu |
Posted: Wed Oct 28, 2009 2:27 am Post subject: |
|
| The hardlink is only in Win7. Maybe Vista, but I don't have it to test anymore. And the hardlink will seem exactly the same as the real file - properties, size, appearance, etc. - except the Compatibility settings will be greyed out. |
|
 |
| Buster |
Posted: Tue Oct 27, 2009 8:09 pm Post subject: |
|
| wraithdu wrote: |
| I took a look through Everything's forums and found the reason NETSTAT.EXE is not found in system32. It is because netstat (and many other system32 files) are actually hardlinks. You can google the term. I don't know how this affects opening or running an app via ShellExecute(). |
I have a computer with Windows XP and Windows 7 installed and when Iīm running Windows XP I can see NETSTAT.EXE in \Windows\System32 and does not look like a hard link. The file is 32kb long.  |
|
 |
| Buster |
Posted: Tue Oct 27, 2009 9:02 am Post subject: |
|
I have fixed the problem with deleted keys/values.
As soon as tzuk adds the feature I requested I will release a new version. |
|
 |