| Author |
Message |
| Ruhe |
Posted: Sun Jul 18, 2010 8:59 am Post subject: |
|
| Due to design problems this project is stopped for an indefinite time. |
|
 |
| Guest10 |
Posted: Fri Jul 09, 2010 10:45 pm Post subject: |
|
I'm sure that I don't use all of the program's capabilities (too little time to spend on it), but I had occasion today to use it to log sandboxed processes as they start.
The Firefox extension called Flashgot is used as a go-between for Firefox and numerous download managers.
The flashgot.exe program runs when Firefox starts and writes a test file to the temporary directory. Then it ends.
About half of the time the flashgot.exe program isn't logged by SBObserver (1.17), on my computer.
I think I've seen the same thing happen with the java program jqsnotify.exe.
Do you think that the 'scan interval' of 3 seconds is the reason for missing a process that starts and ends pretty quickly? |
|
 |
| Ruhe |
Posted: Fri Jul 02, 2010 4:48 pm Post subject: |
|
v1.18
- Scan sandboxed files with Emsisoft Commandline Scanner 5.0, www.emsisoft.com/en/software/cmd/
- Removed different settings and features |
|
 |
| Ruhe |
Posted: Fri Jul 02, 2010 9:01 am Post subject: |
|
The board member wolfmann published an article Programs analysis tools — Sandboxie “add-ons” on his security site.
Beside talking about SandboxDiff, Buster Sandbox Analyzer he also mentioned my Sandbox Observer.
Thanks! |
|
 |
| Ruhe |
Posted: Sun Jun 27, 2010 9:51 am Post subject: |
|
| Just uploaded a new beta build but also decided to remove different settings and features (see SBObserver.ini.default). |
|
 |
| Ruhe |
Posted: Sat Jun 26, 2010 2:43 pm Post subject: |
|
v1.18 - BETA
- Scan sandboxed files with Emsisoft Commandline Scanner 5.0
See %APPDATA%\SBObserver\SBObserver.ini.default for details and needed settings:
[A2Cmd]
;--- Scan sandboxed files with Emsisoft Commandline Scanner 5.0
;--- www.emsisoft.com/en/software/cmd/
;--- Example
;--- A2CmdFolder=c:\Portable\a2cmd
;--- A2CmdParams=/service
;--- Empty 'A2CmdParams' uses default scanner settings. Define exclusions
;--- in section [Exclusions] -> key 'A2Cmd'. It is highly recommended to
;--- install a2cmd with /service once.
A2CmdEnabled=n
A2CmdFolder=
A2CmdParams=/service |
|
|
 |
| Ruhe |
Posted: Sat Jun 26, 2010 11:50 am Post subject: |
|
v1.17
- Fixed an issue after system startup if StartWithWindows=y |
|
 |
| Ruhe |
Posted: Sat Jun 26, 2010 8:59 am Post subject: |
|
v1.16
- Updated sigcheck.exe to v1.70
- Removed options to check system settings (UAC, DEP, AppLocker)
- Changed distribution format from stand-alone executable to ZIP |
|
 |
| Ruhe |
Posted: Wed Jun 23, 2010 7:15 am Post subject: |
|
Users that run SBO via the task scheduler (see CheckDEP.pdf) should change the existing task scheduler job:
3rd screenshot, "Edit Action" -> Enter the path to SBObserver.exe into the field "Start in", C:\Apps in my example. |
|
 |
| Ruhe |
Posted: Sat Jun 19, 2010 3:00 pm Post subject: |
|
v1.15
- Added option and exclusions to check sandboxes for missing 'DropAdminRights' setting
- Logging enabled by default |
|
 |
| Ruhe |
Posted: Sat Jun 19, 2010 11:11 am Post subject: |
|
v1.14
- Re-enabled DEP checking. Follow the steps in the installed CheckDEP.pdf |
|
 |
| Ruhe |
Posted: Sat Jun 19, 2010 8:26 am Post subject: |
|
v1.13
- DEP checking introduced in v1.12 (temporary) removed |
|
 |
| Ruhe |
Posted: Fri Jun 18, 2010 7:47 pm Post subject: |
|
v1.11
- Added option to show additional splash text
v1.12
- Install %APPDATA%\SBObserver\SBObserver.ini.default as template with all default settings
- Added options to check system settings (UAC, DEP, AppLocker) during application start |
|
 |
| Ruhe |
Posted: Fri Jun 11, 2010 8:20 pm Post subject: |
|
v1.10
- Auto-shutdown if Sandboxie setup found
- More logging output |
|
 |
| Me |
Posted: Sun May 30, 2010 10:01 am Post subject: |
|
v1.9
- Changed default and minimal value for "ScanInterval" to "3"
- Enabling/Disabling "Show log" in tray menu dependent on "Logging" setting
- History.txt distributed with main application
- Warning if hash database has been deleted by an external application or action
- Warning if hash database has been modified by an external application or action |
|
 |