Trust No Program
This topic is locked: you cannot edit posts or make replies.
Log messages to disk
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Hi.

tzuk: You probably readed the post where I comment Iīm coding a tool to check for differences between two sandboxes.

At the beginning I only had on mind to do a similar tool to the one majoMo did but after working a while on it I considered it would be more interesting and useful going one step further: analyze changes and evaluate if the sandboxed program(s) performed actions that could be considered as malicious.

Some people may use the tool just to see modifications and other people to get a report with the evaluation of performed actions. So itīs not just a malware behaviour analyzer.

File modifications can be checked directly comparing the files that were on disk before and after the comparision. Something similar happens with registry changes.

I would like to include other checkings: if sandboxed application installed a service or tried to connect to internet or tried to hook keyboard.

I could get such information from the messages presented by Sandboxie when such actions are performed. I talk about the messages telling that X application tried to do this or that and the user must choose if hide of close the message.

My feature request is: I would like to have the option to log to disk Sandboxieīs messages.

Is it possible?
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
Yes, that happens to be a feature that I want to add to Sandboxie some time soon.

But I was thinking about logging everything to c:\Windows\Sandboxie.log, rather than inside the folder of a particular sandbox, so I'm not sure how appropriate it would be for you utility.

_________________
tzuk
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
tzuk wrote:
Yes, that happens to be a feature that I want to add to Sandboxie some time soon.


Nice to hear!

As itīs a simple feature that will not cause compatibility problems, do you think it could be included in the next official release?


tzuk wrote:
But I was thinking about logging everything to c:\Windows\Sandboxie.log, rather than inside the folder of a particular sandbox, so I'm not sure how appropriate it would be for you utility.


I would delete the log before doing the comparision so all the messages would be refered to the sandbox process that SandDiff pretends to analyze.

Therefore logging everything to the same log is fine for me.
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
Buster wrote:
As itīs a simple feature that will not cause compatibility problems, do you think it could be included in the next official release?


You mean in version 3.40 ? No, I'm afraid not. It's not so simple, and not so small. It will have to wait.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
tzuk wrote:
Buster wrote:
As itīs a simple feature that will not cause compatibility problems, do you think it could be included in the next official release?


You mean in version 3.40 ? No, I'm afraid not. It's not so simple, and not so small. It will have to wait.


Yeah, I meant 3.40.

Ok, let me know when you have included the feature to test it.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
tzuk wrote:
But I was thinking about logging everything to c:\Windows\Sandboxie.log


With "everything", do you mean something more than just the messages that the user must hide or close?

If the reply is affirmative, what other things would you be logging?
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
I mean all SBIExxxx messages that pop up.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
tzuk wrote:
I mean all SBIExxxx messages that pop up.


Thatīs exactly what I need.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
tzuk: This feature will be included in Sandboxie 3.41.01?
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
Not in 3.41.01. There are some more pressing issues. But it is on my plans for version 3.42. You're going to have to be patient, Buster.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
tzuk wrote:
Not in 3.41.01. There are some more pressing issues. But it is on my plans for version 3.42. You're going to have to be patient, Buster.


Do you know when patience will have a discount at Bits du Jour? I must buy some of it. Razz
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
Smile
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
Added in version 3.41.10.

To enable, simply create a REG_SZ-type registry value LogFile in the key
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SbieSvc

The contents of this value should be something like this,
1;C:\SbieLog.txt

The prefix 1; is required and indicates the format of the output log file. At this time there is only format level 1.

Then you just specify the file location.

To disable the logging, simply delete this registry value. There is no need to restart the service or take any other action other than creation of the value (to enable) or deletion of the value (to disable).

The log file is a UNICODE text file.
View user's profileSend private message
Log messages to disk
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

Use the RSS feed to watch this topic for replies
  
  
 This topic is locked: you cannot edit posts or make replies.  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 208,388,635 times since June 2004