Trust No Program
This topic is locked: you cannot edit posts or make replies.
HMA! Pro VPN bypass
Ruhe


Joined: 03 Jul 2008
Posts: 803
Location: Germany
Reply with quote
By using HMA! Pro VPN with enabled Secure IP bind for Firefox, websites are accessable with a sandboxed Firefox Shocked
By running Firefox unsandboxed, websites aren't accessible, as expected.

The same with Internet Explorer.

So, what to do to forbid internet access for a sandboxed browser while using HMA! Pro VPN with Secure IP bind?

Info about Secure IP bind on this site and in more detail here (it isn't beta anymore).

Sandboxie 3.56 + 3.57.05, 64bit
HMA 2.6.9


Resource Access Monitor log for a sandboxed Firefox while using HMA! Pro VPN with Secure IP bind

snipped. --tzuk
View user's profileSend private message
Ruhe


Joined: 03 Jul 2008
Posts: 803
Location: Germany
Reply with quote
After setting this in the Firefox sandbox the browser can't access the internet anymore.

Code:
ClosedFilePath=*\forceinterfacelsp.dll

But that's not the solution, because with this setting it can't connect even if HMA is running.

forceinterfacelsp.dll

Ronen, you can test it even without a Pro account, you don't have to connect to the VPN.
I'll send you the client by PM.
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15150
Reply with quote
The resource log doesn't show that any resources need attention so I'm not sure what the solution to the problem will end up being. I am focusing on usability issues at the moment, so I have a backlog of technical problems to look into, but I will try to look into this soon.

_________________
tzuk
View user's profileSend private message
Ruhe


Joined: 03 Jul 2008
Posts: 803
Location: Germany
Reply with quote
I've also informed the developers of HMA about this issue.

Info from the HMA forum:
Code:
The Secure IP Binding feature works through code injection, which is probably disabled by Sandboxie.
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15150
Reply with quote
When I added the setting

OpenIpcPath=*\BaseNamedObjects*\{73B2E84B-B7D9-464d-8376-68D43DE31E1D}

It made the browser in the sandbox not able to connect, similar to the browser outside the sandbox. I'm not sure if this covers everything because I didn't actually have a VPN connection so I could check if connectivity does work at some point. Also, I only tested with Internet Explorer.

I'd like to know how this setting works for you.
View user's profileSend private message
Ruhe


Joined: 03 Jul 2008
Posts: 803
Location: Germany
Reply with quote
The Process Explorer by Microsoft says

Ipc \Sessions\1\BaseNamedObjects\{3A4BE5AC-E783-4939-A746-05920ACDE790}
Ipc \Sessions\1\BaseNamedObjects\{73B2E84B-B7D9-464d-8376-68D43DE31E1D}

belong to "HMA! Pro VPN.exe"

After adding

OpenIpcPath=*\BaseNamedObjects*\{3A4BE5AC-E783-4939-A746-05920ACDE790}
OpenIpcPath=*\BaseNamedObjects*\{73B2E84B-B7D9-464d-8376-68D43DE31E1D}

to my Firefox sandbox all seems to work as it should with the "HMA! Pro VPN 2.6.9" client.

Would be nice to see a template for this.
View user's profileSend private message
Ruhe


Joined: 03 Jul 2008
Posts: 803
Location: Germany
Reply with quote
The Templates.ini of version 3.58 contains the above settings.
View user's profileSend private message
HMA! Pro VPN bypass
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

Use the RSS feed to watch this topic for replies
  
  
 This topic is locked: you cannot edit posts or make replies.  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 212,819,222 times since June 2004