Trust No Program
Reply to topic
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
GetModuleFileName. Pass NULL in the first parameter.

http://msdn.microsoft.com/en-us/library/ms683197(VS.85).aspx

_________________
tzuk
View user's profileSend private message
raid


Joined: 23 Aug 2008
Posts: 58
Location: TN, USA
Reply with quote
tzuk wrote:
I don't see Sandboxie as a malware research tool, so I'm not going to add features that are dedicated to malware research. Buster, I've already mentioned the InjectDll setting which would let you inject DLLs into sandboxed programs. All you need is to write a small DLL that hooks DeleteFile and prevent the deletion. Maybe you and guys can team up and figure out how to do that.


Perfectly understandable Tzuk. Although, Sandboxie does a fine job of assisting in malware research. You've really got one fantastic little program.

I will be purchasing a license for it very soon. Your a professional author and have gone out of your way as far as I'm concerned to answer my question.

Thanks again!

_________________
Everything is so different, yet I am the same...
View user's profileSend private message
dynarx


Joined: 03 Apr 2007
Posts: 174
Location: New South Wales, Australia
Reply with quote
raid wrote:
You've really got one fantastic little program.


Little it may be, but as we say round here, it's not the amount of code in the fight that counts, but the amount of fight in the code! Wink

Just passing, don't mind me Very Happy

Cheers, all.
Dynarx
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Would be anyone able to code the same stuff tzuk did but in Delphi?
View user's profileSend private message
Ruhe


Joined: 03 Jul 2008
Posts: 803
Location: Germany
Reply with quote
I'm a home and hobby Delphi coder but always have problems to read this C/C++ stuff.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Ruhe wrote:
I'm a home and hobby Delphi coder but always have problems to read this C/C++ stuff.


I´m in the same situation. Wink
View user's profileSend private message
Ruhe


Joined: 03 Jul 2008
Posts: 803
Location: Germany
Reply with quote
After some tries, I'm not able to convert this code to Delphi.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
http://www.megaupload.com/?d=EDI97UO3

There you can get a working DLL to avoid file deletion with source code included in Delphi.

I was unable to convert tzuk´s code so I used a hooking unit from other person.

tzuk: a question...

I tried to hook NtSetInformationFile from ntdll.dll but Sandboxie rejects to inject the DLL and aborts opening a sandbox.

Why does it happen?
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
up!
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
I don't know why it happens.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Fixed, thanks!

What about NtSetInformationFile from ntdll.dll? Do you know why it happens?
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
I don't know why it happens.
View user's profileSend private message
Buster


Joined: 06 Aug 2007
Posts: 2185
Reply with quote
Sorry, I thought you were meaning other thing.

If I send you the DLL could you check what´s going wrong?
View user's profileSend private message
tzuk


Joined: 22 Jun 2004
Posts: 15003
Reply with quote
No, Buster, I am sorry but I don't think that's a good idea for me to debug your DLL.
View user's profileSend private message
Question regarding Sandboxed programs that attempt to delete
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 2 of 2  

Use the RSS feed to watch this topic for replies
  
  
 Reply to topic  

Sandboxie is Copyright © 2004-2012 by Sandboxie Holdings LLC.  All rights reserved.
Sandboxie.com | Contact Author
This site has been viewed 208,450,133 times since June 2004