Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: jack_90125 on May 10, 2011, 08:39:55 PM

Title: avast ais v6.1125 sandbox
Post by: jack_90125 on May 10, 2011, 08:39:55 PM
ok updated and for smirks and giggles I had a old program I wanted to install so I right click and select run in sandbox. meanwhile defense+ plus comes up and says xxx wants to run and I say ok and select install mode for d+.
check to see if avast does indeed have it running in the sandbox and it does.
so program installs and actually installs!
why? thought the purpose of the sandbox was to not effect the system in anyway? so how can this be?
Title: Re: avast ais v6.1125 sandbox
Post by: Vlk on May 10, 2011, 08:54:47 PM
Are you saying that you run an app inside the sandbox, and it was able to make modifications to the system? Which app are you talking about? And is it the manual sandbox, or the AutoSandbox? (also, how did you check if it's really running sandboxed? [as you said]).

Thanks
Vlk
Title: Re: avast ais v6.1125 sandbox
Post by: gentle4ug on May 10, 2011, 08:55:37 PM
Since you installed the program in the sandbox.  No permentant changes were made to to your computer's sensitive areas (registry, drivers, etc...) and the program does not have access to your system or personal files.

If you empty the sandbox (don't delete it), the program should just disappear, leaving behind no trace it was ever there.  Think how handy that will be when you get hit with a fake av, or other driveby nasty.  Pretty slick huh.
Title: Re: avast ais v6.1125 sandbox
Post by: jack_90125 on May 10, 2011, 09:11:22 PM
well I right clicked on the setup.exe and selected run in sandox (avast). went thru the install and it actually installed. the program was adobe photo album 2 from years ago. it also installed adobe reader 6.0. and they actually installed to system and made registry entries etc. as well as in the program features it listed both in the add/remove programs. and I uninstalled adobe reader 6 from there.
I knew they were not malicious but was just shocked that they were actually installed.
I had the avast ui open and it said it was running in the sandbox or was sandboxed.
and I assumed that since it was sandboxed any child processes would also be sandboxed. guess it is true what they say about assuming.
win 7 ultimate x 64 os


Are you saying that you run an app inside the sandbox, and it was able to make modifications to the system? Which app are you talking about? And is it the manual sandbox, or the AutoSandbox? (also, how did you check if it's really running sandboxed? [as you said]).

Thanks
Vlk
Title: Re: avast ais v6.1125 sandbox
Post by: gentle4ug on May 10, 2011, 09:21:26 PM
Hummm...... That makes me nervous too.  That kind of behavior is not what I expect from a sandbox.  I don't really care if its safe, signed or whatever.  If I run the installer it in the sandbox (not autosandbox), I expect the program to be installed in the sandbox and stay there and go away when I empty the sandbox.  Anything less makes me question what protection is actually being provided.
Title: Re: avast ais v6.1125 sandbox
Post by: claudiuc on May 10, 2011, 11:13:44 PM
Can you repeat the test? I just installed a program in sandbox and cannot find it anyware :)
Title: Re: avast ais v6.1125 sandbox
Post by: jack_90125 on May 10, 2011, 11:20:19 PM
Can you repeat the test? I just installed a program in sandbox and cannot find it anyware :)

yp just got done reinstalling after an uninstall. same results. with reboots and reg clean between all.
I checked to make a log file but cannot find where avast stores the logs.
but something is off to say the least.
Title: Re: avast ais v6.1125 sandbox
Post by: Dch48 on May 10, 2011, 11:28:25 PM
Maybe selecting it to run as an installer in D+ overrode the sandboxing protections?
Title: Re: avast ais v6.1125 sandbox
Post by: DJBone on May 10, 2011, 11:39:20 PM
Maybe selecting it to run as an installer in D+ overrode the sandboxing protections?

I agree with this opinion.

DJBone
Title: Re: avast ais v6.1125 sandbox
Post by: jack_90125 on May 10, 2011, 11:44:15 PM
I disabled d+ second time and rebooted. same results.
and yes comodo sandbox is disabled too and always is. do not trust it.
not a newbie at this.
Title: Re: avast ais v6.1125 sandbox
Post by: gentle4ug on May 11, 2011, 03:27:05 AM
I've tried to install multiple programs running installers in the sandbox, including Adobe reader.  Nothing penetrated the sandbox.  I couldn't find an installation that would complete.  I'm a happy bunnie.  I'm wondering if something is going on with the "dragon" (commodo).  I haven't let that stuff near my computers since the firewall flamed an installation about a year ago.
Title: Re: avast ais v6.1125 sandbox
Post by: jack_90125 on May 15, 2011, 06:04:09 PM
hey vlk any clues as to why this was not sandboxed?