sandboxie-plus / Sandboxie

Sandboxie Plus & Classic
https://Sandboxie-Plus.com
GNU General Public License v3.0
13.53k stars 1.51k forks source link

In win11 pro, sandboxie cann't open explorer.exe with StartAllBack #2040

Open kdxiaoyi opened 2 years ago

kdxiaoyi commented 2 years ago

Describe what you noticed and did

i use StartAllBack. It will replace the explorer GUI with the look of win10 but it work half ? in EL sandbox ↓ EIb in default sandbox ↓ ds

a similar issue #1127

How often did you encounter it so far?

when i open explorer.exe with StartAllBack

Affected program

explorer.exe (win11 pro)

Download link

not

Where is the program located?

The program is installed only inside a sandbox (NOT in the real system anyway).

Expected behavior

let startallback work truly

What is your Windows edition and version?

win 11 pro 21H2 22000.318

In which Windows account you have this problem?

A local or Microsoft account without special changes.

Please mention any installed security software

Huorong (completely closed when i test)

What version of Sandboxie are you running?

sandboxie plus v1.1.3 x64

Is it a new installation of Sandboxie?

I recently upgraded it from an older version than v1.0.22 / 5.55.22.

Is it a regression?

No response

In which sandbox type you have this problem?

All sandbox types (I tried them all).

Can you reproduce this problem on an empty sandbox?

I can confirm it also on an empty sandbox.

Did you previously enable some security policy settings outside Sandboxie?

i don't know but i believe no

Crash dump

No response

Trace log

No response

Sandboxie.ini configuration

No response

DavidXanatos commented 2 years ago

Perhaps when i was trying StartAllBack before settling on EP i noticed this as well, the fix is simple: just block the SAB dll's with ClosedFilePath

DavidXanatos commented 2 years ago

I cant reproduce the issue what do you mean with EL sandbox?

kdxiaoyi commented 2 years ago

i am so sorry that i see it now EL is Enhanced Isolation A Sanbox in EL mode

DavidXanatos commented 2 years ago

can you post your sandboxie ini i cant reproduce the issue even with a hardened box

kdxiaoyi commented 2 years ago

remember this problem happens with StartAllBack

#
# Sandboxie-Plus configuration file
#

[GlobalSettings]
FileRootPath=\??\%SystemDrive%\Sandbox\%USER%\%SANDBOX%
SeparateUserFolders=y
KeyRootPath=\REGISTRY\USER\Sandbox_%USER%_%SANDBOX%
IpcRootPath=\Sandbox\%USER%\%SANDBOX%\Session_%SESSION%
NetworkEnableWFP=n
EnableObjectFiltering=y
EnableWin32kHooks=y
EditAdminOnly=n
ForceDisableAdminOnly=n
ForgetPassword=n
Template=Edge_Win11Fix
Template=WindowsRasMan
Template=nVidia_Stereoscopic3D
Template=WindowsLive
Template=OfficeLicensing
Template=OfficeClickToRun
Template=7zipShellEx

[UserSettings_1E4A0363]
SbieCtrl_AutoStartAgent=SandMan.exe
SbieCtrl_EnableAutoStart=y
BoxDisplayOrder=DefaultBox,For_Test
SbieCtrl_UserName=kdxiaoyi
SbieCtrl_NextUpdateCheck=1658844242
SbieCtrl_ExplorerNotify=n
SbieCtrl_WindowCoords=200,150,1237,632
SbieCtrl_ActiveView=40021
SbieCtrl_ProcessViewColumnWidths=250,70,300

[For_Test]
Enabled=y
AutoRecover=y
BlockNetworkFiles=y
RecoverFolder=%Desktop%
RecoverFolder=%Personal%
RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}%
BorderColor=#00ffff,ttl,6
Template=AutoRecoverIgnore
Template=LingerPrograms
Template=BlockPorts
Template=qWave
Template=FileCopy
Template=SkipHook
Template=OpenBluetooth
ConfigLevel=9
BoxNameTitle=y
CopyLimitKb=81920
DropAdminRights=y
FakeAdminRights=y

[DefaultBox]
Enabled=y
AutoRecover=y
BlockNetworkFiles=y
RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}%
RecoverFolder=%Personal%
RecoverFolder=%Desktop%
BorderColor=#00FFFF,ttl
Template=OpenBluetooth
Template=SkipHook
Template=FileCopy
Template=qWave
Template=BlockPorts
Template=LingerPrograms
Template=AutoRecoverIgnore
ConfigLevel=9