Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Access Restrictions Whitelist ignored in Firefox 106.0.1 #2391

Closed
rugabunda opened this issue Oct 25, 2022 · 11 comments
Closed

Access Restrictions Whitelist ignored in Firefox 106.0.1 #2391

rugabunda opened this issue Oct 25, 2022 · 11 comments
Labels
Firefox-related Issues with Firefox-based browsers fixed in next build Fixed in the next Sandboxie version Issue reproduced Issue reproduced without uncertainties

Comments

@rugabunda
Copy link

rugabunda commented Oct 25, 2022

Describe what you noticed and did

  1. run firefox
  2. install videodownloadhelper addon, and companion co-app
  3. whitelist net.downloadhelper.coapp-win-64.exe in start restrictions (C:\Program Files\net.downloadhelper.coapp\bin\net.downloadhelper.coapp-win-64.exe)

image

  1. load firefox
  2. note:

image

How often did you encounter it so far?

After Firefox 106.0

Affected program

videodownloadhelper co-app

Download link

Addon: https://addons.mozilla.org/en-CA/firefox/addon/video-downloadhelper/
Co-app: https://www.downloadhelper.net/install-coapp

Where is the program located?

The program is installed both inside and outside the sandbox.

Expected behavior

Whitelist should not be bypassed

What is your Windows edition and version?

Win 11 21H2

In which Windows account you have this problem?

I use the built-in Administrator with Admin Approval Mode turned on.

Please mention any installed security software

ESET

What version of Sandboxie are you running?

1.5.0 / 1.5.1 #2391 (comment)

Is it a new installation of Sandboxie?

I just updated Sandboxie from a previous version (to be specified).

Is it a regression?

No response

In which sandbox type you have this problem?

In a standard isolation sandbox (yellow sandbox icon).

Can you reproduce this problem on an empty sandbox?

I can confirm it also on an empty sandbox.

Did you previously enable some security policy settings outside Sandboxie?

No response

Crash dump

No response

Trace log

No response

Sandboxie.ini configuration

No response

@rugabunda rugabunda added the Confirmation pending Further confirmation is requested label Oct 25, 2022
@rugabunda
Copy link
Author

Problem appeared to begin after updating to firefox 1.0.6.0; I believe this was before the sbie release fixing video problems in firefox.

@bastik-1001
Copy link
Contributor

I see this as well, with Sandboxie 1.5.0 and 1.5.1.

@isaak654 isaak654 added Issue reproduced Issue reproduced without uncertainties and removed Confirmation pending Further confirmation is requested labels Oct 26, 2022
@isaak654 isaak654 changed the title Access Restrictions Whitelist ignored in Firefox 1.0.6.1 Access Restrictions Whitelist ignored in Firefox 106.0.1 Oct 28, 2022
@isaak654
Copy link
Collaborator

Isn't it the same of #724 (comment) ?

@rugabunda
Copy link
Author

rugabunda commented Oct 30, 2022

Isn't it the same of #724 (comment) ?

Perhaps, but it just started for me in recent releases, never had a problem until the last week or so

@bastik-1001
Copy link
Contributor

Sandboxie creates a copy of "C:\Program Files\net.downloadhelper.coapp\bin\net.downloadhelper.coapp-win-64.exe", which it seemingly didn't do before. That assumption is based on the fact that the message came up with Sandboxie 1.5.0.

Adding DontCopy=C:\Program Files\net.downloadhelper.coapp\bin\net.downloadhelper.coapp-win-64.exe to the .ini section for the box with the start restriction, where this process is whitelisted, does indeed not copy the file and therefore does not show the error. Thank you isaak for pointing to the other issue, which made me check if the reason was that the application was being copied.

@rugabunda
Copy link
Author

rugabunda commented Nov 5, 2022

Thank you @bastik-1001 , problem solved. How would this be dealt with in the official version? A dedicated compatibility template? Is the copying a bug?

@DavidXanatos
Copy link
Member

I have investigated this issue and firefox's xul.dll is requesting GENERIC_WRITE on net.downloadhelper.coapp-win-64.exe and sandboxie as it should then migrates the file into the sandbox, so apparently this issue must be caused by a recent change in forefox and not in sandboxie.

the DontCopy approach is the right fix for this problem, it should be put into a compatibility template.

@isaak654 isaak654 added the template request Possibly linked to template requests label Nov 7, 2022
@isaak654
Copy link
Collaborator

isaak654 commented Nov 7, 2022

Well, there is already a template which seems fit for purpose:

[Template_FileCopy]
Tmpl.Title=#4295
Tmpl.Class=Misc
DontCopy=*.url
CopyEmpty=*\microsoft\windows\explorer\thumbcache_*
CopyEmpty=*\microsoft\windows\explorer\iconcache_*
# firefox
CopyAlways=*\places.sqlite
CopyAlways=*\xul.mfl

@DavidXanatos
Copy link
Member

This seam to be a generic firefox issue, it tryes to open any plugin for writing looks like a ff bug to me, same issue with roboform.
So I'm looking towards a generic fix for booth as well as other unknown plugins...

@DavidXanatos DavidXanatos added the fixed in next build Fixed in the next Sandboxie version label Nov 7, 2022
@isaak654 isaak654 added Firefox-related Issues with Firefox-based browsers and removed template request Possibly linked to template requests labels Nov 7, 2022
@rugabunda
Copy link
Author

This seam to be a generic firefox issue, it tryes to open any plugin for writing looks like a ff bug to me, same issue with roboform. So I'm looking towards a generic fix for booth as well as other unknown plugins...

Thank you David

@bastik-1001
Copy link
Contributor

Can anyone see a reason why Firefox changed its behavior? Thank you for working around that issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Firefox-related Issues with Firefox-based browsers fixed in next build Fixed in the next Sandboxie version Issue reproduced Issue reproduced without uncertainties
Projects
None yet
Development

No branches or pull requests

4 participants