Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Accessing Windows Network Share directory, mapped to H: worked 4 days ago... #3858

Closed
jedimasterspaz opened this issue Apr 28, 2024 · 4 comments
Labels
Support request Support request issues

Comments

@jedimasterspaz
Copy link

Describe what you noticed and did

2 computers are on Windows 10. The computer I'm on has Sandboxie Classic.
When I log in to webmail and try to attach a file, I click on the H: and get [#] Network Error [#] Windows cannot access \Ouellette7\Accept
I upgraded to the latest Sandboxie, but it's still a problem.
It works outside of Sandboxie.
It fails in Chrome and Firefox.
I completely uninstalled and reinstalled Sandboxie, including a fresh sandboxie.ini file.

How often did you encounter it so far?

Just started, but is consistant.

Expected behavior

When I click on the H: it shows the Accept directory in the attach window.

Affected program

Firefox 125.0.2 and Chrome 124.0.6367.91

Download link

Not available

Where is the program located?

The program is installed both inside and outside the sandbox.

Did the program or any related process close unexpectedly?

No, not at all.

Crash dump

No response

What version of Sandboxie are you running now?

Sandboxie Classic 5.68.3

Is it a new installation of Sandboxie?

I just updated Sandboxie from a previous version (I don't remember which one).

Is it a regression from previous versions?

No response

In which sandbox type you have this problem?

In a standard isolation sandbox (yellow sandbox icon).

Can you reproduce this problem on a new empty sandbox?

I can confirm it also on a new empty sandbox.

What is your Windows edition and version?

Windows 10 Pro 22H2 OS Build 19045.4291

In which Windows account you have this problem?

A local account (Administrator).

Please mention any installed security software

Microsoft Windows Defender

Did you previously enable some security policy settings outside Sandboxie?

Nothing added.

Trace log

No response

Sandboxie.ini configuration

#
# Sandboxie configuration file
#

[GlobalSettings]
Template=NOD32
Template=WindowsRasMan
Template=WindowsLive
Template=Edge_Fix
Template=OfficeLicensing
Template=OfficeClickToRun
ForceDisableSeconds=300

[DefaultBox]
ConfigLevel=10
AutoRecover=y
BlockNetworkFiles=y
Template=OpenProtectedStorage
Template=AdobeDistiller
Template=AdobeAcrobatReader
Template=AdobeAcrobat
Template=Chrome_KB5027231_fix
Template=Chrome_Profile_DirectAccess
Template=Chrome_Phishing_DirectAccess
Template=Chrome_Sync_DirectAccess
Template=Chrome_Preferences_DirectAccess
Template=Chrome_Passwords_DirectAccess
Template=Chrome_Cookies_DirectAccess
Template=Chrome_History_DirectAccess
Template=Chrome_Bookmarks_DirectAccess
Template=Chrome_Force
Template=Firefox_Profile_DirectAccess
Template=Firefox_Phishing_DirectAccess
Template=Firefox_Session_DirectAccess
Template=Firefox_Passwords_DirectAccess
Template=Firefox_Cookies_DirectAccess
Template=Firefox_Bookmarks_DirectAccess
Template=Firefox_Force
Template=Edge_Profile_DirectAccess
Template=Edge_Phishing_DirectAccess
Template=Edge_Sync_DirectAccess
Template=Edge_Preferences_DirectAccess
Template=Edge_Passwords_DirectAccess
Template=Edge_Cookies_DirectAccess
Template=Edge_History_DirectAccess
Template=Edge_Bookmarks_DirectAccess
Template=Edge_Force
Template=IExplore_ProtectedStorage
Template=IExplore_Feeds_DirectAccess
Template=IExplore_Cookies_DirectAccess
Template=IExplore_History_DirectAccess
Template=IExplore_Favorites_RecoverFolder
Template=IExplore_Favorites_DirectAccess
Template=IExplore_Force
Template=OpenSmartCard
Template=OpenBluetooth
Template=SkipHook
Template=FileCopy
Template=qWave
Template=BlockPorts
Template=LingerPrograms
Template=AutoRecoverIgnore
RecoverFolder=%{374DE290-123F-4565-9164-39C4925E467B}%
RecoverFolder=%Personal%
RecoverFolder=%Desktop%
BorderColor=#00FFFF,ttl,6
Enabled=y
AutoDelete=y
NeverDelete=n

[UserSettings_37DA0474]
SbieCtrl_UserName=ouellettei7
SbieCtrl_BoxExpandedView=DefaultBox
SbieCtrl_NextUpdateCheck=1714877655
SbieCtrl_AutoRunSoftCompat=n
SbieCtrl_AutoApplySettings=n
SbieCtrl_SettingChangeNotify=n
SbieCtrl_ReloadConfNotify=n
SbieCtrl_EditConfNotify=n
SbieCtrl_HideWindowNotify=n
SbieCtrl_WindowCoords=200,150,1237,632
SbieCtrl_ActiveView=40021
@jedimasterspaz jedimasterspaz added the Confirmation pending Further confirmation is requested label Apr 28, 2024
@jedimasterspaz
Copy link
Author

Here's the Resource Access Monitor:
Clsid -------------------------------
Clsid {228826AF-02E1-4226-A9E0-99A855E455A6} ImmersiveShellBroker; PID: 8048
File -------------------------------
File \Device\HarddiskVolume4\Users*\AppData\Local\Mozilla\Firefox\Profiles\gfx6l1ic.default\cache2\entries\A30A539686D8414382299E4C32635883FF0C3F53; PID: 8048
File O \Device\HarddiskVolume4\Users*
\AppData\Roaming\Mozilla\Firefox\Profiles\gfx6l1ic.default\cert9.db-journal; PID: 8048
File O \Device\HarddiskVolume4\Users*\AppData\Roaming\Mozilla\Firefox\Profiles\gfx6l1ic.default\cert9.db-wal; PID: 8048
File O \Device\HarddiskVolume4\Users*
\AppData\Roaming\Mozilla\Firefox\Profiles\gfx6l1ic.default\datareporting\glean\db; PID: 8048
File O \Device\HarddiskVolume4\Users***********\AppData\Roaming\Mozilla\Firefox\Profiles\gfx6l1ic.default\datareporting\glean\db\data.safe.tmp; PID: 8048
Image -------------------------------
Ipc -------------------------------
Ipc \BaseNamedObjects\F932B6C7-3A20-46A0-B8A0-8894AA421973; PID: 8048
Ipc \Device; PID: 8048
Ipc \Device\Afd; PID: 8048
Ipc \Device\Afd\Endpoint; PID: 8048
Ipc \Sessions\1\BaseNamedObjects\Local\SM0:1572:304:WilStaging_02; PID: 1572
Ipc \Sessions\1\BaseNamedObjects\Local\SM0:8048:304:WilStaging_02; PID: 8048
Ipc \Sessions\1\BaseNamedObjects\SM0:8048:304:WilStaging_02; PID: 8048
Ipc \Sessions\1\BaseNamedObjects\SM0:8048:304:WilStaging_02_p0; PID: 8048
Ipc \Sessions\1\BaseNamedObjects\SM0:8048:304:WilStaging_02_p0h; PID: 8048
Key -------------------------------
Key \Registry\Machine\Software\Classes\CLSID{228826AF-02E1-4226-A9E0-99A855E455A6}; PID: 8048
Key \REGISTRY\MACHINE\SOFTWARE\Classes\CLSID{228826af-02e1-4226-a9e0-99a855e455a6}; PID: 8048
Key \Registry\Machine\Software\Classes\CLSID{228826AF-02E1-4226-A9E0-99A855E455A6}; PID: 8048
Key \REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\SbieSvc; PID: 8048
Key \REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Services\SbieSvc; PID: 8048
Key \REGISTRY\USER\S-1-5-21-1685408505-1697397885-1423355688-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings; PID: 8048
Key \registry\user\S-1-5-21-1685408505-1697397885-1423355688-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings; PID: 8048
Key \registry\user\S-1-5-21-1685408505-1697397885-1423355688-1001_classes\CLSID{228826AF-02E1-4226-A9E0-99A855E455A6}; PID: 8048
Pipe -------------------------------
Pipe O \Device\Afd; PID: 8048
WinCls -------------------------------

@xsmolasses
Copy link

Well, you've got BlockNetworkFiles=y in the [DefaultBox] of your Sandboxie.ini
Change to =n and Template=BlockPorts interferes as well, so delete latter line.

Also, EnableLinkedConnections registry entry can't hurt, apply it then restart.

@jedimasterspaz
Copy link
Author

Thank you very much.

@xsmolasses
Copy link

# You can reinstate Template=BlockPorts and see no loss of function;
# as network shares (à la SAMBA) are marshalled by Windows services.
# Said template can block webpages from directly trying those ports.

# Irrespective of BlockNetworkFiles, also effective are these lines:

# applies to any IP addressed by string and any \*\ share name
OpenPipePath=|\\?*.?*.?*.?*\*\*

# self-explanatory
OpenPipePath=|\\your_dhcp_assigned_host_name\share_name\*

# replace with ReadFilePath for enforced read-only shares.
# replace with NormalFilePath for default isolated writes behaviour,
# e.g., DefaultBox\share\192.168.123.123\share_name\foobar.txt

@isaak654 isaak654 added Support request Support request issues and removed Confirmation pending Further confirmation is requested labels May 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Support request Support request issues
Projects
None yet
Development

No branches or pull requests

3 participants