3 ms·
How does ActiveX sandboxing work? As far as I know, it mainly relies on signatures. What happens when you trust a control that has a bug which overwrites your
by stuntmouse 16y ago
How does ActiveX sandboxing work?
As far as I know, it mainly relies on signatures. What happens when you trust a control that has a bug which overwrites your hard disk? And that's leaving out malicious code...
- briansmith 16y agoAFAIK, there is no "ActiveX sandboxing" per se. It is the same as the sandboxing techniques that are available to all Windows executables. But, also Internet Explorer runs in "Protected Mode" by default, so many of these sandboxing techniques get applied--by default--to plugins. See http://msdn.microsoft.com/en-us/library/bb250462(VS.85).aspx http://msdn.microsoft.com/en-us/library/bb250462(VS.85).aspx.
- stuntmouse 16y agoVery informative link. Thank you.
- stuntmouse 16y agoThis looks impressive for systems that are supported (Vista and up). I'm not entirely convinced that all attack vectors have been considered though. They appear to have considered the obvious things: write and execute access to files and other resources from restricted processes, preventing harmful windows message behavior. But would a process with low integrity have read access to every other resource with low integrity? Or is that further constrained by some other access control mechanism? Also, I don't think it's a feature for an unprivileged process to have registry access, though I understand there may be reasons for it. It could also be argued that there is a larger attack surface for protected mode processes, because they can call any OS function, but are just denied when they don't have the access level to commit the action. I must admit I am behind the times with regards to Windows system programming.
- briansmith 16y agoYes, one advantage of Chrome's system is that it can be more restrictive than the operating system. And, the pre-scanning is an extra line of defense. I won't attempt to explain the integrity system in Windows because I am not that familiar with it. But, Wikipedia says that read access can be blocked based on integrity level too. See http://en.wikipedia.org/wiki/Mandatory_Integrity_Control http://en.wikipedia.org/wiki/Mandatory_Integrity_Control
- stuntmouse 16y agoAs a final note, there's no reason why the two couldn't be used in tandem. In fact, they should be.
- briansmith 16y agoI think that Chrome and IE differ in how they split functionality between processes (and thus integrity levels), but both Chrome and IE make extensive use of the various sandboxing tools that Windows offers.