Recommended Posts

Internet Explorer's sandbox is robust. It's more likely that your father's problem comes from add-ons like Flash etc.

Yes. There is a market for VMware vulnerabilities.

So if you get a virus in VM ware there is a chance for it to "come out of the box" and go after you're normal OS?

Im tempted to load the site on my Macbook pro. but I dont want it connected to anything of mine if its still there.

What can I use to check out the site? I've gone to websites that scan other websites, however they all say the site is clean, i just dont want to risk it.

How do I turn on the IE Sandbox on IE 8?

I might go download the Trial of KAV internet Security. and goto the site then. and hope it doesnt mess with anything

So if you get a virus in VM ware there is a chance for it to "come out of the box" and go after you're normal OS?

Im tempted to load the site on my Macbook pro. but I dont want it connected to anything of mine if its still there.

If you have a mapped drive in the VM to a drive on your actual windows machine, then the malware could spread over the network.

If you have a mapped drive in the VM to a drive on your actual windows machine, then the malware could spread over the network.

Damn. How do I go about changing that?

Also just to be clear, if I use Sandboxie, ANY virus/spyware cannot touch my actual windows install correct?

Chrome and IE8 are already sandboxed on Vista and Windows 7. I've never needed more than that, despite generous amounts of surfing shady sites with each browser I've never caught a single piece of malware on Vista or 7. But sandboxes are not magic bullets, for instance an infected browser, even in a sandbox or VM, can still steal any information you input into that browser, such as credit card numbers or bank login credentials. I made a site that may help, it's at http://bulletproof-windows.blogspot.com so check it out, it has lots of tips for securing Vista/7 and browsers on those OSes. I describe (well, link to a site that describes) how to sandbox FF on Vista/7, together with noscript that may be a good solution. Unless you are running .exe's off the internet, you should be pretty safe with whichever browser you choose on Vista/7 (can't say the same for XP) because of all the exploit-prevention stuff that was added to Windows after XP.

Chrome and IE8 are already sandboxed on Vista and Windows 7. I've never needed more than that, despite generous amounts of surfing shady sites with each browser I've never caught a single piece of malware on Vista or 7. But sandboxes are not magic bullets, for instance an infected browser, even in a sandbox or VM, can still steal any information you input into that browser, such as credit card numbers or bank login credentials. I made a site that may help, it's at http://bulletproof-windows.blogspot.com so check it out, it has lots of tips for securing Vista/7 and browsers on those OSes. I describe (well, link to a site that describes) how to sandbox FF on Vista/7, together with noscript that may be a good solution. Unless you are running .exe's off the internet, you should be pretty safe with whichever browser you choose on Vista/7 (can't say the same for XP) because of all the exploit-prevention stuff that was added to Windows after XP.

Thanks!

Damn. How do I go about changing that?

Also just to be clear, if I use Sandboxie, ANY virus/spyware cannot touch my actual windows install correct?

Only the 32bit version of Sandboxie can guarantee that no virus/spyware cannot touch your actual windows install. The 32bit version (only compatible with 32bit windows, not 64bit) goes down to the kernel to sandbox the malware. In 64bit versions of windows Microsoft created patch guard to keep people out of the kernel. In turn Microsoft created some Kernel Level API's basically saying "This is all we will allow you to do". While the access MS gives the deveopers is good, it's not great. So the developer of sandboxie does not guarantee his product in a 64bit environment.

Only the 32bit version of Sandboxie can guarantee that no virus/spyware cannot touch your actual windows install. The 32bit version (only compatible with 32bit windows, not 64bit) goes down to the kernel to sandbox the malware. In 64bit versions of windows Microsoft created patch guard to keep people out of the kernel. In turn Microsoft created some Kernel Level API's basically saying "This is all we will allow you to do". While the access MS gives the deveopers is good, it's not great. So the developer of sandboxie does not guarantee his product in a 64bit environment.

Awe. Well I used sandboxie, i am on windows 7 64BIT. I uninstalled MSE, and installed KAV Internet security and turned everything to high. Used the sandboxie to goto the site. NOTHING popped up saying it was malware or virus. So I assume its good. I did a full scan and nothing.

Scanning with malwarebytes too.

It clearly points to that the issue shouldn't occur if you're running a non-IE browser unless you've enabled the said feature of auto-open.

Exactly my issue. You appear to be making a sweeping judgement that 1). IE is always susceptible to such issues. 2). all other browsers aren't, unless you've enabled said feature.

For the record: a few months ago I was running an up-to-date Firefox. I do not have that option set. I managed to get malware due to a *slightly* out of date Java install. (Ever since then I've kept enabled plugins at a bare minimum.)

J_R_G: could you create a site for XP users if possible?

I did not make the site for Vista/7 out of some short-sightedness or something like that, XP lacks ASLR (and some other things) that make it pretty much easy to infect once you have a 0-day vulnerability, which are easy enough to find in any complex code-base. Not really MS' fault though, when XP was made, there were no x86 CPUs with DEP, and without DEP, ASLR is useless. MS added DEP to XP, but without DEP *and* ASLR the system is pretty easy to infect, even if you run sandbox applications like sandboxie or run as a standard user it's very easy for malware to infect the browser process and steal all your stuff like bank/paypal credentials, credit card #s and so on that you input into the browser. Whatever the reason (too much testing and development to add ASLR to XP, or what have you) XP is really never going to be a 'secure' OS by modern standards, so I don't see the point of really trying to act like it is, it's much better to concentrate on securing an OS that already has a fundamentally secure foundation, like Vista or Win 7 (or modern apple/oss equiv.)

BUT - you can still just use common sense and apply some things from my security blog to XP, like run as standard user (hard to do without UAC, folder virtualization, and so on though that are only in Vista+), use sandboxie, enable DEP for all processes, run MSE and secunia vulnerability scanner, keep OS + apps updated, etc.

But my main advice would be, that if you really care about security, just upgrade to Win 7 (preferably x64.)

Exactly my issue. You appear to be making a sweeping judgement that 1). IE is always susceptible to such issues. 2). all other browsers aren't, unless you've enabled said feature.

For the record: a few months ago I was running an up-to-date Firefox. I do not have that option set. I managed to get malware due to a *slightly* out of date Java install. (Ever since then I've kept enabled plugins at a bare minimum.)

Again, read what I post; the post was done on the basis of the original poster running firefox from the get-go therefore I question how he got infected with it. Either read the post or shut up.

Firefox is secure by itself. Just avoid going to malicious sites to start with.

A) Not true

B) Useless advice without add-ons to tell you what not to go to

1) Install NoScript, this makes FF secure by default

2) Install Web of Trust, this tells you which sites are unreliable

3) If WoT doesn't give a rating, don't turn any scripts on, and you're good

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • This is about the EU given consumers options, Apple is all about not giving options and locking you into its own services, this hurts Apple far more than it hurts the EU market because it makes Apple products look less appealing by Apple refusing to offer its own service because they have to give options to rivals, the end results are consumers might look at alternatives like Android. It's a game Apple can't really win when there are alternatives and Apple will in time change course on this, until then, let Apple hurt themselves in the EU market.
    • Microsoft unveils new Surface Laptop with improved trackpad, Snapdragon X2, and more by Taras Buria Microsoft's new Surface Laptop Ultra generated a lot of buzz earlier this month, but in addition to its most powerful laptop with an NVIDIA chip, Microsoft also has a more affordable laptop lineup, which has been waiting for an update for quite a while. Today, Microsoft announced the eighth-generation Surface Laptop. The new Surface Laptop is powered by the Snapdragon X2 Plus and X2 Elite processors. These chips offer faster CPU performance, up to 58% faster graphics, and 80 TOPS Neural Processing Units (NPUs) for on-device AI processing. Like the previous models, these chips retain their great energy efficiency, and Microsoft says that buyers can expect up to 20 hours of work on a single charge. The laptop is available in two sizes: 13.8-inch and 15-inch. You will have a hard time finding visual differences between the new and previous models, as Microsoft is not taking any major design leaps, except for the new Jade color, which may look familiar to Surface Laptop 5 owners. Other colors include Platinum, Black, and Dune. The 15-inch variant got a higher-resolution display. It is a 3,270 x 2,180 resolution screen with a pixel density of 262 ppi (the 13-inch model has a 201 ppi density) and a maximum brightness of 600 nits SDR and HDR. Unlike the Surface Pro 12th-gen, which is available with optional OLED displays, the Surface Laptop sticks with IPS, a 1,300:1 contrast ratio, a 120Hz refresh rate, and a 3:2 aspect ratio. Another notable change in the Surface Laptop 8 is its trackpad. It now provides haptic feedback when you perform various actions in apps and the operating system. It is a relatively new feature that Microsoft brought to Windows 11 in recent updates, and it is only available on certain devices, such as the Logitech MX Master 4, Surface Slim Pen 2, the upcoming Surface Laptop Ultra, and now the Surface Laptop 8. The new Surface Laptop with the new Surface Pro Like its tablet-shaped sibling, the new Surface Laptop is notably more expensive. It starts at a $1,599 for a 13.8-inch configuration with a 256GB SSD and 16GB of RAM. However, in the US, the base model has double the storage while keeping the same price. Available configurations include up to 64GB of memory and up to 2TB SSD (user-removable PCIe Gen4). The Surface Laptop 8 is now available for purchase on the official Microsoft website.
    • Microsoft announces 12th-gen Surface Pro with Snapdragon X2 processors by Taras Buria So far, 2026 has been rich in Surface announcements. Microsoft started with a fresh lineup of Surface for Business devices powered by Intel's new Core Ultra 300 processors. Then the company revealed the Surface Laptop Ultra, its most powerful laptop with NVIDIA's RTX Spark processor. Now, it is time for new Surface Pro and Surface Laptop models with Qualcomm processors. Microsoft's original Copilot+ PCs with Snapdragon X1 chips debuted in late May 2024. Two years later, Microsoft is finally updating the lineup with new models featuring Snapdragon X2 processors. The 12th-gen Surface Pro continues the well-established formula of Microsoft's flagship tablet, and Microsoft is not even changing colors, as the tablet will be available in three colors: Dune, Black, and Platinum. The most important changes are mostly hidden inside. Microsoft switched from the Snapdragon X1 to the new Snapdragon X2, which promises up to 53% faster graphics performance than the previous generation and up to 15.5 hours of battery life. The built-in NPU is also much more powerful, and it can run at up to 80 TOPS for on-device AI processing. Like before, the new Surface Pro is available with a 13-inch IPS display, and Microsoft is still offering OLED as a separate, more expensive configuration. Speaking of configurations, the Surface Pro will be available with a 10-core Snapdragon X2 Plus or a 12-core Snapdragon X2 Elite. Microsoft expanded the available RAM configurations to 64GB (previously 32GB was the maximum), while storage remains unchanged at 256GB, 512GB, or 1TB of user-replaceable PCIe Gen4 SSDs. The new Surface Pro and the Surface Laptop Other specs remain mostly unchanged. The computer has the same 1440p Windows Hello webcam, two USB4 ports for charging, data, and display output, Wi-Fi 7 and Bluetooth 5.4 support, dual speakers, and compatibility with Surface Pro Signature and Flex keyboards. With that said, there is one very important aspect of the Surface Pro that changed significantly, and it is the price. While the previous-gen Surface Pro launched at $999 for the base configuration, in 2026, the entry-level Surface Pro with Snapdragon X2, 16GB of memory, and 256GB will set you back an eye-watering $1,499. To sweeten the pill, Microsoft is running a limited-time promotion where Surface Pro buyers can get a free Surface Pro 13-inch Keyboard. The promo runs from June 16 through June 30. The new Surface Pro is available now on the official Microsoft Store website.
  • Popular Contributors

    1. 1
      +primortal
      525
    2. 2
      +Edouard
      209
    3. 3
      PsYcHoKiLLa
      113
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!