{"id":3689,"date":"2016-06-10T19:06:02","date_gmt":"2016-06-10T19:06:02","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=3689"},"modified":"2016-06-10T19:08:04","modified_gmt":"2016-06-10T19:08:04","slug":"enter-sandbox-part-11-breaking-the-sandbox-literally","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2016\/06\/10\/enter-sandbox-part-11-breaking-the-sandbox-literally\/","title":{"rendered":"Enter Sandbox &#8211; part 11: Breaking the sandbox, literally :)"},"content":{"rendered":"<p>My homemade VMs run on VMWare. I use it for a number of years now and is my preference as it&#8217;s very fast (especially on SSD), configuration is very flexible, the management of snapshots is very user-friendly and in general &#8211; I am really happy with it.<\/p>\n<p>I use VMWare to run some of automated malware analysis too and with nearly 1 million files processed there are occasions when it breaks.<\/p>\n<p>I would be really curious to know what is the failure ratio for the commercial sandboxes, but I would imagine this must be happening quite a bit, given the volume of samples they process. I guess it&#8217;s probably one of the best stress tests for VMs &#8211; the code ran in a malware sandbox does a lot of funny stuff and is written by gazillions of clever programmers. There is a huge variety of code, data, errors, undocumented tricks, etc. &#8211; I bet some researchers already do it, but I would imagine this could be a good way to automate fuzzing of the VM software in order to find VM escapes.<\/p>\n<p>In any case, since this post falls under &#8216;Enter sandbox&#8217; series, it&#8217;s actually just a quickie dedicated to the dialog boxes that every once in a while kill my batch processing \ud83d\ude42<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3690\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/1-300x116.png\" alt=\"1\" width=\"300\" height=\"116\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/1-300x116.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/1.png 384w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3691\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/2-300x85.png\" alt=\"2\" width=\"300\" height=\"85\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/2-300x85.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/2.png 477w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3692\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/3-300x110.png\" alt=\"3\" width=\"300\" height=\"110\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/3-300x110.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/3.png 475w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3693\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/4-300x177.png\" alt=\"4\" width=\"300\" height=\"177\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/4-300x177.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/4.png 413w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3694\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/5-300x106.png\" alt=\"5\" width=\"300\" height=\"106\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/5-300x106.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/5.png 382w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3695\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/6-300x113.png\" alt=\"6\" width=\"300\" height=\"113\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/6-300x113.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/6.png 324w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3696\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/7-300x236.png\" alt=\"7\" width=\"300\" height=\"236\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/7-300x236.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/7.png 382w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-medium wp-image-3697\" src=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/8-300x157.png\" alt=\"8\" width=\"300\" height=\"157\" srcset=\"https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/8-300x157.png 300w, https:\/\/www.hexacorn.com\/blog\/wp-content\/uploads\/2016\/06\/8.png 348w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>My homemade VMs run on VMWare. I use it for a number of years now and is my preference as it&#8217;s very fast (especially on SSD), configuration is very flexible, the management of snapshots is very user-friendly and in general &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2016\/06\/10\/enter-sandbox-part-11-breaking-the-sandbox-literally\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[41,18],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3689"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=3689"}],"version-history":[{"count":3,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3689\/revisions"}],"predecessor-version":[{"id":3700,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3689\/revisions\/3700"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=3689"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=3689"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=3689"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}