![]() |
|
#1
|
|||
|
|||
|
Seth Rosenblatt at CNET is reporting on a new beta product developed by Pedro Bustamante and David Sanchez Lavazo, both (formerly?) of Panda Security, which claims to block all exploits:
http://download.cnet.com/8301-2007_4...ntent=My+Yahoo |
|
#2
|
||||
|
||||
|
Quote:
At no point in the article do they indicate how it works except that it isn't a sandbox or antivirus. So it's very likely something similar to EMET. Nice, but they also claim to prevent Java exploits, which EMET doesn't. And I'm very doubtful that this program would stop Java exploits. edit: Downloaded it and wrote up a very quick piece. https://insanitybit.wordpress.com/20...exploitshield/ I'll see if I can test it out later. edit2: It does seem to stop Java exploits but I haven't tested it personally so I can't say exactly how.
__________________
Last edited by Hungry Man : September 29th, 2012 at 10:26 PM. |
|
#3
|
|||
|
|||
|
I would take any program that claims 100% success with a grain of salt.
|
|
#4
|
|||
|
|||
|
Quote:
Hahaha, well said! ![]() |
|
#5
|
|||
|
|||
|
There are Youtube videos of it. Search for them using the keyword ZeroVulnLabs.
![]() |
|
#6
|
|||
|
|||
|
Thanks for testing & reviewing our product.
Yes ExploitShield Browser Edition does protect Java and other components within the browser (Flash, Shockwave, Adobe Reader, etc.). Of course nothing is 100% as you said. The comment refers to the type of exploits we have tested against, it has blocked 100% of them. That is not to say of course there could be a new exploit tomorrow which it doesn't. But for now everything we've thrown at it has been blocked... 3 different IE 0-days, 3 different Java 0-days, Blackhole Exploit Kit 2.0, Phoenix, Incognito, Sakura, PDF exploits, VLC exploits, Windows Media Player exploits, etc. EDIT: I am pbust btw but this is a project of mine which is separate from Panda. Last edited by ZeroVulnLabs : September 28th, 2012 at 12:31 PM. |
|
#7
|
||||
|
||||
|
Looks interesting. It's still in beta and they're looking for testers. From what the video shows it's very much like EMET except it blocks java exploits. It has a list of shielded programs. Worth taking a look.
__________________
Realtime: WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS. On-Demand: MBAM+EAM Hitman pro (Scans daily) |
|
#8
|
||||
|
||||
|
Interesting....
The title of the thread brought me back to the day's of Exploit Prevention Labs and Linkscanner/ScoketShield. Taking this for a spin around the block in ShadowMode.
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness |
|
#9
|
|||
|
|||
|
What the heck. I'm gonna try it.....
![]()
__________________
'Peace on Earth - Purity of Essence.' - Dr. Strangelove |
|
#10
|
||||
|
||||
|
Quote:
__________________
|
|
#11
|
||||
|
||||
|
@ ZeroVulnLabs
Looks interesting I've discovered that ES has stopped HitManProAlert from running ! No fly out as it hasn't even launched ! Are you, or anyone else able to confirm this ? Anyway, all the best with it ![]()
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#12
|
|||
|
|||
|
Weird, I don't see any block events similar to what you are describing. Can you PM me your exploitshield.log file from within %ProgramFiles%\ZeroVulnerabilityLabs\ExploitShield directory?
|
|
#13
|
|||
|
|||
|
Quote:
http://www.zerovulnerabilitylabs.com...bs-technology/ http://www.zerovulnerabilitylabs.com...ked-questions/ |
|
#14
|
||||
|
||||
|
Great, thank you.
edit: well, it kinda told me more about what it isn't. It's not exactly clear still but I suppose that's alright.
__________________
|
|
#15
|
|||
|
|||
|
I hope you understand we cannot tell all the details of how we do it... for many reasons. Bad guys, competitors, etc.
|
|
#16
|
||||
|
||||
|
I understand.
__________________
|
|
#17
|
||||
|
||||
|
@ ZeroVulnLabs
I'll PM the Log in a minute You'll notice i had to install it several times, due to my wanting to see what it was going to install first via ProcessGuard alerts first. Amongst other things, i needed to allow the driver & FF injection. After these were allowed it installed with no errors, that i could see anyway.I don't see any obvious issues in the Log, but you're the best judge of that Have you tried it with HMPA ? I'm using FF v.3.6.14 & don't intend on changing it. Regards
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#18
|
|||
|
|||
|
Thanks for the log!
I don't see any block events. What exactly happened with HMP? Are you sure it was ExploitShield blocking it or it simply failed to run? Did you see a red+black+white alert popup from ExploitShield? |
|
#19
|
||||
|
||||
|
@ ZeroVulnLabs
I'll log out of here so i can close FF & reload & see what happens. Then log back in again & report what i find.
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#20
|
|||
|
|||
|
For those of you that want to test it against real and live drive-by exploit kits, we do have a section in our forum where we post live exploit URLs. You have to be registered and logged in to view it:
http://www.zerovulnerabilitylabs.com/forum |
|
#21
|
||||
|
||||
|
Quote:
NO I "think" the FF injection by ES is interfering "somehow" with HPMA. Please note, it's HitManProAlert & not HitManPro ![]()
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#22
|
|||
|
|||
|
Installed HMP but didn't see a HMP.Alert anywhere. Where can I download the .Alert program from?
|
|
#23
|
||||
|
||||
|
Here ya go http://www.wilderssecurity.com/showthread.php?t=324841
Also i've discovered ES prevents my FF addon SecretAgent from allowing seperate windows to be selectively configured differently. https://www.dephormation.org.uk/index.php?page=81 Some windows i like to use in default mode, others randomized.
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#24
|
|||
|
|||
|
Thanks for the info. We'll check both of these and get back to you.
|
|
#25
|
|||
|
|||
|
When I stop protection, the color of the taskbar icon doesn't change. I would expect a diagonal line or a change in color (red) or change in tooltip.
Also changing from start to stop or back to start protection causes a "Not responding" message before the change is made. Version 0.7 Windows 7 Ultimate, 32 bit IE 9 Last edited by Thankful : September 28th, 2012 at 07:03 PM. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|