Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 28th, 2012, 09:17 AM
sbwhiteman sbwhiteman is offline
Regular Poster
 
Join Date: Jul 2009
Posts: 50
Default ZeroVulnerabilityLabs ExploitShield

Seth Rosenblatt at CNET is reporting on a new beta product developed by Pedro Bustamante and David Sanchez Lavazo, both (formerly?) of Panda Security, which claims to block all exploits:

http://download.cnet.com/8301-2007_4...ntent=My+Yahoo
  #2  
Old September 28th, 2012, 09:24 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: ZeroVulnerabilityLabs ExploitShield

Quote:
It blocks 100 percent of the exploits it protects against
So it protects against what it protects 100% of the time. Yeah...

At no point in the article do they indicate how it works except that it isn't a sandbox or antivirus.

So it's very likely something similar to EMET. Nice, but they also claim to prevent Java exploits, which EMET doesn't. And I'm very doubtful that this program would stop Java exploits.

edit: Downloaded it and wrote up a very quick piece. https://insanitybit.wordpress.com/20...exploitshield/

I'll see if I can test it out later.

edit2: It does seem to stop Java exploits but I haven't tested it personally so I can't say exactly how.
__________________

Last edited by Hungry Man : September 29th, 2012 at 10:26 PM.
  #3  
Old September 28th, 2012, 09:27 AM
phalanaxus phalanaxus is offline
Regular Poster
 
Join Date: Jan 2011
Posts: 72
Default Re: ZeroVulnerabilityLabs ExploitShield

I would take any program that claims 100% success with a grain of salt.
  #4  
Old September 28th, 2012, 09:42 AM
carat
 
Posts: n/a
Default Re: ZeroVulnerabilityLabs ExploitShield

Quote:
Originally Posted by Hungry Man
So it protects against what it protects 100% of the time. Yeah...

Hahaha, well said!
  #5  
Old September 28th, 2012, 10:40 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,456
Default Re: ZeroVulnerabilityLabs ExploitShield

There are Youtube videos of it. Search for them using the keyword ZeroVulnLabs.
  #6  
Old September 28th, 2012, 11:30 AM
ZeroVulnLabs ZeroVulnLabs is offline
Developer
 
Join Date: Mar 2012
Location: USA
Posts: 236
Default Re: ZeroVulnerabilityLabs ExploitShield

Thanks for testing & reviewing our product.

Yes ExploitShield Browser Edition does protect Java and other components within the browser (Flash, Shockwave, Adobe Reader, etc.).

Of course nothing is 100% as you said. The comment refers to the type of exploits we have tested against, it has blocked 100% of them. That is not to say of course there could be a new exploit tomorrow which it doesn't. But for now everything we've thrown at it has been blocked... 3 different IE 0-days, 3 different Java 0-days, Blackhole Exploit Kit 2.0, Phoenix, Incognito, Sakura, PDF exploits, VLC exploits, Windows Media Player exploits, etc.

EDIT: I am pbust btw but this is a project of mine which is separate from Panda.

Last edited by ZeroVulnLabs : September 28th, 2012 at 12:31 PM.
  #7  
Old September 28th, 2012, 11:37 AM
kjdemuth's Avatar
kjdemuth kjdemuth is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Boston, MA
Posts: 2,340
Default Re: ZeroVulnerabilityLabs ExploitShield

Looks interesting. It's still in beta and they're looking for testers. From what the video shows it's very much like EMET except it blocks java exploits. It has a list of shielded programs. Worth taking a look.
__________________
Realtime:
WSA AV (Maxed Settings), Sandboxie Paid ( Dropmyrights and Browsers sandboxed) Lifetime license, NVT EXE Radar Pro (Lockdown mode). K9 Web protection. (malware, phishing and HTTPS force) Norton DNS.
On-Demand:
MBAM+EAM
Hitman pro (Scans daily)
  #8  
Old September 28th, 2012, 04:26 PM
LoneWolf's Avatar
LoneWolf LoneWolf is online now
Massive Poster
 
Join Date: Jan 2006
Posts: 3,132
Default Re: ZeroVulnerabilityLabs ExploitShield

Interesting....
The title of the thread brought me back to the day's of Exploit Prevention Labs and Linkscanner/ScoketShield.
Taking this for a spin around the block in ShadowMode.
__________________
May you fly straight to heaven - but if you go to Hades - may Lethe run with Guinness
  #9  
Old September 28th, 2012, 04:36 PM
kdcdq kdcdq is offline
Frequent Poster
 
Join Date: Apr 2002
Location: Southwestern Massachusetts
Posts: 540
Default Re: ZeroVulnerabilityLabs ExploitShield

What the heck. I'm gonna try it.....
__________________
'Peace on Earth - Purity of Essence.'
- Dr. Strangelove
  #10  
Old September 28th, 2012, 04:37 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: ZeroVulnerabilityLabs ExploitShield

Quote:
Originally Posted by ZeroVulnLabs
Thanks for testing & reviewing our product.

Yes ExploitShield Browser Edition does protect Java and other components within the browser (Flash, Shockwave, Adobe Reader, etc.).

Of course nothing is 100% as you said. The comment refers to the type of exploits we have tested against, it has blocked 100% of them. That is not to say of course there could be a new exploit tomorrow which it doesn't. But for now everything we've thrown at it has been blocked... 3 different IE 0-days, 3 different Java 0-days, Blackhole Exploit Kit 2.0, Phoenix, Incognito, Sakura, PDF exploits, VLC exploits, Windows Media Player exploits, etc.

EDIT: I am pbust btw but this is a project of mine which is separate from Panda.
You mention it's not a sandbox (or someone did) but it seems like your product denied execution of a payload. It's a bit vague so I can't really tell what's happening yet but that seems sandboxesque to me? Can you provide some details as to how it works?
__________________
  #11  
Old September 28th, 2012, 04:59 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Exclamation Re: ZeroVulnerabilityLabs ExploitShield

@ ZeroVulnLabs

Looks interesting so i installed it.

I've discovered that ES has stopped HitManProAlert from running ! No fly out as it hasn't even launched !

Are you, or anyone else able to confirm this ?

Anyway, all the best with it
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #12  
Old September 28th, 2012, 05:17 PM
ZeroVulnLabs ZeroVulnLabs is offline
Developer
 
Join Date: Mar 2012
Location: USA
Posts: 236
Default Re: ZeroVulnerabilityLabs ExploitShield

Weird, I don't see any block events similar to what you are describing. Can you PM me your exploitshield.log file from within %ProgramFiles%\ZeroVulnerabilityLabs\ExploitShield directory?
  #13  
Old September 28th, 2012, 05:27 PM
ZeroVulnLabs ZeroVulnLabs is offline
Developer
 
Join Date: Mar 2012
Location: USA
Posts: 236
Default Re: ZeroVulnerabilityLabs ExploitShield

Quote:
Originally Posted by Hungry Man
You mention it's not a sandbox (or someone did) but it seems like your product denied execution of a payload. It's a bit vague so I can't really tell what's happening yet but that seems sandboxesque to me? Can you provide some details as to how it works?
What we can say is posted on our site. I recommend these two pages:
http://www.zerovulnerabilitylabs.com...bs-technology/
http://www.zerovulnerabilitylabs.com...ked-questions/
  #14  
Old September 28th, 2012, 05:30 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: ZeroVulnerabilityLabs ExploitShield

Great, thank you.

edit: well, it kinda told me more about what it isn't. It's not exactly clear still but I suppose that's alright.
__________________
  #15  
Old September 28th, 2012, 05:34 PM
ZeroVulnLabs ZeroVulnLabs is offline
Developer
 
Join Date: Mar 2012
Location: USA
Posts: 236
Default Re: ZeroVulnerabilityLabs ExploitShield

I hope you understand we cannot tell all the details of how we do it... for many reasons. Bad guys, competitors, etc.
  #16  
Old September 28th, 2012, 05:35 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: ZeroVulnerabilityLabs ExploitShield

I understand.
__________________
  #17  
Old September 28th, 2012, 05:35 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Lightbulb Re: ZeroVulnerabilityLabs ExploitShield

@ ZeroVulnLabs

I'll PM the Log in a minute You'll notice i had to install it several times, due to my wanting to see what it was going to install first via ProcessGuard alerts first. Amongst other things, i needed to allow the driver & FF injection. After these were allowed it installed with no errors, that i could see anyway.

I don't see any obvious issues in the Log, but you're the best judge of that

Have you tried it with HMPA ?

I'm using FF v.3.6.14 & don't intend on changing it.

Regards
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #18  
Old September 28th, 2012, 05:42 PM
ZeroVulnLabs ZeroVulnLabs is offline
Developer
 
Join Date: Mar 2012
Location: USA
Posts: 236
Default Re: ZeroVulnerabilityLabs ExploitShield

Thanks for the log!

I don't see any block events. What exactly happened with HMP? Are you sure it was ExploitShield blocking it or it simply failed to run? Did you see a red+black+white alert popup from ExploitShield?
  #19  
Old September 28th, 2012, 05:47 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Default Re: ZeroVulnerabilityLabs ExploitShield

@ ZeroVulnLabs

I'll log out of here so i can close FF & reload & see what happens. Then log back in again & report what i find.
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #20  
Old September 28th, 2012, 05:50 PM
ZeroVulnLabs ZeroVulnLabs is offline
Developer
 
Join Date: Mar 2012
Location: USA
Posts: 236
Default Re: ZeroVulnerabilityLabs ExploitShield

For those of you that want to test it against real and live drive-by exploit kits, we do have a section in our forum where we post live exploit URLs. You have to be registered and logged in to view it:
http://www.zerovulnerabilitylabs.com/forum
  #21  
Old September 28th, 2012, 05:51 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Lightbulb Re: ZeroVulnerabilityLabs ExploitShield

Quote:
Did you see a red+black+white alert popup from ExploitShield?

NO

I "think" the FF injection by ES is interfering "somehow" with HPMA.

Please note, it's HitManProAlert & not HitManPro
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #22  
Old September 28th, 2012, 06:02 PM
ZeroVulnLabs ZeroVulnLabs is offline
Developer
 
Join Date: Mar 2012
Location: USA
Posts: 236
Default Re: ZeroVulnerabilityLabs ExploitShield

Installed HMP but didn't see a HMP.Alert anywhere. Where can I download the .Alert program from?
  #23  
Old September 28th, 2012, 06:09 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,854
Lightbulb Re: ZeroVulnerabilityLabs ExploitShield

Here ya go http://www.wilderssecurity.com/showthread.php?t=324841

Also i've discovered ES prevents my FF addon SecretAgent from allowing seperate windows to be selectively configured differently. https://www.dephormation.org.uk/index.php?page=81 Some windows i like to use in default mode, others randomized.
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #24  
Old September 28th, 2012, 06:12 PM
ZeroVulnLabs ZeroVulnLabs is offline
Developer
 
Join Date: Mar 2012
Location: USA
Posts: 236
Default Re: ZeroVulnerabilityLabs ExploitShield

Thanks for the info. We'll check both of these and get back to you.
  #25  
Old September 28th, 2012, 06:40 PM
Thankful Thankful is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: New York City
Posts: 2,407
Default Re: ZeroVulnerabilityLabs ExploitShield

When I stop protection, the color of the taskbar icon doesn't change. I would expect a diagonal line or a change in color (red) or change in tooltip.
Also changing from start to stop or back to start protection causes a "Not responding" message before the change is made.

Version 0.7
Windows 7 Ultimate, 32 bit
IE 9

Last edited by Thankful : September 28th, 2012 at 07:03 PM.
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:51 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums