Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 27th, 2012, 02:22 PM
Breakfastofchumps Breakfastofchumps is offline
Frequent Poster
 
Join Date: Jul 2011
Posts: 321
Default Bypassing EMET 3.5′s ROP Mitigations

Quote:
UPDATE : It seems MS was aware of this kind of bypasses, so I bypassed EMET ROP mitigations using another EMET’s implementation mistake. EMET team forget about the KernelBase.dll and left all its functions unprotected. so I used @antic0de‘s method for finding base address of kernelbase.dll at run-time, then I used VirtualProtect inside the kernelbase.dll, not ntdll.dll or krenel32.dll. you can get new exploit at the end of this post.

I have managed to bypass EMET 3.5, which is recently released after Microsoft BlueHat Prize, and wrote full-functioning exploit for CVE-2011-1260 (I choosed this CVE randomly!) with all EMET’s ROP mitigation enabled.

Any truth in this article?

https://repret.wordpress.com/2012/08...p-mitigations/
__________________
Kis 2013
Emet
  #2  
Old September 27th, 2012, 03:12 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Bypassing EMET 3.5′s ROP Mitigations

Yes, it's true. This was discussed in the EMET topic.

Unfortunately for Windows users there are a select few areas of a programs address space that will always remain static - no matter if you're using EMET or ASLR Always On or not.

This demonstrates that even a single area of address space is sufficient for an attacker to bypass ASLR.

Once they've done that it's a matter of bypassing EMET's new Anti-ROP mitigations, which isn't very difficult.

This doesn't mean EMET is 'broken' or 'weak' - it's still going to protect you from exploits, it's still going to make exploits harder to write, and generic exploitation of a program running EMET is still difficult.
__________________
  #3  
Old September 27th, 2012, 03:14 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: Bypassing EMET 3.5′s ROP Mitigations

very true
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #4  
Old September 27th, 2012, 03:48 PM
Breakfastofchumps Breakfastofchumps is offline
Frequent Poster
 
Join Date: Jul 2011
Posts: 321
Default Re: Bypassing EMET 3.5′s ROP Mitigations

Thank you Hungry Man.
__________________
Kis 2013
Emet
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:30 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums