![]() |
|
#1
|
|||
|
|||
|
Quote:
Any truth in this article? https://repret.wordpress.com/2012/08...p-mitigations/
__________________
Kis 2013 Emet |
|
#2
|
||||
|
||||
|
Yes, it's true. This was discussed in the EMET topic.
Unfortunately for Windows users there are a select few areas of a programs address space that will always remain static - no matter if you're using EMET or ASLR Always On or not. This demonstrates that even a single area of address space is sufficient for an attacker to bypass ASLR. Once they've done that it's a matter of bypassing EMET's new Anti-ROP mitigations, which isn't very difficult. This doesn't mean EMET is 'broken' or 'weak' - it's still going to protect you from exploits, it's still going to make exploits harder to write, and generic exploitation of a program running EMET is still difficult.
__________________
|
|
#3
|
||||
|
||||
|
very true
![]()
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13 |
|
#4
|
|||
|
|||
|
Thank you Hungry Man.
__________________
Kis 2013 Emet |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|