Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #126  
Old July 15th, 2012, 07:00 AM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,016
Default Re: Introducing EMET v3

Interesting, thanks for checking HM. I guess we'll know the answer if it's crashing or not in the final version.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #127  
Old July 20th, 2012, 10:04 AM
zakazak zakazak is offline
Frequent Poster
 
Join Date: Sep 2010
Posts: 231
Default Re: Introducing EMET v3

I wonder if EMET could slow down windows? My EMET.xml has ~160kb and pretty much all my apps included:

*link deleted*

@edit: WinSCP is missing in that list.
__________________
CIS & Mbam Pro
OpenDNS + DNSCrypt / EMET / UAC / Applocker
My complete "9 layers of protection" security setup

Last edited by zakazak : July 21st, 2012 at 05:14 AM.
  #128  
Old July 20th, 2012, 02:22 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Introducing EMET v3

EMET shouldn't slow anything down. It's like saying "ASLR has a hit on performance" - technically it does but it's completely negligible. Unless you're on 128mb of RAM and every bit counts you'll be fine.
__________________
  #129  
Old July 21st, 2012, 05:13 AM
zakazak zakazak is offline
Frequent Poster
 
Join Date: Sep 2010
Posts: 231
Default Re: Introducing EMET v3

But still for every .exe that runs, EMET will have to scan the whole .xml file if the .exe is inside the rules. And every .exe will have to load an additional .dll (emet.dll) ?
__________________
CIS & Mbam Pro
OpenDNS + DNSCrypt / EMET / UAC / Applocker
My complete "9 layers of protection" security setup
  #130  
Old July 21st, 2012, 01:58 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Introducing EMET v3

It doesn't have to scan anything. And the emet.dll is something like 40kb.
__________________
  #131  
Old July 25th, 2012, 05:44 AM
test test is offline
Regular Poster
 
Join Date: Feb 2010
Posts: 55
Default Re: Introducing EMET v3

EMET 3.5 Tech Preview
  #132  
Old July 25th, 2012, 06:25 AM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,016
Default Re: Introducing EMET v3

Now that is what I call a nice update! Updated and enabled the new protections on a few processes, no issues yet.

Note:
Quote:
EMET 3.5 TP requires uninstalling previous versions of EMET first. Previously configured applications and rules will be retained and will work again after installing EMET 3.5 TP.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #133  
Old July 25th, 2012, 08:22 AM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,557
Default Re: Introducing EMET v3

Quote:
Originally Posted by funkydude
Now that is what I call a nice update! Updated and enabled the new protections on a few processes, no issues yet.

Note:

I just hope the kind of prompt mentioned in the blog post goes away when the stable version comes out; I do not wish any of my relatives to have to guess whether they should answer "Yes" or "No", because they won't have any idea.
  #134  
Old July 25th, 2012, 01:53 PM
test test is offline
Regular Poster
 
Join Date: Feb 2010
Posts: 55
Default Re: Introducing EMET v3

Quote:
Originally Posted by funkydude
...enabled the new protections on a few processes, no issues yet.
+ 1

EMETized:
IE, Chrome, Foxit reader, VLC, LibreOffice (Latest versions)

Now i only need to check if Sbxie interfers in some way even if i don't think so...

*Sorry for my poor english*
  #135  
Old July 25th, 2012, 02:08 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Introducing EMET v3

When it's finally released I think it deserves its own topic. Huge update.

I use "All" for the .xml and I just enabled all of the ROP mitigations for those. Works fine for me. If EMET was hard to bypass before it just got a lot harder. Anti-ROP is a big deal, it pairs so nicely with EAF, DEP, and ASLR.

edit: I actually wrote about these mitigation techniques when they came out and how they're not all that strong. They mention the same issues in the technet blog.
__________________

Last edited by Hungry Man : July 25th, 2012 at 02:23 PM.
  #136  
Old July 25th, 2012, 04:06 PM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,557
Default Re: Introducing EMET v3

Quote:
Originally Posted by Hungry Man
When it's finally released I think it deserves its own topic. Huge update.

Agreed.

Quote:
Originally Posted by Hungry Man
I use "All" for the .xml and I just enabled all of the ROP mitigations for those. Works fine for me. If EMET was hard to bypass before it just got a lot harder. Anti-ROP is a big deal, it pairs so nicely with EAF, DEP, and ASLR.

Good to see it is working fine for you. I was hoping to see someone else post before I actually enabled the ROP settings.
  #137  
Old July 25th, 2012, 04:15 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Introducing EMET v3

Rebooted into Windows and I haven't had a single crash.
__________________
  #138  
Old July 25th, 2012, 11:37 PM
jdd58's Avatar
jdd58 jdd58 is offline
Frequent Poster
 
Join Date: Jan 2008
Location: Iowa
Posts: 415
Default Re: Introducing EMET v3

It looks like the 3.5 Tech Preview has been pulled already.

We are sorry, the page you requested cannot be found.
  #139  
Old July 25th, 2012, 11:50 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,680
Default Re: Introducing EMET v3

Quote:
Originally Posted by jdd58
It looks like the 3.5 Tech Preview has been pulled already.

We are sorry, the page you requested cannot be found.

I have no problem reaching the web page...

Did you go here:

http://www.microsoft.com/en-us/downl....aspx?id=30424 ?
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #140  
Old July 26th, 2012, 08:04 AM
jdd58's Avatar
jdd58 jdd58 is offline
Frequent Poster
 
Join Date: Jan 2008
Location: Iowa
Posts: 415
Default Re: Introducing EMET v3

Quote:
Originally Posted by puff-m-d
I have no problem reaching the web page...

Did you go here:

http://www.microsoft.com/en-us/downl....aspx?id=30424 ?

Got it now. Thanks puff-m-d!
  #141  
Old July 26th, 2012, 02:52 PM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,557
Default Re: Introducing EMET v3

2 days of testing on 2 machines. No issues. EMET is probably one of my favorite pieces of software.
  #142  
Old July 26th, 2012, 03:21 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Introducing EMET v3

https://insanitybit.wordpress.com/20...ech-preview-9/

Wrote a guide. I provided a new XML file that enables all ROP mitigations for every program that comes in the ALL.XML.

Let me know if you get crashes and if so which program/ which mitigation caused it.
__________________
  #143  
Old July 27th, 2012, 04:30 AM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,680
Default Re: Introducing EMET v3

Quote:
Originally Posted by Hungry Man
And the emet.dll is something like 40kb.
It used to be in the prior 3.5 versions, but now it has jumped up to 548 kb (or at least that is what I find here).
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996

Last edited by puff-m-d : July 27th, 2012 at 04:49 AM.
  #144  
Old July 27th, 2012, 04:48 AM
STV0726's Avatar
STV0726 STV0726 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 868
Default Re: Introducing EMET v3

Quote:
Originally Posted by Hungry Man
https://insanitybit.wordpress.com/20...ech-preview-9/

Wrote a guide. I provided a new XML file that enables all ROP mitigations for every program that comes in the ALL.XML.

Let me know if you get crashes and if so which program/ which mitigation caused it.

That file you tell people to download...is that basically a template/preset save you made of all things you recommend adding EMET protections for?

If so, I might just love you.
__________________
~ STV0726
OS: Windows 7|SRP|SUA|UAC|EFS|EMET|Firewall|Backup
Resident: Webroot SecureAnywhere 2013|Sandboxie
On-Demand: MBAM|SAS|HMP|Comodo CE|Secunia PSI
Browser: Firefox|Web of Trust|Adblock Plus|NoScript
Hardware/Other: Linksys Router|Norton ConnectSafe DNS
  #145  
Old July 27th, 2012, 06:25 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Introducing EMET v3

At 548kb you'd need hundreds of application s open with it for there to be a noticeable difference in RAM usage.

@STV,
Import the file and you'll get protection for applications that are specifically configured. The ROP mitigations have not been configured and I put them on for all of the applications by default.
__________________
  #146  
Old July 27th, 2012, 06:38 AM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,680
Default Re: Introducing EMET v3

I did not mean to imply that this increase would impact system resources to any great extent but just that the dll itself had increased substantially in size. It just makes me ask if all of the increase was just for the new exploits added or if the exploits already covered were improved in any ways.
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #147  
Old July 27th, 2012, 02:21 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Introducing EMET v3

Adding the new code for the ROP mitigations is probably why it increased size.
__________________
  #148  
Old July 27th, 2012, 04:31 PM
xxJackxx's Avatar
xxJackxx xxJackxx is offline
Very Frequent Poster
 
Join Date: Oct 2008
Location: USA
Posts: 2,557
Default Re: Introducing EMET v3

Quote:
Originally Posted by Hungry Man
At 548kb you'd need hundreds of application s open with it for there to be a noticeable difference in RAM usage.

Yeah, I personally could care less about a little RAM usage. I don't see any noticeable slowdown with EMET.
  #149  
Old July 28th, 2012, 01:58 AM
STV0726's Avatar
STV0726 STV0726 is offline
Frequent Poster
 
Join Date: Jul 2010
Posts: 868
Default Re: Introducing EMET v3

A question about importing presets other people made:

1) What happens for apps listed that aren't actually installed on your comp? Will the entry just remain there for if you ever do install it or does it cause an error?

2) @Hungry: So importing that has all the apps you recommend using EMET and the mitigations checked on?
__________________
~ STV0726
OS: Windows 7|SRP|SUA|UAC|EFS|EMET|Firewall|Backup
Resident: Webroot SecureAnywhere 2013|Sandboxie
On-Demand: MBAM|SAS|HMP|Comodo CE|Secunia PSI
Browser: Firefox|Web of Trust|Adblock Plus|NoScript
Hardware/Other: Linksys Router|Norton ConnectSafe DNS
  #150  
Old July 28th, 2012, 03:00 AM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,519
Default Re: Introducing EMET v3

@STV,

1) They'll activate when you install the application

2) all.xml is provided by Microsoft with all of *their* configurations. I took all.xml and enabled every ROP mitigation for the applications listed there.

Hence allrop.xml.
__________________
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:18 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums