ExploitShield Browser Edition 0.9

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Mar 26, 2013.

Thread Status:
Not open for further replies.
  1. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    TH DR_LaRRY_PEpPeR.
     
  2. DR_LaRRY_PEpPeR

    DR_LaRRY_PEpPeR Registered Member

    Joined:
    Oct 11, 2012
    Posts:
    141
    Location:
    St. Louis area
    As Sampei Nihira found, I can confirm that ExploitShield.dll with not load, under any circumstances, with any version of Sandboxie 4.01.xx. So for now, no, it doesn't work with Sandboxie 4. :doubt:
     
  3. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    File Rihanna - Stay (2) false mp3 (asf).
    Analysis VT on line:

    ~VT link removed~


    Immagine.JPG

    ExploitShield 0 pop-up alert !!

    _______________________________


    Opening the file with WMP (no VLC) you open your browser and you have a window file download (setup.exe):

    ~VT link removed~

    Anubis - Analysis Report

    Sorry my bad English.
     
    Last edited by a moderator: May 5, 2013
  4. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    That's not an exploit. It's a simple redirect to download a file from the web (ie social engineering) and its the job of the AV to stop that. You would have to choose to download and open it before it can run on your machine.

    ScreenShot00304.png
    ScreenShot00305.png

    An exploit on the other hand would run the file automatically without user prompts and it would be blocked by ExploitShield. Some examples of media player (VLC, Quicktime, WMP) exploits being blocked by ExploitShield can be found at http://www.youtube.com/playlist?list=PL95F2A1B2AA762B5B.
     
  5. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    @ ZVL

    Thanks for your explanation.
     
  6. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    Links to malware are not allowed in this forum.
     
  7. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Removed.
    Th.:thumb:
     
  8. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  9. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  10. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    Is there any benefit to using this with Sandboxie? Wouldn't Sandboxie stop any exploits from getting onto your system anyway?
     
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  12. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Last edited: May 13, 2013
  13. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Sure thing, if there's anything we can do to help to make them compatible we'd love to. But it seems as if its a problem with allowing ES within SBIE, so its probably mostly if not all to be fixed by SBIE?
     
  14. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    I would ask help for this mediator to DR_LaRRY_PEpPeR who respect of me know certain english.
    I send him on Private message.

    p.s. Send.
     
    Last edited: May 13, 2013
  15. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    Does Exploitshield offer any additional protection inside Sandboxie? Wouldn't any exploits be contained within the sandbox and be removed once it is emptied?
     
  16. DR_LaRRY_PEpPeR

    DR_LaRRY_PEpPeR Registered Member

    Joined:
    Oct 11, 2012
    Posts:
    141
    Location:
    St. Louis area
    Yep, Sandboxie should fully protect you, ultimately. It's just that ES could stop something from being dropped in the first place, and then possibly running inside the sandbox while it's active, before it's deleted, etc.

    So it's like how I/we use EMET, to stop exploits at an earlier stage, before it gets to Sandboxie as the last line of (strong) defense. :)


    Agreed, short of ES using a different method to inject the DLL, Sandboxie needs to be fixed to allow it to load as it does in 3.76. It's probably not a major thing, and I'd think it'd get fixed here eventually, just not a high-priority thing now. :) I guess it's a more "generic problem" that could possibly affect another product's loading of DLLs as well... *shrug*
     
  17. 0strodamus

    0strodamus Registered Member

    Joined:
    Aug 23, 2009
    Posts:
    1,058
    Location:
    United Surveillance States
    That's what I thought. Thanks for confirming for me doctor! :)
     
  18. kupo

    kupo Registered Member

    Joined:
    Jan 25, 2011
    Posts:
    1,121
    I've got the missing tray icon bug. Ending the application and starting it again somehow restored it for the CURRENT session only. Restarting my laptop will again have a missing tray icon. Very annoying, lol.
    EDIT: Reinstalling did not fix the "issue".
     
    Last edited: May 16, 2013
  19. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    ES has intervened.
    Chrome home page https://encrypted.google.com/

    Immagine.jpg

    Supposition:
    Installation of new version 8.3 of Clic& Clean ?

    Problem no more replicable after 3 pop-up.

    OS Windows 7 64 bit
    SUA

     
    Last edited: May 20, 2013
  20. vojta

    vojta Registered Member

    Joined:
    Feb 26, 2010
    Posts:
    830
    I also have Click& Clean 8.3 in Chrome and ES never gave me an alert.
     
  21. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    It's the same bug as mentioned in the other ExploitShield thread. It's a known issue which will be fixed in the next release. It doesn't happen every time nor to all users and its difficult to replicate reliably.
     
  22. kupo

    kupo Registered Member

    Joined:
    Jan 25, 2011
    Posts:
    1,121
    Bump! Any ETA on the next release? The missing tray icon is really annoying. :D
     
  23. Dundertaker

    Dundertaker Registered Member

    Joined:
    Oct 17, 2009
    Posts:
    391
    Location:
    Land of the Mer Lion
    Just got wind of this application and installed it in an XP SP3 with Avast IS version 8 Build 1489 as realtime. I have no protection even when I check/find/target dll in Process Hacker "Exploitshield.dll".

    See image below. What am I doing wrong here...? I see also that I can seem to "Start" Exploitshield. After installation, I rebooted and it was still like that. Then I checked if Chrome will be protected and it wasn't. So I uninstalled and installed again (ver 0.9.1 beta) and reboted. I checked it was the same > can't start application so Chrome/Firefox/Opera is unprotected.
     

    Attached Files:

    Last edited: May 25, 2013
  24. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    As you can see from the GUI the red label says that ExploitShield is not running. This is probably due to an incomplete uninstall of a previously installed version and/or conflict with your security software.

    Try the following:
    1- Right-click the ES traybar icon and choose Exit.
    2- Uninstall ES from Control Panel
    3- Reboot
    4- Download and install again

    Is the GUI still showing the red label?
     
  25. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Last edited: May 27, 2013
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.