Free Microsoft security tool Enhanced Mitigation Evaluation Toolkit locks down apps

Discussion in 'other security issues & news' started by MrBrian, Mar 7, 2010.

Thread Status:
Not open for further replies.
  1. Doritoes

    Doritoes Registered Member

    Joined:
    Jul 2, 2010
    Posts:
    56
    Apple Safari won't run if you set DEP to always on with EMET.
     
  2. safeguy

    safeguy Registered Member

    Joined:
    Jun 14, 2010
    Posts:
    1,795
    I did run it with Admin privileges...both under my LUA account and under my Admin account - still the same nothing.

    And afaik, the command line interface is similar to V1.02 which I've used before...so that isn't my objective.

    Yes, indeed. I'm referring to that. Any ideas?

    Seems like I'm not alone in this case....thanks for that. I really wish to see what's up with the GUI and if it's gonna make it easier to use.
     
  3. HAN

    HAN Registered Member

    Joined:
    Feb 24, 2005
    Posts:
    2,098
    Location:
    USA
    Installed EMET 2.0 on an XP SP3 box. The only thing that appears to work is the system wide DEP indicator (which is correct... set to Opt Out.) (I know that SEHOP and ASLR aren't available in XP.)

    Beyond that, nothing shows in the Running EMET column. Should it be? I tired adding apps and nothing happens, even after reboots.

    **EDIT**
    I kept tinkering and finally got something to show up. But more tinkering and it was gone. So IMO, the GUI is buggy. At least in XP. The command line interface was always right if EMET was activated for an application but you have no granularity of control with the command line. This tool has a ways to go...
     
    Last edited: Sep 8, 2010
  4. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    v2.0.0.1 is available.

    From http://blogs.technet.com/b/srd/archive/2010/09/10/use-emet-2-0-to-block-the-adobe-0-day-exploit.aspx:
     
  5. jdd58

    jdd58 Registered Member

    Joined:
    Jan 30, 2008
    Posts:
    556
    Location:
    Sonoran Desert
  6. HJO

    HJO Guest

    No automatic update? lol
     
  7. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    I'd rather they didn't add useless features.
     
  8. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    It seems the installer from the official download link is not updated yet, as I tried to install it and the only options were to repair or remove my current 2.0 version.
     
  9. HJO

    HJO Guest

    Same here...
     
  10. alternety

    alternety Registered Member

    Joined:
    Nov 18, 2008
    Posts:
    37
    I am one of the unwashed masses trying to use EMET for the zero day problems with Reader. I downloaded it and installed it.

    MS page says simply enter this C:\Program Files (x86)\EMET>emet_conf.exe --add "c:\program files (x86)\Adobe\Reader 9.0\Reader\acrord32.exe"
    and all will be well. I simply don't understand what has to be done.

    I opened a command prompt and entered the text string - not recognized as command. Changed directory I was in to c: and tried. No go.

    Changed directory to c:\Program Files (x86) and typed in only the text after that in the MS page. Still nothing.

    Could anyone help me out with MSDOS 101 here?

    I am also curious if this will resolve the Flash exploit. What I read seemed to say the same file is at fault in both cases.

    Never mind about using it. I just used the GUI and that was fine.

    However I would still like to know if this also fixes the Flash exploit?


     
    Last edited: Sep 14, 2010
  11. AvinashR

    AvinashR Registered Member

    Joined:
    Dec 26, 2009
    Posts:
    2,063
    Location:
    New Delhi Metallo β-Lactamase 1
    Check you program files where EMET 2.0 is installed.. You'll find that EMET.dll, EMET64.dll and MitigationInterface.dll have been updated to version 2.0.0.1 ... GUI and some other files have not been updated to 2.0.0.1 .. So it seems that the most important files are updated :)

    Hope it will help you.. :)
     
  12. AvinashR

    AvinashR Registered Member

    Joined:
    Dec 26, 2009
    Posts:
    2,063
    Location:
    New Delhi Metallo β-Lactamase 1
    Very True .. But command lines have been changed.. You cannot use the old command lines in version 2.0 ... Why don't you try it and find if it is working for you or not.. :)
     
  13. Sadeghi85

    Sadeghi85 Registered Member

    Joined:
    Dec 20, 2009
    Posts:
    747
    Change the directory to C:\Program Files (x86)\EMET and type this:

    Code:
    emet_conf.exe --add "c:\program files (x86)\Adobe\Reader 9.0\Reader\acrord32.exe"
     
  14. guest

    guest Guest

    Wich kind of apps do you protect with EMET?

    How could be a normal configuration or how is your configuration?

    Is usable for a normal user the profile "Maximun security settings"?

    Thanks
     
  15. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    I've gone for 'Application Opt Out' with the DEP setting because some poorly coded applications refuse to run with it set to maximum.

    With regards to applications you can opt-in pretty much everything with no problems,but I suggest giving each program a thorough test after setting it just in case of any anomalies.

    The real SRP/LUA experts here will be able to advise on potential issues better than an EMET noob such as I :D
     
  16. microbial

    microbial Registered Member

    Joined:
    Aug 26, 2009
    Posts:
    156
    Location:
    UK
    Why is SEHOP when enabled listed as 'Application Opt Out?'

    Surely you're 'opting in' to the protection provided by enabling SEHOP?! I'm confused...


    EMET.jpg
     
  17. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    I thought that SEHOP was possible to turn on for Windows Vista SP2. At least, that's what says at Microsoft page, where it says how to manually apply SEHOP, through registry. Which, I did.
    But, today, after installing EMET on a relative's system, it showed as being disabled, and the only way to have it enabled was has "Always on". A crash occured. I let it disabled.

    That's odd. Why would Microsoft EMET recommend it to be disabled, if it is supposed to work with Vista SP2 as well? Odd... Odd.
     
  18. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Don't you need to turn it on with the fixit tool first?
     
  19. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    It's working fine for me running Vista SP2 here.I just ran the Fix-It tool despite it saying it was only for SP1 (the beauty of having rollback software).
     
  20. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    And, I had it done, weeks ago. But, it seems that, for whatever reason, it didn't apply? No idea.

    I'll try to re-apply the fix first, once again, and then check again with EMET.
     
  21. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    That one made my laugh. So, Microsoft says SEHOP only works for Windows Vista SP2 and forward, but you got it working for SP1? That's great.

    I wonder what the heck Microsoft is doing. Don't they test it properly?
     
  22. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    No sorry you misunderstood me,although I'm always pleased to make folks laugh :D

    I ran the MS automated Fix-It tool despite it stating it only applies to Vista SP1 and Server 2008,confusing since I thought it was enabled by default with the latter OS o_O I'm running SP2 here.Anyway the upshot is that it all worked perfectly for me.
     
  23. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    Without detailed instructions, I would have no idea what to opt in and out of. As an average user, is there any point in my installing EMET?
     
  24. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    A good starting point is to add the executables for all your programs in there and look for any issues.I've added all my common stuff and there have been no problems so far.It's worth using because it mitigates against a lot of exploits such as the many Adobe pdf,etc.Always better to preemptively block a whole category of exploits than to try to catch individual malware later on.
     
  25. justenough

    justenough Registered Member

    Joined:
    May 13, 2010
    Posts:
    1,549
    I am using NitroPDF because I read about Adobe's vulnerablity. Would it still be worthwhile using EMET, or just enable DEP and SEHOP in 7?

    When you say add the executables, I guess I would add them one at a time and see what happens.

    So far all I've done is set EMET to maximum security settings, so DEP is always on, SEHOP is opt out, and ASLR is opt in. So I would be adding the executables to ASLR?

    Nothing is showing as running in the EMET column.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.