Introducing EMET v3

Discussion in 'other security issues & news' started by ronjor, May 15, 2012.

Thread Status:
Not open for further replies.
  1. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Interesting, thanks for checking HM. I guess we'll know the answer if it's crashing or not in the final version.
     
  2. zakazak

    zakazak Registered Member

    Joined:
    Sep 20, 2010
    Posts:
    529
    I wonder if EMET could slow down windows? My EMET.xml has ~160kb and pretty much all my apps included:

    *link deleted*

    @edit: WinSCP is missing in that list.
     
    Last edited: Jul 21, 2012
  3. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    EMET shouldn't slow anything down. It's like saying "ASLR has a hit on performance" - technically it does but it's completely negligible. Unless you're on 128mb of RAM and every bit counts you'll be fine.
     
  4. zakazak

    zakazak Registered Member

    Joined:
    Sep 20, 2010
    Posts:
    529
    But still for every .exe that runs, EMET will have to scan the whole .xml file if the .exe is inside the rules. And every .exe will have to load an additional .dll (emet.dll) ?
     
  5. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    It doesn't have to scan anything. And the emet.dll is something like 40kb.
     
  6. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
  7. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Now that is what I call a nice update! Updated and enabled the new protections on a few processes, no issues yet.

    Note:
     
  8. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    I just hope the kind of prompt mentioned in the blog post goes away when the stable version comes out; I do not wish any of my relatives to have to guess whether they should answer "Yes" or "No", because they won't have any idea. :ouch:
     
  9. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    + 1

    EMETized:
    IE, Chrome, Foxit reader, VLC, LibreOffice (Latest versions)

    Now i only need to check if Sbxie interfers in some way even if i don't think so...

    *Sorry for my poor english*
     
  10. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    When it's finally released I think it deserves its own topic. Huge update.

    I use "All" for the .xml and I just enabled all of the ROP mitigations for those. Works fine for me. If EMET was hard to bypass before it just got a lot harder. Anti-ROP is a big deal, it pairs so nicely with EAF, DEP, and ASLR.

    edit: I actually wrote about these mitigation techniques when they came out and how they're not all that strong. They mention the same issues in the technet blog.
     
    Last edited: Jul 25, 2012
  11. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Agreed.

    Good to see it is working fine for you. I was hoping to see someone else post before I actually enabled the ROP settings. :thumb:
     
  12. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Rebooted into Windows and I haven't had a single crash.
     
  13. jdd58

    jdd58 Registered Member

    Joined:
    Jan 30, 2008
    Posts:
    556
    Location:
    Sonoran Desert
    It looks like the 3.5 Tech Preview has been pulled already.

    We are sorry, the page you requested cannot be found.
     
  14. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
  15. jdd58

    jdd58 Registered Member

    Joined:
    Jan 30, 2008
    Posts:
    556
    Location:
    Sonoran Desert
  16. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    2 days of testing on 2 machines. No issues. EMET is probably one of my favorite pieces of software. :thumb:
     
  17. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
  18. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    It used to be in the prior 3.5 versions, but now it has jumped up to 548 kb (or at least that is what I find here).
     
    Last edited: Jul 27, 2012
  19. STV0726

    STV0726 Registered Member

    Joined:
    Jul 29, 2010
    Posts:
    900
    That file you tell people to download...is that basically a template/preset save you made of all things you recommend adding EMET protections for?

    If so, I might just love you.
     
  20. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    At 548kb you'd need hundreds of application s open with it for there to be a noticeable difference in RAM usage.

    @STV,
    Import the file and you'll get protection for applications that are specifically configured. The ROP mitigations have not been configured and I put them on for all of the applications by default.
     
  21. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    I did not mean to imply that this increase would impact system resources to any great extent but just that the dll itself had increased substantially in size. It just makes me ask if all of the increase was just for the new exploits added or if the exploits already covered were improved in any ways.
     
  22. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Adding the new code for the ROP mitigations is probably why it increased size.
     
  23. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Yeah, I personally could care less about a little RAM usage. I don't see any noticeable slowdown with EMET.
     
  24. STV0726

    STV0726 Registered Member

    Joined:
    Jul 29, 2010
    Posts:
    900
    A question about importing presets other people made:

    1) What happens for apps listed that aren't actually installed on your comp? Will the entry just remain there for if you ever do install it or does it cause an error?

    2) @Hungry: So importing that has all the apps you recommend using EMET and the mitigations checked on?
     
  25. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    @STV,

    1) They'll activate when you install the application

    2) all.xml is provided by Microsoft with all of *their* configurations. I took all.xml and enabled every ROP mitigation for the applications listed there.

    Hence allrop.xml.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.