Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. Darvid Koak

    Darvid Koak Registered Member

    Joined:
    Oct 28, 2015
    Posts:
    3
    I can't find a working link to 1.08.1.1043.
     
  2. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
  3. Darvid Koak

    Darvid Koak Registered Member

    Joined:
    Oct 28, 2015
    Posts:
    3
  4. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,934
    Location:
    North of the 38th parallel.
    Last edited: Oct 30, 2015
  5. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
  6. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,934
    Location:
    North of the 38th parallel.
    Hello bjm_:

    That is what I use too. Just remember to include the below configuration file entries also.

    [GlobalSettings]

    Template=MBAE
     
  7. Buddel

    Buddel Registered Member

    Joined:
    Apr 28, 2015
    Posts:
    1,942
    The latest RC (1044) is running smoothly on my machine (Win10 32-build). Thanks, Pedro.
     
  8. atunis5804

    atunis5804 Registered Member

    Joined:
    Jan 17, 2015
    Posts:
    43
    I have had problems with MB anti-exploit on my windows 10 64bit PC. Is there a 64bit version available?
     
  9. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Thanks....I've been following this Thread for sometime, reluctant to trial MBAE because Sandboxie does not have default MBAE Template / Compatibility.
     
  10. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  11. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    @ZeroVulnLabs the beta build is 1044, though your footnote reads 1040.
     
  12. 1PW

    1PW Registered Member

    Joined:
    Apr 2, 2010
    Posts:
    1,934
    Location:
    North of the 38th parallel.
    Perhaps an integral MBAE template will eventually be included in a future SBIE.

    Can't you imagine this is exactly what Ronen Tzur (SBIE's original author) had in mind when the editable SBIE configuration feature was included?

    In the meantime, the immense protection benefits of MBAE should be permitted to overcome your understandable cautiousness.

    Cheers bjm_
     
    Last edited: Oct 31, 2015
  13. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Sure, I can believe. My belief however does equate to the required skill set to create [Template_Local_MBAE].

    Before hmpalert template was added by Sandboxie.
    Surfright offered the OpenPipePath to satisfy Sandboxie.

    Why are Sandboxie shields discussed.
    Are there exploit kits aimed at Sandboxie processes.
    Thanks
     
    Last edited: Oct 31, 2015
  14. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    Upgraded from build 1043 to 1044. I will report back if I experience any problems. I'm using Windows 7X64 Ultimate.
     
  15. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,005
    From 1.08.1.1043 to 1.08.1.1044 on Windows 10 Pro x64.
    No problems so far.

     
  16. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Yes, but in a different way than to be expected. Some exploits are sandbox and VM aware and will not run if they detect either one.
     
    Last edited: Nov 1, 2015
  17. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    Yeah, maybe that's why HMP.A has sandbox-aware malware vaccination.
     
  18. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    I'd be careful with that. Some malware when detecting the presence of a VM go berserk and destroy the system just to screw with researchers. A sandbox-aware malware vaccination approach might play against the user with some malware.
     
  19. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,457
    Location:
    .
    I'll be careful. I'm waiting with anticipation to read Wilders members post they've had real (running machine as normal) exploits thwarted by MBAE or Alert. I chose Alert for ease of Sandboxie compatibility. I've not heard Wilders members post running machine as everyday and had sandbox-aware malware vaccination event.
    Regards
     
  20. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,005
    Malwarebytes Anti-Exploit Premium 1.08.1.1044 stable / November 4, 2015
    https://forums.malwarebytes.org/ind...tes-anti-exploit-history-updates/#entry999707

    ------------------------------------------------------------------------------

    https://www.malwarebytes.org/support/releasehistory/
    New Features
    • Added Layer0 Dynamic Anti-HeapSpraying mitigation
    • Added Layer0 Anti-Exploit fingerprinting mitigation
    • Added Layer0 finetuned VBScript mitigation for IE
    • Added Layer1 ROP-RET gadget detection mitigation
    • Added Layer3 Application Behavior rules
    • Added protection for Microsoft Edge
    • Added protection for LibreOffice
    • Added failover upgrade mechanism
    • Added auto-recovery for Anti-Exploit service

    Fixes
    • Fixed conflict with third-party products that use the same hooks
    • Fixed conflict with Office family profile
    • Fixed conflict with banking software plugin for browsers
    • Fixed conflict with Citrix when opening IE
    • Fixed conflict with components from Asus and Huawei
    • Fixed conflict with Kaspersky 16
    • Fixed conflict with Comodo
    • Fixed conflict with Imprivata OneSign
    • Fixed issue when custom shields were not kept after upgrade
    • Fixed issue with exclusions sometimes not applied to PDF profile
    • Fixed issue with Layer3 Application Behavior
    • Fixed issue with missing balloon notifications
    • Fixed issue with missing balloon notifications
    • Fixed false positive with Adobe Acrobat
    • Fixed false positive with certain .NET modules under IE
    • Fixed PhantomPDF crash when converting to doc
    .
     
    Last edited: Nov 5, 2015
  21. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,240
    Location:
    Among the gum trees
    With all due respect, it is a risk I'm willing to take. I would rather know my machine is infected than have undiagnosed malware running on my machine, even if that means having a 'broken' computer - something which can easily be remedied if you do regular image backups.
     
  22. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  23. kdcdq

    kdcdq Registered Member

    Joined:
    Apr 19, 2002
    Posts:
    815
    Location:
    A Non-Sh*thole State
    After installing MBAE 1.08 on one of my systems, I started getting an exploit blocked message for IE or one of its' add-ons. Going back to the previous 1.07 stopped the problem.

    So now I am wondering if 1.08 has a new bug in it, OR the new version is now identifying an exploit not caught by 1.07. :confused:
     
  24. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
  25. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,899
    Location:
    localhost
    no, identical. just that the post does not mention the full ver. number :)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.