Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    Indeed, and your signature shows 1044 as the latest build. :)
    Welcome back Pedro!
     
  2. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  3. Pliskin

    Pliskin Registered Member

    Joined:
    Feb 8, 2009
    Posts:
    440
  4. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    If it's anything like the original Duqu, even though it is a kernel exploit, MBAE would block the infection by blocking the payload in its Layer3 (Application Behavior). The best solution however remains to patch against this to prevent the exploit shellcode from running. Once they get shellcode to execute they pretty much have free reign over the system and can find a way to bypass any other security measures in place.
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  6. Last edited by a moderator: Dec 17, 2015
  7. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  9. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
    It doesn't matter whether a cat is white or black, as long as it catches mice.
     
  10. ance

    ance formerly: fmon

    Joined:
    May 5, 2013
    Posts:
    1,359
    But the signature cat is rather silly because tomorrow it can't catch a changed mouse. :D

    Is it possible to convert a Malwarebytes Antimalware licence to Malwarebytes Anti-Exploit? :geek:
     
  11. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,010
    I said: as long as it catches......
     
  12. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    I read too quickly, if the driver is signed it can still inject code into Edge, so of course security tools will have no problems, my bad.
     
  13. marzametal

    marzametal Registered Member

    Joined:
    Mar 19, 2014
    Posts:
    766
    I won a competition and scored myself MBAE Premium for a year.

    I have a question: do I need to go tick crazy on the boxes in Advanced Settings?

    Cheers in advance.
     
  14. haakon

    haakon Guest

    I did; all checked. And I've got 12 custom shields added, half of 'em Other.
     
  15. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    I have all boxes checked in Advanced Settings and added some shields mostly "MS Office" then "Browsers" and only 3 "Other".
     
  16. marzametal

    marzametal Registered Member

    Joined:
    Mar 19, 2014
    Posts:
    766
    Thanks for the replies... much appreciated. It's nice that a LUA account cannot touch the advanced settings. So far no issues to report. I think lists in MBAE will be replicated throughout other apps such as AppGuard and SpyShelter sandbox. All of a sudden, I am feeling less and less of a need to run Sandboxie as "real-time"; might switch it back to "on-demand".
     
  17. ozbadcat

    ozbadcat Registered Member

    Joined:
    Dec 31, 2015
    Posts:
    44
    Hi Guys .... can I please ask your opinions on the following - I have IE 9 on my computer and as most know updates will cease on Jan 12 for all versions of IE except IE 11 ..... my dilemma is whether I upgrade to IE 11 and risk BSOD/trashing presently faultless running computer or equally as bad unwantedly downloading the dreaded kb3035583/Win 10 upgrade ( which some others say IS included in the upgrade to IE 11 by default !!!! ) or go instead go Malwarebytes Anti-Exploit to FUTURE protect my IE from security issues ( I already have Malwarebytes AM premium installed - which I trust greatly )
     
  18. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
    I have no problems with IE11, but only use it occasionally (Windows 7). My main browser is Firefox. If you are set on keeping IE9 I would definitely consider an anti-exploit. I use MBAE premium and what's in my signature with no problems. Other options are Microsoft EMET, HitmanPro.alert and AppGuard.
     
  19. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    I would use MBAE no matter WHICH browser you are using.
     
  20. haakon

    haakon Guest

    For the supported browsers in MBAE Free, at least. Otherwise, MBAE Premium and add a Browser Shield as needed.
     
  21. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,935
  22. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
  23. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,935
    ok, so no exploit kit instead a manually triggered download? (or mail attachment)
     
  24. TheKid7

    TheKid7 Registered Member

    Joined:
    Jul 22, 2006
    Posts:
    3,576
    If you are using an out-of-date Sun Java Runtime (i.e., version 6 or 7), how effective is Malwarebytes Anti-Exploit at stopping Java Exploits?

    Thanks in Advance.
     
  25. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    With all exploits the answer is: "It depends"

    Here are some of my experiences when I tested the Java mitigation in Anti-Exploit 1.05:
    - Executables that are downloaded and executed by the applet itself will be blocked.
    - Access to cmd, PowerShell (and likely other programs like Wscript) is being blocked.

    Although Anti-Exploit should include more mitigations
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.