Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. haakon

    haakon Guest

    1.05 is a cyber-ancient one year old. Are you saying the more mitigations you expect have not yet been included in 1.08?

    An assumption here would be you were not running any other product which might have prevented/alerted to the download. Yes, no?
     
  2. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    I only shared some observations I made back with Anti-Exploit 1.05.
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  4. haakon

    haakon Guest

    Understood. Likewise, whenever I reply to a suspension setting inquiry on a Supersport forum, I always relate experiences I had with my 1996 Suzuki 600. :D
     
  5. CHEFKOCH

    CHEFKOCH Registered Member

    Joined:
    Aug 29, 2014
    Posts:
    395
    Location:
    Swiss
    Today Cyberfox stopped working for me with protection enabled in AE 1.08.1.1045 on Win Ent LTSB N x64 (10586.63) after installing latest uBlock beta version with 0xc0000018. The crash stack says this is because Dynamic AntiHeap protection.

    An option to automatically submit such crashes would be nice.
     
  6. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Do you still receive the same problem after rebooting or going through a fresh re-install?
     
  7. CHEFKOCH

    CHEFKOCH Registered Member

    Joined:
    Aug 29, 2014
    Posts:
    395
    Location:
    Swiss
    Fresh install of Win/Cyberfox?
    I did not tried that (I wait until next uBlock update but I think it not have anything to do with that addon). But I restarted Windows and got the same problem, even more worse now because I disabled Cyberfox protection within the given AE list and re-enabled the Software but still got the problem. So I think it's Cyberfox fault or Windows (maybe because latest KB).
     
  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Fresh install of MBAE.
     
  9. CHEFKOCH

    CHEFKOCH Registered Member

    Joined:
    Aug 29, 2014
    Posts:
    395
    Location:
    Swiss
    Sadly it not helped me.

    Edit:
    What I also noticed that after a fresh installation (if Cyberfox is running) it also crashes the browser.
     
    Last edited: Jan 18, 2016
  10. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Can you post or PM me a FRST log?
     
  11. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,925
    either only for cyberfox or for 64bit. Firefox v44 x86 is performing well with MBAE in background. ublock origin 1.6.0beta3 <-- install update first
     
  12. CHEFKOCH

    CHEFKOCH Registered Member

    Joined:
    Aug 29, 2014
    Posts:
    395
    Location:
    Swiss
    Thank you Brummelchen & ZeroVulnLabs, the problem dissipated after another beta uBlock update today. I restarted Win and installed the update (stopped/started) the protection and now it works. Strange isn't it? Maybe I'm to fast and should wait for stable next time, my fault....

    However the only problem is that the Browser is crashing while you install MBAE which I reproduced on all my machines (VM and real). But I sent logs to possible solve that, not really an "big problem", just restart browser but I think the Dynamic AntiHeap protection is what Cyberox not like, I also submitted the log to the Cyberfox/Mozilla team.
     
  13. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,925
    i think that depends on plugins. but it did not happend here the last versions. and my download-plugin for dlm.
     
  14. liba

    liba Registered Member

    Joined:
    Jan 21, 2016
    Posts:
    344
    please release a new version!
     
  15. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
    Really liking the Premium version, it has pretty much everything covered already lol. Didn't have to add any custom shields, unless I wanted to be really "paranoid".

    Switched from HMP.Alert, and I actually find this faster and less buggy... For one, there is a longstanding issue of lack of whitelisting in that program and this doesn't seem to have it.
     
  16. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    Why, do you have a problem with the current one?
     
  17. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,009
    1.08.1.1045 / November 23, 2015
    1.07.1.1015 / July 24, 2015
    1.06.1.1019 / April 23, 2015
    1.06.1.1018 / March 31, 2015
    1.05.1.1014 / December 1, 2014
    1.04.1.1012 / September 4, 2014
    1.03.1.1220 / June 12, 2014
    https://www.malwarebytes.org/support/releasehistory/
     
  18. liba

    liba Registered Member

    Joined:
    Jan 21, 2016
    Posts:
    344
    malwarebytes-anti-exploit NOT FULLY PROTECTED

    Exploit Test Tool
    http://dl.surfright.nl/hmpalert-test.exe
     
    Last edited by a moderator: Jan 23, 2016
  19. guest

    guest Guest

    I would like to activate all the settings in the advanced protection section.
    The problem is, how do I know that when an app crash which is MBAE advanced setting X causing it?
    Could you add a feature to facilitate this? The idea would be to activate all the settings and then use the app crashes to lower them down.
     
  20. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    1. Do you even know how to test exploit mitigation software?
    2. Anti-Exploit will not automatically 'protect'/recognise the HMP.Alert test tool, you will have to add it manually to Anti-Exploit.
     
  21. liba

    liba Registered Member

    Joined:
    Jan 21, 2016
    Posts:
    344
    lol, i know this. are you using malwarebytes Anti-Exploit ?

    malwarebytes anti-exploit (latest version)

    (chrome + ie)
    ROP - WOW64 bypass > fail
    ROP - Exploit WOW64 > fail
    Heap Spray 1 > fail
    Heap Spray 3 > fail

    malwarebytes anti-exploit is totally crap
     
  22. ance

    ance formerly: fmon

    Joined:
    May 5, 2013
    Posts:
    1,359
    ... but it's still installed on my computer. :'(
     
  23. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    I use different configurations depending on my needs :)

    Every company has its own marketing strategy: SurfRight likes to compare HitmanPro.Alert to other anti-exploit tools by providing a test tool, Malwarebytes publishes a blog post about Anti-Exploit stopping Angler or Neutrino every two weeks, Microsoft simply says: EMET is great but can be bypassed and PaloAlto says: Traps is the best, but we don't allow anyone to test it.

    I only judge exploit mitigation software after running a set of custom test cases. running individual test cases provided by the HMPA test tool is a first step, but the tool does not simulate a multi-staged exploit with heap spray, info leak, ROP chain, shellcode execution, EoP and payload delivery.

    I also don't like to just bash on security software as it is unlikely that I can make a better solution in my spare time.
     
  24. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, it's quite silly to say that MBAE is crap, even though HMPA might be using a couple of more advanced anti-exploit techniques. And from what I've understood, the exploit test tool is indeed not enough to judge other apps when it comes to exploit blocking capabilities. I think both MBAE and HMPA are great tools.
     
  25. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    5,925
    4 of 6 postings and all what i read is whining, flaming and boring. if you dont like it - uninstall and dont bother us instead support.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.