Security Flaw Fixed in Malwarebytes Antivirus

Discussion in 'other anti-virus software' started by Minimalist, Dec 10, 2015.

  1. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Yes it is getting signature updates but no product updates. If patch was delivered through signature updates it might be fixed.
     
  2. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Obviously, the bigwigs of Malwarebytes seem not to be aware aware of this thread here, in Wilders...absent by choice? Strange, that.
     
  3. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I can't seem to find the mbam thread here anymore.
     
  4. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
  5. jwcca

    jwcca Registered Member

    Joined:
    Dec 6, 2003
    Posts:
    772
    Location:
    Toronto
    If mbam.exe or one of it's dlls has code that examines the 'database update' stream and uses some of that data to 'patch' the executable(s) then the statement that MalwareBytes 'patched' the program is true.

    Because I'm an 'old guy', I was only aware of the 'old way' of downloading a small executable that contained the changes plus the code to apply the changes or patches to the main executables, although those also updated the version number of the program to show that the patch had been applied, which is why I was concerned when that number hadn't been changed.

    Wikipedia has a reasonable description of 'patches', I copied some of that as follows:

     
  6. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
  7. haakon

    haakon Guest

    2.2.0.1024 was released about mid-October.

    Consternation about a vulnerability with an "immediate fix" and details are nada? Um, yes. Well, for paying customers mostly. Free users can demand an apology. :rolleyes:
     
  8. haakon

    haakon Guest

    MBAM Premium Vulnerability Disclosure
    "In early November, a well-known and respected security researcher by the name of Tavis Ormandy alerted us to several security vulnerabilities in the consumer version of Malwarebytes Anti-Malware."
    • https://blog.malwarebytes.org/news/2016/02/malwarebytes-anti-malware-vulnerability-disclosure/
    "Consumers using the Premium version of Malwarebytes Anti-Malware should enable self-protection under settings to mitigate all of the reported vulnerabilities."

    It would be nice if they'd post up a method to determine if one's system has been compromised by any of the "all of the reported vulnerabilities."
     
    Last edited by a moderator: Feb 2, 2016
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
  10. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,008
    Enable self-protection module: This setting controls whether Malwarebytes Anti-Malware creates a safe zone to prevent malicious manipulation of the program and its components. Checking this box introduces a one-time delay as the self-protection module is enabled. While not a negative, the delay may be considered undesirable by some users. When unchecked, the "early start" option which follows is disabled.
    Enable self-protection early start: When the self-protection module is enabled, you may choose to enable or disable this option. When enabled, the self-protection module will become enabled earlier in the computer's boot process — essentially changing the order of services and drivers associated with your computer's startup.
    https://www.malwarebytes.org/support/guides/mbam/
     
  11. haakon

    haakon Guest

    Thanks for posting up a clickable link of the same italics emphasized URL I posted up. I often forget about the copy/paste challenged members in our midst. :D
     
  12. haakon

    haakon Guest

    More in the news...
    http://www.networkworld.com/article/3029071/malwarebytes-still-fixing-flaws-in-antivirus-software.html
    http://www.theregister.co.uk/2016/02/02/malwarebytes_0day/
     
  13. Minimalist

    Minimalist Registered Member

    Joined:
    Jan 6, 2014
    Posts:
    14,883
    Location:
    Slovenia, EU
    Malwarebytes Starts Bug Bounty Program Following Recent Security Bugs
    http://news.softpedia.com/news/malw...m-following-recent-security-bugs-499813.shtml

     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.