Security software can reduce effectiveness of DEP/ASLR

Discussion in 'other security issues & news' started by MrBrian, Sep 5, 2011.

Thread Status:
Not open for further replies.
  1. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    You can apply SEHOP per application in XP. You just won't have it system wide.
     
  2. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    Yes, I know, if you look at the link I referenced in my post above there is an image about a third of the way down that clearly indicates this.;)

    Thanks! :)

    P.S. I see you already posted that link > here earlier. ;)

    Edit: added P.S.
     
    Last edited: Sep 11, 2011
  3. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Yes indeed, after installing the 64bit java I installed the 64bit flash beta and had them use the 64bit version of IE.

    I will keep that msi trick in mind next time.
     
  4. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Ah, I see.

    Ie IE9's Javascript engine 64bit yet?
     
  5. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    No, maybe with IE10. But the person I did it for wouldn't care about 500ms extra js processing time.
     
  6. Konata Izumi

    Konata Izumi Registered Member

    Joined:
    Nov 23, 2008
    Posts:
    1,557
    Here is a .bat file to set most windows files in EMET protected applications.
    I found this batch file on some old thread here in wilders. (i updated the commands -add changed to -set)

    I havent experience crashes while using this.

    change .txt to .bat (don't forget to run as admin and reboot after applying)
     

    Attached Files:

  7. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Found out Daemon Tools Lite has DEP and ASLR enabled for its exes and ASLR for its dlls.
     
  8. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Who knows if in a near future Virtual Clone Drive supports it. ;)
     
  9. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    -edit-

    On the other hand, Spybot team still hasn't replied to my thread asking about ASLR support. I wonder if it would take them that long to provide an upgrade to the current stable Spybot version? Maybe yes, maybe no...
     
  10. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    It would only benefit them.

    Probably no, because they are probably too lazy and its probably low priority, who knows :D
     
  11. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Did a scan of Online Armor 5.1 with Attack Surface Analyzer. Can download the report at the link below.

    -http://www.megaupload.com/?d=UMXUNWCI-
     
    Last edited: Sep 21, 2011
  12. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Noticed this in Emsisoft Anti-Malware 6.0.0.33 changelog:

    Feature #2448: Updates the context menu extension to no longer disable ASLR for processes it is loaded into.
     
  13. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    That's pretty funny to be honest. Good thing I have no need for such 3rd party software.
     
  14. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    I fail to see whats funny about it. I posted this as it was related to the discussion in this thread regardless if a person uses the software or not.
     
    Last edited: Sep 21, 2011
  15. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    A context menu entry.... disabling ASLR... it's hilarious. You know what a context menu entry is right?
     
  16. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Are you serious of course know what a context menu entry is. I still don't see what's funny or hilarious about it. That was a silly question to ask me.
     
    Last edited: Sep 21, 2011
  17. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    I would say that it is very nearly so ridiculous that it's to the point of humor.
     
  18. wat0114

    wat0114 Guest

    ...as opposed to entry ;)
     
  19. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    I just gave a quick run to the latest Spybot 2.0 beta version, and for what I could see it does not support ASLR either. Isn't Spybot team aware of ASLR, at all?
     
  20. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Apparently not. And its not a priority it seems.
     
  21. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    I still haven't tested it out (to see why I disliked it in the past), but I did download PowerArchiver and WinZip (both paid products), and only WinZip supports ASLR.

    Both have pleasant GUIs, though. Not all is lost. :D
     
  22. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    I asked Tzuk to enable ASLR.
     
  23. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    Hahaha. Well at least you found another archiver that supports ASLR. :D
     
  24. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Unfortunately, I may have seen what wasn't there. I was retesting Winzip moments ago, and while looking at Process Explorer, there was no ASLR.

    I think I confused it with some other application offering ASLR, while looking at PE back then.

    Sorry about it. :(
     
  25. 1chaoticadult

    1chaoticadult Registered Member

    Joined:
    Oct 28, 2010
    Posts:
    2,342
    Location:
    USA
    No problem m00n , it happens.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.