Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. puff-m-d

    puff-m-d Registered Member

    Joined:
    Feb 13, 2002
    Posts:
    5,703
    Location:
    North Carolina, USA
    Hello,

    For LibreOffice you only need one custom shield, add "soffice.bin". That will shield all for LibreOffice.
    HTH...
     
  2. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
    Is it advisable to shield MS Silverlight and if so how.
     
  3. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    For LibreOffice all you need to add is 1 custom shield for "soffice.bin". This will give coverage of all LibreOffice apps.

    Edit: oops just saw puff answered the question.
     
  4. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    It is automatically shielded, no need to add a custom shield.
     
  5. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    7,997
    Thank you. :thumb:
    -------
    @ Pedro,
    Will you add support (auto shield) for LO?
     
    Last edited: Sep 26, 2014
  6. G1111

    G1111 Registered Member

    Joined:
    May 11, 2005
    Posts:
    2,294
    Location:
    USA
    Okay, thanks Pedro.
     
  7. Questions

    1) Does MBAE protect flash player, even when IE protection is deactivated?

    2) I have added WWAHost.exe (browser) and Powershell.exe (other), seems to work without problems on Win 8.1. See explanation of WWAHost, any reason to omit this in the default list?

     
    Last edited by a moderator: Sep 27, 2014
  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    If IE shield is deactivated in MBAE, MBAE will still protect Flash under other browsers (Firefox, Chrome, etc.) but not Flash under IE.

    The IE-based Metro apps run differently than the regular IE. The criteria for adding new apps to the default shield list is based on it being (1) widely distributed and (2) subject to exploits. Clearly in this case it fits the first criteria but not the second. If we see that second criteria change due to new research, poc, etc in the future we will add it to the default shield. In the meantime as other users have reported you can create a custom shield for WWAHost.
     
  9. ance

    ance formerly: fmon

    Joined:
    May 5, 2013
    Posts:
    1,360
    When will it be fixed? :) Does Malwarebytes Anti-Exploit protect the plugin-container.exe of Firefox too?
     
  10. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    This thing looks like it's pretty much ready for me to add it to my arsenal, and I'm eager to do so... if only something could be done about this Sandboxie incompatibility.

    A real crying shame that is... because SBIE is such a beloved product. If something isn't done about this it will lose you out on a large chunk of a potential customer base. This should be priority #1 right now.
     
  11. WilliamP

    WilliamP Registered Member

    Joined:
    Jun 1, 2003
    Posts:
    2,208
    Location:
    Fayetteville, Ga
    I have been running both (SB and MAE) with no problems. I am using the latest SB 4.13.5
     
  12. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,094
    Location:
    Germany
    It's not that you cannot have both on your system but sandboxed apps won't be protected by MBAE.
     
  13. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    Zactly... which pretty much defeats the purpose. I should have been more specific.
     
  14. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    Depends on how you're using SBIE, I am using it on demand for example (not for browser protection), so I do not mind that MBAE can not protect processes inside the sandbox. Also, while SBIE can not stop exploits, it will at least be able to contain them. But it would be indeed nice if they could work together. :)
     
  15. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    Yes I can understand this, but the reason I asked was because I'm a bit surprised by their approach. From what I've read they do not try to stop memory overflow (corruption), but instead they came up with something else. It does make me wonder if this ""stateful application control" approach can be applied to any app on the fly, I highly doubt that this is the case. :)

    This is from the PDF file:

    "To prevent endpoint compromise, Trusteer Apex restricts ‘sensitive’ application operations: Trusteer Apex monitors the application state at the time the application executes sensitive operations, for example writing a file to the file system. Trusteer Apex uses a whitelist of legitimate application states to verify that the sensitive operation is executed under a known, legitimate state. An exploit will attempt to execute sensitive operations under an unknown (not whitelisted) state, thus it will be stopped. This unique approach allows Trusteer Apex to accurately detect and block both known and zero-day exploits, without knowing anything about the threat or the exploited vulnerability."
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    It is fixed already in the MBAE 1.05. We'll release it soon as Experimental version.

    Someone recently posted about a compatibility template for Sandboxie 3.x with MBAE. Of course unfortunately not 4.x:
    https://forums.malwarebytes.org/ind...choosing-between-sandboxie-and-mbae/?p=884176
     
  17. Ashanta

    Ashanta Registered Member

    Joined:
    Aug 21, 2007
    Posts:
    702
    Location:
    Europe
    I had some troubles with previous version of MBAE, 1.0.0.10 if I remember well. Some conflict with Firefox. I noticed when checking about:crashes that the module mbae.dll was causing this conflict with Firefox. I've not yet intalled the latest version, hope this can't occur with the latest release.
     
  18. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    MBAE Beta 0.10 expires today Oct 1, 2014. It is strongly recommended to uninstall and install the non-beta version from malwarebytes.org. Once you are on a non-beta version MBAE will auto-upgrade itself to newer versions as they become available.
     
  19. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    is Malwarebytes Anti-Exploit free program?
     
  20. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590

    No it isn't.
     
  21. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    There's MBAE Free which protects browsers, browser add-ons and Java in real-time.

    Then there's MBAE Premium which adds protection for MS Office, PDF Readers, media players and custom shields.

    Both Free and Premium have automatic upgrades to new versions.
     
  22. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,561
    Location:
    The Netherlands
    Can you turn this off? I hate it when apps auto-update. ;)
     
  23. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    It prompts you first. You can cancel it.
     
  24. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    thank you
     
  25. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    thank you
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.