Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. fblais

    fblais Registered Member

    Indeed, and your signature shows 1044 as the latest build. :)
    Welcome back Pedro!
     
  2. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

  3. Pliskin

    Pliskin Registered Member

  4. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    If it's anything like the original Duqu, even though it is a kernel exploit, MBAE would block the infection by blocking the payload in its Layer3 (Application Behavior). The best solution however remains to patch against this to prevent the exploit shellcode from running. Once they get shellcode to execute they pretty much have free reign over the system and can find a way to bypass any other security measures in place.
     
  5. Rasheed187

    Rasheed187 Registered Member

  6. Last edited by a moderator: Dec 17, 2015
  7. anon

    anon Registered Member

  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

  9. anon

    anon Registered Member

    It doesn't matter whether a cat is white or black, as long as it catches mice.
     
  10. ance

    ance formerly: fmon

    But the signature cat is rather silly because tomorrow it can't catch a changed mouse. :D

    Is it possible to convert a Malwarebytes Antimalware licence to Malwarebytes Anti-Exploit? :geek:
     
  11. anon

    anon Registered Member

    I said: as long as it catches......
     
  12. Rasheed187

    Rasheed187 Registered Member

    I read too quickly, if the driver is signed it can still inject code into Edge, so of course security tools will have no problems, my bad.
     
  13. marzametal

    marzametal Registered Member

    I won a competition and scored myself MBAE Premium for a year.

    I have a question: do I need to go tick crazy on the boxes in Advanced Settings?

    Cheers in advance.
     
  14. haakon

    haakon Guest

    I did; all checked. And I've got 12 custom shields added, half of 'em Other.
     
  15. Solarlynx

    Solarlynx Registered Member

    I have all boxes checked in Advanced Settings and added some shields mostly "MS Office" then "Browsers" and only 3 "Other".
     
  16. marzametal

    marzametal Registered Member

    Thanks for the replies... much appreciated. It's nice that a LUA account cannot touch the advanced settings. So far no issues to report. I think lists in MBAE will be replicated throughout other apps such as AppGuard and SpyShelter sandbox. All of a sudden, I am feeling less and less of a need to run Sandboxie as "real-time"; might switch it back to "on-demand".
     
  17. ozbadcat

    ozbadcat Registered Member

    Hi Guys .... can I please ask your opinions on the following - I have IE 9 on my computer and as most know updates will cease on Jan 12 for all versions of IE except IE 11 ..... my dilemma is whether I upgrade to IE 11 and risk BSOD/trashing presently faultless running computer or equally as bad unwantedly downloading the dreaded kb3035583/Win 10 upgrade ( which some others say IS included in the upgrade to IE 11 by default !!!! ) or go instead go Malwarebytes Anti-Exploit to FUTURE protect my IE from security issues ( I already have Malwarebytes AM premium installed - which I trust greatly )
     
  18. G1111

    G1111 Registered Member

    I have no problems with IE11, but only use it occasionally (Windows 7). My main browser is Firefox. If you are set on keeping IE9 I would definitely consider an anti-exploit. I use MBAE premium and what's in my signature with no problems. Other options are Microsoft EMET, HitmanPro.alert and AppGuard.
     
  19. bellgamin

    bellgamin Registered Member

    I would use MBAE no matter WHICH browser you are using.
     
  20. haakon

    haakon Guest

    For the supported browsers in MBAE Free, at least. Otherwise, MBAE Premium and add a Browser Shield as needed.
     
  21. Brummelchen

    Brummelchen Registered Member

  22. ropchain

    ropchain Registered Member

  23. Brummelchen

    Brummelchen Registered Member

    ok, so no exploit kit instead a manually triggered download? (or mail attachment)
     
  24. TheKid7

    TheKid7 Registered Member

    If you are using an out-of-date Sun Java Runtime (i.e., version 6 or 7), how effective is Malwarebytes Anti-Exploit at stopping Java Exploits?

    Thanks in Advance.
     
  25. ropchain

    ropchain Registered Member

    With all exploits the answer is: "It depends"

    Here are some of my experiences when I tested the Java mitigation in Anti-Exploit 1.05:
    - Executables that are downloaded and executed by the applet itself will be blocked.
    - Access to cmd, PowerShell (and likely other programs like Wscript) is being blocked.

    Although Anti-Exploit should include more mitigations
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice