WSA and EMET 4.0 Compatibility Issues

Discussion in 'Prevx Releases' started by ambient_88, Apr 20, 2013.

Thread Status:
Not open for further replies.
  1. ambient_88

    ambient_88 Registered Member

    Joined:
    Jun 23, 2008
    Posts:
    854
    Hello,

    I believe that WSA and EMET 4.0 have compatibility issues related to the Identity Shield. If I enable the ID shield, Google Chrome won't even start (crashes at startup). If I have ID shield disabled, then it runs just fine.

    Joe, can you please look into this issue? I wouldn't really want to choose one over the other if possible.


    Thanks.
     
  2. guest

    guest Guest

    EMET 4 is in beta, with many incompatibilities, so i will wait before implementing it and i will just keep WSA as it is now.
     
  3. ambient_88

    ambient_88 Registered Member

    Joined:
    Jun 23, 2008
    Posts:
    854
    You do have a point. I guess there's no use fixing the incompatibilities for now since EMET can change a great deal from now until the final release.

    Thanks for the reply anyway.
     
  4. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    emet.dll from EMET v4 is being blocked in the browser by Identity Shield, perhaps that explains the crashes?
     
  5. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    That sounds like the browser addon isolation - could you try changing just the DLL to allow and see if it works?

    Thanks!
     
  6. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    That seems to fix it.
    If this can be fixed from the cloud, here is the line from the scan log:
    c:\windows\apppatch\emet.dll [MD5: A1C42183DF570B83952DCABC62F6B685] [Flags: 00081000.9623]
     
  7. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    EMET 4.0 final has been released, with Deep Hooks turned on and ID shield turned on, some browsers will crash. If either of them is turned off they don't crash, so it seems the compatibility issue is between Deep Hooks option and ID shield. Here is more info on Deep Hooks from the manual:
    Also, when ID shield is enabled, EMET's Banned Functions don't seem to work:
     
  8. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    Thanks for the heads up - I'll see what we can do to work around this.
     
  9. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Nice :)
     
  10. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Hi, is there any news on this issue?
     
  11. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    It seems the issue still persists in v8.0.4.12
     
  12. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    That's correct, we have not been able to correct this yet but it is still on the list.
     
  13. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Thanks, I hope it can be fixed soon.
     
  14. PrevxHelp

    PrevxHelp Former Prevx Moderator

    Joined:
    Sep 14, 2008
    Posts:
    8,242
    Location:
    USA/UK
    FYI - this should be fixed in the next build. Thanks!
     
  15. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,873
    Location:
    Outer space
    Very nice, thanks :)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.