EMET (Enhanced Mitigation Experience Toolkit)

Discussion in 'other anti-malware software' started by luciddream, Apr 1, 2013.

  1. Quitch

    Quitch Registered Member

    Joined:
    Apr 24, 2008
    Posts:
    94
    You should use the most secure settings your system works with.
     
  2. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Were you able to successfully pin the websites? I tried to pin a website, but it didn't stick? o_O I don't see it in EMET's GUI. I'd imagine that if it worked, it would be shown there. :argh:

    I followed a Microsoft blog article explaining how one should pin, but didn't seem to work. :ouch:
     
  3. Sequence, first create a pinning rule, next add the website and assign it a pinning rule. I use three banks ING, RABO and OHRA, rabo and ohra had the same certificate path, so I combined it to the rabo_ohra rule, see picture
     

    Attached Files:

  4. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Oh, I made confusion. I first added the domain, then the pinning rule. :D This time it stick.

    Anyway, I'd prefer a similar method to the one Chromium uses. That way we wouldn't have to install certificates. Or, at least, a more automatic method that would do it in our behalf; it would download the certificate and pin it to the specified domain.

    I just need to figure out Chromium's way first. :argh: :D


    Thanks! :thumb:
     
  5. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,644
    Location:
    USA
    Depends on your 3rd party software but I am running 64 bit Windows 8 with EMET set on Maximum and no issues so far.
     
  6. Okay, here is how to do it in Chrome/Chromium, enter this text and follow explanation on picture

    chrome://net-internals/#hsts

    Don;t forget to use the --hsts-host command switch when starting Chrome
     

    Attached Files:

  7. guest

    guest Guest

    What is this for? to check if it's working?

    And what it's the point of this EMET? if you enter to this domain and the cert is not the same EMET will block the website?
     
  8. @ MODS,

    Please, move post #134 of Boerenkoolmetworst (how to add Chrome to certificate pinning feature of EMET, which is enabled for IE by default)

    and post #153 (how to add certificate pinning in EMET) and #156 (how to add a domain to chrome's hsts set)

    To CISCODISCO's thread "Ms EMET Certificatre Pinning)

    Thanks
     
  9. You are right confusing, asked mods to move it to another thread. I like to use what is allready available in stead of installing software, sort of security minimalist with maximum protection :D
     
  10. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    I'm afraid that's not how it works. First, the chrome://net-internals/#hsts only works for the browser session. That's the intended design. Second, the command flag --hsts-hosts seems to no longer exist? o_O :argh: :eek: :D

    Check here:
    -http://peter.sh/experiments/chromium-command-line-switches/
    and here: -https://src.chromium.org/svn/trunk/src/chrome/common/chrome_switches.cc

    Freakish moment. :ouch:
     
  11. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    Since this is a new version, I was a bit lost in comparison to previous versions of EMET. I've selected Maximum protection as well, thanks for the tip.

    Everything is working great so far :thumb:
     
  12. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    I like its new feature that you can "Configure Process..." via the "Running Processes" pane.
     
  13. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    There are some skins even there. Somehow dull they are.
     
  14. TheWindBringeth

    TheWindBringeth Registered Member

    Joined:
    Feb 29, 2012
    Posts:
    2,171
    Has anyone seen EMET 4.0 phoning home anything? I haven't, I'm just asking, thanks.
     
  15. Dwarden

    Dwarden Registered Member

    Joined:
    Apr 11, 2003
    Posts:
    177
    Location:
    Czech Republic
    they need really online database of rules for various apps and theirs versions ...

    unfortunately my old compatibility list of v3 and v3.5 is gone ...

    so writing new one is going to be PITA :)
     
  16. Creer

    Creer Registered Member

    Joined:
    Jun 29, 2008
    Posts:
    1,345
    Had the same situation it only needs some extra time to fix it.
     
  17. Tyrizian

    Tyrizian Registered Member

    Joined:
    Apr 26, 2012
    Posts:
    2,839
    I'm really digging this new version, definitely a keeper :thumb:
     
  18. Quitch

    Quitch Registered Member

    Joined:
    Apr 24, 2008
    Posts:
    94
    I really don't understand why it has skins at all. Especially irritating is that it doesn't have the option to just use the damn look of the system!
     
  19. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,644
    Location:
    USA
    Agreed. Not liking the skins and it would be nice if it just had the native OS look as an option. The dark skin looks nice but is difficult to read. :doubt:
     
  20. CrusherW9

    CrusherW9 Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    517
    Location:
    United States
    Isn't the default skin a Windows 8 kind of look? Also, there is a skin that looks like a Windows 7 style skin. I don't remember what it's called but it's in there.
     
  21. Quitch

    Quitch Registered Member

    Joined:
    Apr 24, 2008
    Posts:
    94
    No, it's the Office 2013 look, there is no Windows 8 look because that'd be called "No skin".

    The Windows 7 skin matches Windows 7 basic. Note that the minimise, maximise and close icons are wrong for Windows 8.
     
  22. CrusherW9

    CrusherW9 Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    517
    Location:
    United States
    Oh, I haven't used Office 2013 so that's why I didn't know the difference. I saw the Windows 7 one and then the dark one. The dark one won hands down :D Haven't spent any time with the Windows 7 one to notice.
     
  23. co22

    co22 Registered Member

    Joined:
    Nov 22, 2011
    Posts:
    411
    Location:
    router
    related to theme,in xp
    they forgot cover theme on right click menu on systray icon of EMET
    and Also when open main window in running processes section when right click
    and select configure process... its not covered by theme
    and still menu is like office 2003
     
  24. ance

    ance formerly: fmon

    Joined:
    May 5, 2013
    Posts:
    1,359
    Are skins really necessary for a security application? :D Do you protect your office applications too? :doubt:
     
  25. Creer

    Creer Registered Member

    Joined:
    Jun 29, 2008
    Posts:
    1,345
    For the regular Joe skins make big difference in terms of user experience, for IT folks command line would be enough ;)
    MS probably wants invite/encourage to use EMET more people which is good :thumb:
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.