Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    I would imagine that bypasses MBAE would be a lot easier on XP, given the static addresses everywhere.

    Assuming their techniques are similar to EMET's EAF or Anti-ROP, all of which are not exactly difficult to get around, especially when you know the addresses of everything.
     
  2. luciddream

    luciddream Registered Member

    Joined:
    Mar 22, 2007
    Posts:
    2,545
    I agree HungryMan... in fact I think that's obvious. But just saying if people are going to stick with XP regardless, having it is better than not having it. Even I, a major XP otaku that's been very outspoken about it on this site, recommends upgrading when official support ends for it. But some won't. And I think having this would be better than having a dated/vulnerable version of .NET FW on their machines to run an also dated version of EMET. Less vulnerable attack surface and a product that's continuing to be updated, assuming support for XP will continue with MBAE for awhile.
     
  3. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Yes, that will continue.
     
  4. THESAWISFAMILY2005

    THESAWISFAMILY2005 Registered Member

    Joined:
    Aug 10, 2012
    Posts:
    198
    Location:
    SACRAMENTO CALIFORNIA
    what exactly does this program do?
     
  5. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  6. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    For the first time, MBAE does not cause freezes in Chrome for me. As of the latest beta 0.09.5.0250 everything is working smoothly. At least, so far! :thumb:
     
  7. molhopicante

    molhopicante Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    135
    I'm using HitmanPro Alert and MBAM Real Time.

    Do i need Malwarebytes Anti-Exploit?
     
  8. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    MBAM does not include MBAE and HMPA is post-infection only, so yes, you do need MBAE.
     
  9. VXB

    VXB Registered Member

    Joined:
    Oct 2, 2010
    Posts:
    18
    What is the differences/advantages between MAE and EMET?
     
  10. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Last edited: Jan 3, 2014
  11. ance

    ance formerly: fmon

    Joined:
    May 5, 2013
    Posts:
    1,359
    Great support pbust. :thumb:
     
  12. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    EMET stops exploits at stage 1 only, MBAE does it at stage 2 as well.
    You need tune EMET, MBAE does everything itself.
     
  13. Dragon1952

    Dragon1952 Registered Member

    Joined:
    Sep 16, 2012
    Posts:
    2,470
    Location:
    Hollow Earth - Telos
    I installed the last MBAE in the same folder as the one before it. Could that be why some Chrome Extensions were frozen sometimes.
     
  14. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    We have detected a problem under some circumstances with MBAE 0.09.5.0250. We've fixed it already in a .0300 build and people are reporting it fixes the problem correctly. PM me with your email address and I'll send it to you.
     
  15. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    You're right, thanks for pointing that out. I'll fix my previous post.

    Correct, EMET is not necessary if running MBAE, at least not since we added a lot of stage1 protections.
     
  17. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA
    What's the ram usage currently?
     
  18. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,295
    I had the missing icon problem, so I killed the mbae.exe and restarted from MBAE desktop icon.

    ScreenShot_MBAE_missing icon_01.gif

    But, then I noticed it was showing 'Shielded applications:' 0 , so I stopped MBAE, and restarted again using the radio button.

    ScreenShot_MBAE_missing icon_02.gif

    So, I am not sure whether that was normal, or not.
     
  19. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    It shows the currently running shielded applications.
    If none are running, then it shows 0.
     
  20. fblais

    fblais Registered Member

    Joined:
    Jul 31, 2008
    Posts:
    1,341
    Location:
    Québec, Canada
    I presently see 704KB (yes, kilobytes!) Working Set memory.
     
  21. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    EMET will be not necessary if a user can add any applications under MBAE protection, like in EMET.
     
  22. KaptainBug

    KaptainBug Registered Member

    Joined:
    Dec 26, 2013
    Posts:
    480
    True. I don't use adobe reader or microsoft office. In that case, only protection MBAE can provide is for firefox, flash and media player. So I am happy with EMET for now.
     
  23. humble3d

    humble3d Registered Member

    Joined:
    Jan 31, 2003
    Posts:
    12
    Many thanks to everyone for all you do to keep us safe... :)
     
  24. That's the fine line between a vulnerability and an exploit (an exploitable vulnerability has access to predictable memory addresses in the wild to change the flow of events and execute arbitrary code). So you are basically saying it is easy to exploit when you have an exploit. Yes water is wet most of the time. Come on you are studying IT and have mastered the principles of programming, you can do better :p
     
    Last edited by a moderator: Jan 4, 2014
  25. Overkill

    Overkill Registered Member

    Joined:
    Mar 16, 2012
    Posts:
    2,343
    Location:
    USA

    WOW! That's great, thanks:thumb:

    Is it pretty stable currently? Can I run it with my current setup?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.