Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Yes, MBAE currently protects Flash, Shockwave, Silverlight, Java and any other browser add-on, plugin, etc.

    Yes, MBAE protects IE, Chrome, Firefox and Opera by default if installed on the computer (and if installed at a later date).
     
  2. siketa

    siketa Registered Member

    Q asked about browser variants...Dragon, Iron, Waterfox, etc. but as far as I remember you once said Not yet.
     
  3. Q Section

    Q Section Registered Member

    Thank you but the question is whether MBAE also recognizes and protects the browsers which are variants of Chrome and Firefox for example SRWare Iron, Pale Moon, Waterfox and Cyberfox all the while keeping in mind there may also be several of various versions of Chrome and Firefox installed on the same computer.

    Another good question is: suppose someone installed an addon for Firefox that was actually a security breach (as some are). Will MBAE detect this every time or does it assume all installed addons are safe since they have been installed in the browser?

    Lastly will MBAE protect the browsers if perchance some older versions of Flash or Java are installed on the computer/browser (along with the current versions as well)?

    Many users have older versions of Flash, Java and other addons that are out-of-date having been replaced by newer versions that have been patched because of security breaches found in the previous version.

    To summarize: Imagine one computer that has installed (before MBAE is installed) Chrome versions 22 & 35 wherein a few versions of Flash are also installed. That same computer also may have Firefox 3.1, 20 & 27.01 along with Waterfox and Dragon each with older and current versions of Java and Flash.

    Thank you and best regards
     
    Last edited: Mar 2, 2014
  4. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Sorry I misread. Currently MBAE only protects the main browsers mentioned earlier (IE, FF, Chrome & Opera). But we are currently implementing the ability for you to add any browser variants or other third-party applications that you wish. It will be ready in a couple of beta versions.

    Yes, any addons that run in the browser's process space are automatically protected by MBAE.


    Yes, MBAE is version-agnostic (as well as vulnerability-agnostic and payload-agnostic). If the addon is running within the browser process space it is automatically protected by MBAE.

    With the exception of the Waterfox and Dragon browsers (which you'll be able to protect in a couple of MBAE versions) the answer is yes, MBAE will protect all those up-to-date and outdated browsers and its up-to-date or outdated addons.
     
  5. Q Section

    Q Section Registered Member

    How about malicious addons? How are they treated? Let us say they are installed in the browser before the first use of MBAE.
     
  6. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Depends on what the malicious addon does. If it inserts an iframe to every page which points to an exploit kit, then MBAE would block the exploit from ever running. But if the malicious addon does something different like keylogging for example, then it is outside of the scope of MBAE. I suggest reading the MBAE FAQs for a more in-depth discussion of what MBAE is and is not:
    https://forums.malwarebytes.org/index.php?showtopic=136424
     
  7. Sampei Nihira

    Sampei Nihira Registered Member

  8. guest

    guest Guest

  9. Sampei Nihira

    Sampei Nihira Registered Member

    :thumb: ;)
     
  10. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    No worries, everyone who helped out during the MBAE beta reporting/reproducing bugs either here or in the Malwarebytes forum will receive a license key. No limit on the number.
     
  11. Sampei Nihira

    Sampei Nihira Registered Member

  12. Hungry Man

    Hungry Man Registered Member

    For what it's worth, EMET does implement stage 2 mitigation techniques (anti-ROP). In case you want to update your FAQ. It does not implement stage 3 techniques.
     
  13. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Good point, fixed. Thanks.
     
  14. 93036

    93036 Registered Member

    Looking forward to using this again. I uninstalled it so that I could try out EMET, but it configuration setup can be a challenge.
     
  15. Tested latest version (0.10), less delay in protected programs startup (as 0.09), still mail programs missing (for business environment outlook is also a threatgate, when will this be protected also) :'(
     
  16. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Yes, email clients is in the backlog as well.
     
  17. Rasheed187

    Rasheed187 Registered Member

    @ ZeroVulnLabs

    I've sent you a PM, about the new version. ;)
     
  18. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Yes, it will be released very soon.
     
  19. Rasheed187

    Rasheed187 Registered Member

    Well, that was not really the question. :D

    But nice to hear, I would really like to test it. :)

    Can you perhaps post some screenshots?
     
  20. Drew99GT

    Drew99GT Registered Member

    What will be the difference between the free and paid versions of MBAE?
     
  21. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    GUI of the upcoming 0.10 version is practically the same as the 0.09.

    As for what the free vs paid version will have, we're not ready to say this yet. You'll be able to see it once we release a beta version of it (with the new GUI).
     
  22. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

  23. Solarlynx

    Solarlynx Registered Member

    The new 0.10.0.1000 version runs smooth so far.

    Why mbae-svc.exe goes into the Internet?
     
  24. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

  25. 800ster

    800ster Registered Member

    Looks good, installed and working fine for me so far. Nothing visibly different from the previous version...... the "Shielded Applications" counter still seems acts like a random number generator!
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice