EMET (Enhanced Mitigation Experience Toolkit)

Discussion in 'other anti-malware software' started by luciddream, Apr 1, 2013.

  1. trparky

    trparky Registered Member

    Joined:
    Feb 23, 2003
    Posts:
    29
    trparky here, the same trparky that WildByDesign introduced.

    Anyways, the program I wrote scans the registry to remove obsolete files from EMET and then scans for Flash-related executable files (FlashPlayerApp, FlashUtil, etc.) and adds them to EMET. Simple, easy, and quick to use. What may take several minutes to do by hand can be done by the program in less than ten seconds.
     
  2. guest

    guest Guest

    I performed some limited testing using an old vulnerability in Flash Player.

    Windows XP with Flash Player 12.0.0.44 + EMET 4.1:
    - iexplore.exe configured in EMET: blocked (stack pivot)
    - plugin-container.exe configured in EMET: blocked (stack pivot)
     
    Last edited by a moderator: Feb 6, 2015
  3. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Thank you for taking your time to do these tests and for sharing the results, it's definitely appreciated.
     
  4. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    What does FlashPlayerApp.exe do? I've never seen it running before while browsing on Flash enabled sites.
    EDIT: Just ran it to find out, it is the Flash settings manager, so it seems unnecessary to add it to EMET.
     
  5. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    The standalone version of Flashplayer uses FlashplayerApp.exe.

    -EDIT-

    For starters, FlashplayerApp.exe has been historically the prime infection vector for malware. Next, if you use the FlashPlayer control panel to check for updates, this app is what is used. It also spawns your default browser to connect to the Adobe update web site.

    FlashPlayerApp_Spawn.png
     
    Last edited: Feb 7, 2015
  6. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  7. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
  8. taytong888

    taytong888 Registered Member

    Joined:
    Mar 26, 2006
    Posts:
    168
    Had to clear "Simulated Execution Flow" check box, in order to be able to open Internet Explorer IE11 (iexplore.exe) which I just updated today.
     
  9. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I just installed EMET 5.2 on Windows 7X64 Ultimate to give her a try. I used the recommended settings, and so far I had to remove EAF mitigation from IE, javaw.exe, javaws.exe, and AcroRd32.exe. I manually added Firefox, and I also had to remove EAF mitigation. Is anyone else seeing the same behavior? I wonder if another security product i'm using could be triggering EAF mitigation. Online Armor injects into all these processes. I left the mitigations unchecked that were unchecked by default. The mitigations unchecked by default were mostly EAF +, ASR, and Heapspray as you can see in the screenshot below.
     

    Attached Files:

  10. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I'm going to try adding some of the mitigations unchecked by default with recommended settings, and see what happens.
     
  11. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    I can no longer run IE11 on 8.1 regardless of settings used...:(
     
  12. reldel

    reldel Registered Member

    Joined:
    Aug 14, 2007
    Posts:
    27
    Location:
    Felton, DE, USA
    Same here, using IE11, 64bit browser with Enhanced Protective Mode activated. IE just crashes using EMET recommended settings, tried unchecking EAF+, ASLR, no success. Had to uninstall and go back to 5.1 on Windows 8.1. Also NOD32 installed.
     
  13. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    txs a lot for the report, i've just sent a mail to the support.
     
  14. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    That was my experience when testing EMET on Windows 7 previously, having to disable EAF for Firefox and possibly a few other programs. Although with Windows 8.x and Windows 10, I haven't had to disable any mitigations. Windows 7 seemed to be a bit picky with EMET and certain programs.
     
  15. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    Kudos to GreenCat on MS Connect Portal, the culprit is related to certificate trust (pinning).

    Disabling this feature, IE 11 (on 8.1) works as expected...
     
  16. reldel

    reldel Registered Member

    Joined:
    Aug 14, 2007
    Posts:
    27
    Location:
    Felton, DE, USA
    Thanks, I'll give it a go.
     
  17. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Anyone try EMET 5.2 on WIN 7 x64, IE10, and cert. pinning enabled? Is IE10 also crashing?
     
  18. clubhouse1

    clubhouse1 Registered Member

    Joined:
    Sep 26, 2013
    Posts:
    1,124
    Location:
    UK
  19. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Running great here on WIN 7 x64, SP1 and IE10.

    Installed over 5.1. I did export my app and cert. settings from 5.1 and imported them to 5.2. I have protection settings set to maximum i.e. DEP always on. Also EPM set on in IE10. And I do have a number of web sites pinned. Just browsed to one and connected fine.
     
  20. guest

    guest Guest

  21. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Running w/Windows 7 Home Premium x64.

    Internet Explorer 11 w/All the latest updates. With IE Enhanced Protected Mode enabled. Using the 64bit IE 11.


    Using just the one EMET Application rule for IE which applies to both 32bit and 64bit IE executable files. All the Mitigations are set and worked flawlessly using EMET 5.1 and seems to be working flawlessly now with EMET 5.2. However after testing a little then I remove jp2iexp.dll from IE ASR modules list to run java scripts.


    In addition; like with EMET 5.1 I also enable all the Mitigations except for the ASR on all the java components.


    I thus far never experienced any problems.



    Using TorBrowser the Firefox can't be set with 'ROP Simulate Execution Flow', only problem I've encountered thus far.


    Kind Regards,
    Phant0m``.
     
  22. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Can someone post a list or screen shot of 5.2 ASR and EAF modules since I imported my 5.1 rules? Want to check if anything changed. Thanks ...............
     
  23. test

    test Registered Member

    Joined:
    Feb 15, 2010
    Posts:
    499
    Location:
    italy
    EAF_modules → mshtml.dll;flash*.ocx;jscript*.dll;vbscript.dll;vgx.dll

    ASR_modules → npjpi*.dll;jp2iexp.dll;vgx.dll;msxml4*.dll;wshom.ocx;scrrun.dll;vbscript.dll
    ASR_zones → 1;2 (1 = Intranet; 2 = Trusted)
     
  24. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    This is driving me nuts.

    Started with ver. 5.1 and appears to be continuing in 5.2. I guess the first question is does anyone know if there is a limit on the number of new apps that can be added to the popular software profile? What is going on is the GUI at times chops off the top of the display where the 7*** apps start. Sometimes the first, sometimes the first and second, etc.. Other times, I have had one or more apps randomly deleted; again starting at the top 7*** apps. No rhyme or reason to this.

    I have added around ten new apps to the profile.
     
  25. Cutting_Edgetech

    Cutting_Edgetech Registered Member

    Joined:
    Mar 30, 2006
    Posts:
    5,694
    Location:
    USA
    I just noticed that Adobe Flash is not listed in the default list of applications being protected by EMET 5.2. Also how is the user suppose to disable EMET 5.2 when they need to update an application like java, or any other application being protected by EMET?

    Edited 3/13 @ 8:35: I use Firefox so I will need to add it manually, but I read somewhere that IE11 runs flash player inside it's own process so it does not need to be added. I'm not sure about previous versions of IE.
     
    Last edited: Mar 13, 2015
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.