Malwarebytes Anti-Exploit

Discussion in 'other anti-malware software' started by ZeroVulnLabs, Oct 15, 2013.

  1. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    mood, I wonder why cylance all of a sudden decided to flag is as an exploit ?
    you might be right, just chalk the 60 bucks as a loss. I will still send zero the file he asked for if he lets me know where to send it to.
     
  2. guest

    guest Guest

    ...flagging an Anti-Exploit as an Exploit o_O
    But maybe a solution can be found after sending the file.
     
  3. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Hi boredog, you can just PM me the FRST logs. From the looks of it seems like a false positive from Cylance.
     
  4. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    no option to attach the file and if I try copy and paste it won't accept it. 773 k
     
  5. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    When writing a PM there's a button that says "Upload a file". Use that feature to attach the FRST logs.
     
  6. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    sorry zero but when I click on you to start a conversation there is no upload file option.
     
  7. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    Click on "Start a conversation" and then you'll see the option at the bottom-right:

    upload_2016-6-29_13-38-36.png
     
  8. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    sorry not getting that option here. tried changing to 3x fluid and still nothing..
     
  9. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    ShvFI

    thanks for clarifying that.

    that is the same screen I get
     
  10. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,009
    +1
     
  11. SweX

    SweX Registered Member

    Joined:
    Apr 21, 2007
    Posts:
    6,429
    Just FWIW, I see the same as in your screenshot. Probably not post count then.
     
  12. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    Issue 1: Bug in 1.09.1.1130 stack pivot disabling
    Disabling "Stack Pivoting Protection" under "Advanced Settings" has no effect. With all mitigations disabled no exploitation attempt should be intercepted, but with 1.09.1.1130 a stack pivot will still be intercepted no matter what.
    This issue has only been tested using Internet Explorer 8 on Windows 7 SP1.

    Issue 2: Outdated MBAE documentation
    The MBAE help documentation (mbae.chm) is outdated. The change log ("What's new!") for example mentions new features introduced version 1.06 (a version from over a year ago).
     
  13. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    ropchain that might explain the issue with IE 11 in the newest beta build.
     
  14. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    still waiting for zero to tell me how to give him me file
     
  15. JRViejo

    JRViejo Super Moderator

    Joined:
    Jul 9, 2008
    Posts:
    98,010
    Location:
    U.S.A.
  16. boredog

    boredog Registered Member

    Joined:
    Feb 1, 2015
    Posts:
    2,499
    "Members are not able to attach files to private conversations." per lowwatwermark

    got it so zero still needs to tell me where to send file then.
     
  17. haakon

    haakon Guest

    @ ZeroVulnLabs pbust

    For the love of god would you please, please (please!) get boredog to continue this issue in the Malwarebytes Forum? Clearly, both of you are better served in that.

    @ boredog

    pbust is very active at the Malwarebytes Forum which is all set up for getting your files. None of this "Members are not able to attach files to private conversations" stuff. In fact, they looooove getting files over there. Not only that, they have mods that call themselves Forum Deity who will make absolutely certain you won't have wait helplessly at your keyboard. Really!
     
  18. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    @boredog, feel free to email me to pbustamante at malwarebytes dot org.

    @ropchain, thanks for reporting. Will check this immediately.
     
  19. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    @ropchain, just to verify, you are closing and reopening the app prior to retesting after changing the advanced configs, right? The DLL needs to unload and re-inject after config changes.
     
  20. Mr.X

    Mr.X Registered Member

    Joined:
    Aug 10, 2013
    Posts:
    4,809
    Location:
    .
    @ZeroVulnLabs
    Beta 1.09.1.1130 working just fine here since its release, on my daily net activity... :thumb:
     
  21. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
  22. anon

    anon Registered Member

    Joined:
    Dec 27, 2012
    Posts:
    8,009
    Last edited: Jun 30, 2016
  23. ZeroVulnLabs

    ZeroVulnLabs Developer (aka "pbust")

    Joined:
    Mar 5, 2012
    Posts:
    1,189
    Location:
    USA
    No need, we've repro'ed and are analyzing the problem. Thanks again!
     
  24. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    I am closing and reopening IE in between altering the config.
     
  25. ky331

    ky331 Registered Member

    Joined:
    Jun 25, 2008
    Posts:
    158
    I'm a bit leery of the impending merge of MBAE+MBARW into MBAM:

    1a) COMPLEXITY: Even if the installer --- or subsequent program options --- allow the user the ability to enable only those modules which they actually want, this will be greatly confusing to novices who have no idea what everything's about. In particular,
    1b) Each module (AM, AE, ARW) currently has its own settings/configuration menu. It's daunting enough for some people to handle the configurations one-at-a-time... it will become all-the-more intimidating if all these settings are merged into one big listing.
    2) CONFLICTS: As you know, there are competing --- and often conflicting --- products available. Let's start with EMET 4.x/5.x, which is well-known to conflict with MBAE. There are many people happily/currently using MBAM+EMET, who might be caught off-guard if a "new and improved" MBAM starting pushing MBAE on them, resulting in lots of program crashes. Likewise for HitmanPro.Alert. In terms of Anti-Ransomware --- and I don't know if these are compatible or conflicting --- you're up against the likes of CryptoPrevent, and WIN(Patrol)-AntiRansomware --- to name just two. I am concerned that MBAM's reputation would be irreparably damaged if an augmented version conflicted with these (or similar) products.
    3) INTERDEPENDENCE: Lastly, there's the concept of "not having all your eggs in one basket": if malware somehow neutralizes MB, the user would lose all 3 modules (AM, AE, ARW). That's reason enough why many people prefer to pick-and-choose components from separate vendors: so if one happens to get successfully attacked, hopefully the others will still remain intact, providing their aspect of defense.
     
    Last edited: Jun 30, 2016
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.