EMET (Enhanced Mitigation Experience Toolkit)

Discussion in 'other anti-malware software' started by luciddream, Apr 1, 2013.

  1. Gobbler

    Gobbler Registered Member

    Joined:
    Jul 30, 2010
    Posts:
    270
    Found it by myself while playing with EMET, you can verify it in two ways firstly set ASLR in EMET to "Opt In" and then navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\MitigationOptions and double click on MitigationOptions and reset the value to 555 then reboot the computer, now open the EMET interface and you would now see ASLR is turned to "Always On" in system settings.

    Secondly, you can right click on any process in process explorer and it would have Force Relocate enabled for it in the lower portion of the context menu, also you can look in the lower pane and each non ASLR dll would be highlighted/relocated.

    Yep, know about that but non ASLR exe processes doesn't seem to be relocated and every time load in same addresses even with ASLR set to "Always On" :(
     
  2. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
  3. fax

    fax Registered Member

    Joined:
    May 30, 2005
    Posts:
    3,899
    Location:
    localhost
    EMET 4.1 Uncovered

    A rather interesting analysis and assessment...
    -http://0xdabbad00.com/wp-content/uploads/2013/11/emet_4_1_uncovered.pdf-
     
  4. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    As much as Windows Update scans it seems like they would be able to detect if EMET was installed and which version...then offer an update if one existed. At least that is what they should be doing.
     
  5. Syobon

    Syobon Registered Member

    Joined:
    Dec 27, 2009
    Posts:
    469
    i can't get emet 4.1 to work with sandboxie 4.06, no EMET.DLL loaded in programs under sandboxie, anyone else facing the same problem? thanks.
     
  6. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,094
    Location:
    Germany
    It should work with forced programs and the compatibility option checked in Sandboxie.
     
  7. fearlessscientist

    fearlessscientist Registered Member

    Joined:
    Sep 6, 2013
    Posts:
    166
    Location:
    USA
    Yes, EMET does not protect programs running in sandboxie free version.
     
  8. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,094
    Location:
    Germany
    If you are using the free version, Syobon, you don't have the option of forced programs.
     
  9. Krysis

    Krysis Registered Member

    Joined:
    Dec 28, 2012
    Posts:
    371
    Location:
    DownUnder
    Don't use Sandboxie generated shortcuts – or - modify to allow Explorer to run sandboxed program:
    Eg – for Firefox:

    "C:\Program Files\Sandboxie\Start.exe" explorer "C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
    (add Explorer.exe to Start\Run Access in sandbox)

    Now Emet.dll should run.

    Edit
    This is actually a Sandboxie issue - not an EMET one.
     
    Last edited: Nov 20, 2013
  10. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    EMET agent not running error indeed seems gone after reboot.


    Nice find :) Some interesting info in there:



    Yes that would be handy, but it's still MS we're talking about :D
     
  11. guest

    guest Guest

    Well, still a valuable information nonetheless. Thank you. :thumb:
     
  12. fearlessscientist

    fearlessscientist Registered Member

    Joined:
    Sep 6, 2013
    Posts:
    166
    Location:
    USA
    Immediately after I login to windows, there is an icon flashing on my taskbar for a fraction of a second, and it looks like EMET's icon. Can anyone confirm if they see the same in windows 7 ? I want to make sure its not any malware. I have scanned my machine with all scanners in my signature and it looks clean.
     
  13. acr1965

    acr1965 Registered Member

    Joined:
    Oct 12, 2006
    Posts:
    4,995
    I've not read the entire thread but is it common to have to disable "Caller" ROP Mitigation in browsers? I have had to disable it for Google Chrome, FF and IE 11 (also my media player, Zoom). For some reason PaleMoon browser works fine without having to disable this. Is there any serious security problems associated with having the ROP Mitigation disabled? If so, is there a mitigating security measure that can be taken as a whole or in the settings of each browser individually?

    thanks
     
  14. FleischmannTV

    FleischmannTV Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    1,094
    Location:
    Germany
    @ acr1965

    Regarding Chrome, please look here and here. As to the other browsers, I don't know.
     
  15. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    With EMET 4.1, with all the different softwares I use, so far each one is set with all EMET mitigation .. even Internet Explorer 11 with no ill-effects currently.

    Also with 'Stop on exploit', 'Deep Hooks', 'Anti Detours', 'Banned Functions'.

    ... been all set since official release of 4.1 and no problems to report yet.
     
  16. guest

    guest Guest

    Firefox went "it's already running but not responding" mode with all mitigations enabled.
     
  17. aztony

    aztony Registered Member

    Joined:
    Sep 9, 2012
    Posts:
    737
    Location:
    The Valley Arizona
    I am just wondering if anyone else is getting this. I have EMET 4.1 running on (2) PCs, one XP and Win 7. Just yesterday I found that when I try to open the UI from the sys tray on the XP pc I get an error message that admin rights is required. But the UI opens right up when I initiate the task from the start menu. This happens only on the XP rig.

    see screenshots
     

    Attached Files:

  18. fearlessscientist

    fearlessscientist Registered Member

    Joined:
    Sep 6, 2013
    Posts:
    166
    Location:
    USA
    It's a known issue. Happens in windows 7 as well.
     
  19. aztony

    aztony Registered Member

    Joined:
    Sep 9, 2012
    Posts:
    737
    Location:
    The Valley Arizona
    I see. Thanx
     
  20. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    Hi fearlessscientist.

    What are the conditions under Windows 7 which makes this message appear?

    Why I'm asking because I've not once experienced such when opening the EMET UI via systray on Windows 7 x64.

     
  21. fearlessscientist

    fearlessscientist Registered Member

    Joined:
    Sep 6, 2013
    Posts:
    166
    Location:
    USA
    I made a google search for it and many people have the problem. Looks like the problem occurs when you have UAC disabled. I haven't tried with UAC enabled though.
     
  22. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    ok, thanks. Mine is at system default.
     
  23. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    I believe it happens when you work in Admin acc. I have EMET on 3 PC Win-7. I have to use 1 PC in Admin acc. only. I have the issue on that PC only.

    I've just checked my main PC where I work in SUA. When I entered the Admin acc. I could launch EMET 4.1 GUI from the sys tray icon without this issue.
     
    Last edited: Nov 27, 2013
  24. aztony

    aztony Registered Member

    Joined:
    Sep 9, 2012
    Posts:
    737
    Location:
    The Valley Arizona
    Yeah, I just found it odd because it wasn't doing that when I 1st updated from 4.0.
     
  25. TomAZ

    TomAZ Registered Member

    Joined:
    Feb 27, 2010
    Posts:
    1,131
    Location:
    USA
    Yep. Experienced it here on XP as well. Thought it was just my machine, so uninstalled it. But now that I know, I may give it another try.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.