EMET (Enhanced Mitigation Experience Toolkit)

Discussion in 'other anti-malware software' started by luciddream, Apr 1, 2013.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    So much for EMET 4.1 self-protection. I was testing out Quarri's MyPOQ armored browser. It crashed IE10 and took EMET 4.1 with it.
     
  2. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    163,926
    Location:
    Texas
    http://blogs.technet.com/b/srd/arch...riven-customer-focused-approach-for-emet.aspx
     
  3. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,644
    Location:
    USA
    I just saw that 4.1 update 1 was released today so I come back here and see that ronjor doesn't miss a thing. :) Testing it out now.
     
  4. cavehomme

    cavehomme Registered Member

    Joined:
    May 19, 2010
    Posts:
    137
    Location:
    Alps
    I've installed EMET 4.1 with default settings just now, not clear though if certificate pinning is needed since I am using Bitdefender AV Pro which carries out its own certificate checks (as I understand it). My thinking is that there may be a potential conflict if Certificate Pinning is enabled, but I would very much appreciate some comments from people who are far more experienced than I am, thank you.
     
  5. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
    It seems that a new precedent has been set Re "x.1 update 1" *puppy*
     
    Last edited: May 1, 2014
  6. SchmidtB

    SchmidtB Registered Member

    Joined:
    Apr 8, 2014
    Posts:
    1
    Location:
    Germany
    Hitmanpro is showing bad certificates for several EMET 4.1 files :-(
     
  7. Baserk

    Baserk Registered Member

    Joined:
    Apr 14, 2008
    Posts:
    1,321
    Location:
    AmstelodamUM
    Are your root certificates up to date?
    Afaik, last month, new MS certificates were issued though Windows Update (and some soon withdrawn and then re-issued).
    Perhaps you've got old 1024bit certificates instead of new 2048bit ones?
     
  8. cavehomme

    cavehomme Registered Member

    Joined:
    May 19, 2010
    Posts:
    137
    Location:
    Alps
    Just ran Hitman after installing EMET 4.1 today, no bad certificates showing.
     
  9. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
  10. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
  11. harshisthere

    harshisthere Registered Member

    Joined:
    Aug 8, 2011
    Posts:
    84
    Downloading now but there is changelog.
     
  12. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    I couldn't find any. Usually if you install EMET, it also installs a manual(PDF), with shortcut in Start menu. Perhaps there is a changelog in there?
     
  13. harshisthere

    harshisthere Registered Member

    Joined:
    Aug 8, 2011
    Posts:
    84
    Nothing there.
     
  14. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,644
    Location:
    USA
    Page not found... I'll probably stick with the 4.1 update 1 for now anyway. It seems to be working well.
     
  15. Peter2150

    Peter2150 Global Moderator

    Joined:
    Sep 20, 2003
    Posts:
    20,590
    Just google Microsoft EMET 5.0 Brought me right to the download page.
     
  16. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,872
    Location:
    Outer space
    Afaik, that is Technical Preview 1, not 2.
    Hmm, a pity.
    Just visited it again, it redirects to login.live.com for logging in, like it used to.
     
  17. kronckew

    kronckew Registered Member

    Joined:
    Aug 27, 2006
    Posts:
    455
    Location:
    CSA Consulate, Glos., UK
    i found the download page HERE for emet 5 tp 2.
     
  18. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,644
    Location:
    USA
    Interesting. It shows me as already logged in but still says "page not found". Maybe they just don't want me to get there. Not a big deal, just strange that it works for you and not me.
     
  19. smith2006

    smith2006 Registered Member

    Joined:
    Mar 28, 2006
    Posts:
    808
    I had the same problem.

    I have managed to sign up (clicking "Join") & download using this link awhile ago:

    https://connect.microsoft.com/directory/?keywords=EMET
     
  20. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,219
    Location:
    USA
  21. taytong888

    taytong888 Registered Member

    Joined:
    Mar 26, 2006
    Posts:
    168
    Running EMET 5.0 TP1,with Recommended Settings. I am having the following problem:

    When I finish using IE 11.0, I close it. But then the screen shows a pop-up message which reads: "IE has closed unexpectedly. Windows is looking for solutions..." Then IE restarts.

    I also notice that IE has ASR enabled, but Firefox and Chrome browsers do not. I don't experience the same problem with these 2 browsers when I close them. Unchecking ASR box for Internet Explorer doesn't seem to solve the problem.

    Any ideas or suggestions to fix this annoying problem? Thanks for your help.
     
  22. KaptainBug

    KaptainBug Registered Member

    Joined:
    Dec 26, 2013
    Posts:
    480
    what happens if you remove IE from EMET's protection ?
     
  23. taytong888

    taytong888 Registered Member

    Joined:
    Mar 26, 2006
    Posts:
    168
    Hello KaptainBug,

    Your suggestion works, and the problem is gone. Just one fewer benefit of EMET. I have not used IE for a long time.
     
  24. KaptainBug

    KaptainBug Registered Member

    Joined:
    Dec 26, 2013
    Posts:
    480
    No.. That was not my suggestion.. That was only to see if EMET is infact the culprit for IE freeze.. Now since its confirmed that EMET is causing the problem, add IE to EMET and uncheck each mitigation one by one and see exactly which mitigation is causing IE to hang. So you can disable that particular mitigation alone in EMET and still get protected from other mitigations..
     
  25. taytong888

    taytong888 Registered Member

    Joined:
    Mar 26, 2006
    Posts:
    168
    Hi KaptainBug,

    Sorry I misunderstood you. I put IE back under EMET's protection and did a few tests. Results are as follows:

    1. Disable each protection parameter (e.g. DEP, SEHOP) one by one while the rest remains enabled. Open then close IE. Same error message popping up.

    2. Disable only parameters of the same ROP Group (i.e. Load, Mem, Caller, SimE, Stack) while the rest of the parameters stays enabled. Same result as in Test#1 above.

    3. Ditto for parameters of the "Other" Group (i.e., SEHOP, EAF, ASR). Same result as in Test #1.

    4. When I disable only MEM Group parameters such as DEP, Null, Heap, Man and Bott, there's no more error message after opening then closing IE.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.