EMET (Enhanced Mitigation Experience Toolkit)

Discussion in 'other anti-malware software' started by luciddream, Apr 1, 2013.

  1. CHEFKOCH

    CHEFKOCH Registered Member

    Joined:
    Aug 29, 2014
    Posts:
    395
    Location:
    Swiss
    @WSpu
    EMET 5.5 isn't affected from your mentioned thing -> "and the technique works for all tested versions of EMET (4.1, 5.1, 5.2, 5.2.0.1)" so seems the latest version doesn't have these kind of problem. The mentioned CVE in this article was already fixed with 5.1.

    From what I know and my own research on this says that there is currently no hole.
     
  2. Phant0m

    Phant0m Registered Member

    Joined:
    Jun 7, 2003
    Posts:
    3,726
    Location:
    Canada
    This person withdrawn his post. o_O
     
  3. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    The related FireEye article is especially detailed and interesting.

    Link: https://www.fireeye.com/blog/threat-research/2016/02/using_emet_to_disabl.html

     
  4. ropchain

    ropchain Registered Member

    Joined:
    Mar 26, 2015
    Posts:
    335
    @WildByDesign

    With EMET 5.5 EAF now also sets an additional guard page on NTDLL to kill more shellcodes. ;)
     
  5. I have added these Attack Surface Reduction settings for all Office (2007) applications: HTML, flash, Javascript, Visual Basic script and dotNet execution interpreter. EMET ASR prevents these components to load so they cannot be abused by code embedded in the content of documents, spreadsheets, presentations, et cetera.

    upload_2016-2-28_11-1-1.png

    Note: I have disabled early warining (EmeT phone home) and tray icon. You need to disable tray icon to stop EMET showing warnings of dot Net execution interpreter being blocked when starting office apps. Since no dot Net is executed, all Office Aps function normally (same happens when you don't disable javascript in Outlook, EMET will throw a pop-up, but Outlook works normally).
     
    Last edited by a moderator: Feb 28, 2016
  6. pcalvert

    pcalvert Registered Member

    Joined:
    May 21, 2005
    Posts:
    237
    Hi Kees,
    What about PDF readers. Shouldn't they also be given similar protection?

    Phil
     
  7. Yes, you are totally right

    I use Edge as PDF Reader (disabled IE11 and WMP)
    • Create a block rule for Edge in Windows Firewall
      (simply change the allow rules to block for both inbound and outbound)
    • Disable Flash in Edge
      settings>view advanced settings>Use Adobe Flash (OFF)
    • Disable Javascript in Edge
      [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MicrosoftEdge\Internet Settings\Zones\3]
      "1400"=dword:00000001

    Since Edge is a new application which is compiled with Control Flow Guard, so EMET does not (need to) protect it
     
    Last edited by a moderator: Feb 29, 2016
  8. Martin_C

    Martin_C Registered Member

    Joined:
    Dec 4, 2014
    Posts:
    525
    @Windows_Security :

    May I suggest you a much easier method that also happens to have a higher degree of daily usability ??

    Instead of applying all those settings you mention, then you can just use the Microsoft Reader app.
    If you don't have it installed, then it's free in the store.
    It handles PDF, XPS and TIFF files.

    1. No need to block it in firewall, since it will not connect out.

    2. No need to block Flash, since it does not use Flash.

    3. No need to go in registry to disable JavaScript.
    The Microsoft Reader app has a easily accessible switch in its settings to enable/disable JavaScript.

    So on a daily basis you have JavaScript disabled and whenever you need to fill out a form then you just enable JavaScript in app settings, fill out the fields in your form, mail or print it, disable JavaScript again right there in apps settings.
    Much easier then having to go into registry whenever you need JavaScript enabled.

    4. Microsoft Reader is a UWP app like Edge and are also compiled with Control Flow Guard, and just like Edge it also runs sandboxed in Appcontainer, so no need to worry about protecting it any further.

    Thought I would mention it, since it's a lot easier to just set the Reader app to default PDF handler and then have the JavaScript switch easily accessible.
     
  9. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    Try to manually change the IL.
    With Windows 7 + Sumatra PDF (my reader pdf offline) ,does not work the level untrusted.
    I used Mark Minasi Tool.



    http://sendvid.com/fw5embf2
     
  10. CHEFKOCH

    CHEFKOCH Registered Member

    Joined:
    Aug 29, 2014
    Posts:
    395
    Location:
    Swiss
    emule really? .... :D

    Just use Sumatra and block internet it's enough. o_O
     
  11. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    The pc is of my daughter.
     
  12. Cool thx, but I still use Egde as PF reader, because i did all the trouble already on my PC, will add this to wife's laptop because she uses Edge as browser.
     
    Last edited by a moderator: Feb 29, 2016
  13. Dirk41

    Dirk41 Registered Member

    Joined:
    Mar 22, 2016
    Posts:
    26
    hi guys. may i ask you a simple question?
    i just installed emet. i set recommended configurations at the beginning. but now i try to open it but nohing appears: i mean i see the process in background,the icon beside the clock on the bottom right, but i can't open it apparently.
    i use a standard account ,so it asks me a password,i type it, it',s ok it doesn't say it is wrong, but then the window closes

    thank you in advace


    EDIT: tried to reinstall. nothing
     
    Last edited: Mar 28, 2016
  14. Dirk41

    Dirk41 Registered Member

    Joined:
    Mar 22, 2016
    Posts:
    26

    problem solved. it has to be installed by admin



    a question: i am not an expert,so i would go with recommended settings. if i stay in this way, it is useful anyway or it's like not have it? thank you
     
  15. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
  16. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
    @ WildByDesign

    With EMET 5.5 on a OS W.10 you run the Exploit Test Tool (HPA3 ver 1.9.2)?
    Score?

    TH.
     
  17. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    @Sampei Nihira I am running EMET 5.5 on Windows 10 still, but I have not specifically tested Exploit Test Tool against EMET as of yet. I can give that a try later if I've got some extra time. Do I need to add the Exploit Test Tool executable to EMET's list of configured Apps? Or is there any other specific configuration within EMET that I need to set prior to running the Exploit Test Tool?
     
  18. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  19. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    @Sampei Nihira Preliminary testing results: Windows 10 Pro 64-bit, EMET 5.5, hmpalert-test version 1.9.2 32-bit. Unfortunately Surfright isn't offering the 64-bit exploit test tool recently, not sure how much of a difference that would make.

    EMET 5.5 let the following slip through:
    • Unpivot Stack
    • ROP - Wow64 bypass
    • ROP - Exploit Wow64
    • ROP - system() in msvcrt - partial
    • ROP - VirtualProtect() via CALL gadget
    • Heap Spray 1
    • Heap Spray 2
    • Heap Spray 3
    • Anti-VM - VMware
    • Anti-VM - Virtual PC
    • Webcam test (not an exploit)
    • Keyboard logger (not an exploit)
    This was not testing using AppContainer, though. I am still trying to figure out how to test EMET with AppContainer appropriately.
     
    Last edited: Apr 23, 2016
  20. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,365
    Location:
    Italy
  21. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    EMET 5.51 released!
    Link: https://www.microsoft.com/en-us/download/details.aspx?id=53354
    Also, the EMET support article has been updated as of 08/02/2016.
    Link: https://support.microsoft.com/en-ca/kb/2458544


    Updated user guide: https://www.microsoft.com/en-us/download/details.aspx?id=53355

    EDIT: Apparently 20+ new skins/themes added. That was unexpected. :cool:
     
    Last edited: Aug 3, 2016
  22. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    From user manual (5.5 and 5.51):
    EDIT: Here is a bit of info that I found from the previous release 5.5 manual, a change brought forward with that 5.5 release (which of course is still relevant with 5.51 release):
     
    Last edited: Aug 3, 2016
  23. rm22

    rm22 Registered Member

    Joined:
    Oct 26, 2014
    Posts:
    357
    Location:
    Canada
    Nice, no tweaking needed on installing 5.51 - even Chrome works with the default mitigations selected for it. I recall spending a loooong time getting some Softs to work with 4.1
     
  24. WildByDesign

    WildByDesign Registered Member

    Joined:
    Sep 24, 2013
    Posts:
    2,587
    Location:
    Toronto, Canada
    Some phenomenal tips for blocking some specific bypasses by configuring EMET via group policy along with other great information. These could be configured via EMET GUI or registry as well.
    Source: https://github.com/iadgov/Secure-Host-Baseline/tree/master/EMET

     
  25. Solarlynx

    Solarlynx Registered Member

    Joined:
    Jun 25, 2011
    Posts:
    2,015
    Good news! I wish I could use them on my MBAE though. :)
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.