Max security on EMET - is it that simple?

Discussion in 'other anti-malware software' started by raven211, Jun 17, 2011.

Thread Status:
Not open for further replies.
  1. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    That setting and I'm done?
     
  2. Konata Izumi

    Konata Izumi Registered Member

    Joined:
    Nov 23, 2008
    Posts:
    1,544
    If none of your apps break under maximum settings.. lucky you :thumb:
    but if you experience something bad change the settings to

    Opt out
    opt out
    Opt in

    :)

    also add all your internet facing apps under "Configure Apps" option.
     
  3. lordraiden

    lordraiden Registered Member

    Joined:
    Jan 30, 2006
    Posts:
    3,066

    Read this: http://www.rationallyparanoid.com/articles/microsoft-emet-2.html

    Are you using this settings without issues or the default ones all opt in?

    What is the difference btw opt-in and opt-out?
     
  4. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    I read that DEP should be opt in for compatibility, so is it not ASLR that should be opt out?


    Do I really have to add all my games? That would a pain in the buttcake...

    Thanks
     
  5. lordraiden

    lordraiden Registered Member

    Joined:
    Jan 30, 2006
    Posts:
    3,066
    If you think that a malware can target an expoit in a game... maybe you can add some popular online games like WoW

    http://www.rationallyparanoid.com/articles/microsoft-emet-2.html

    From the link that I provided you before:

     
  6. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    3,764
    Location:
    Outer space
    Opt-in(default setting for Vista and & 7 even without EMET) does actually nothing to enforce the migitations, the programs on your computer have to specifically opt-in to DEP/ASLR/SEHOP to use it, if they don't it is not used.
    Opt-out makes all programs use it unless they specifically opt-out because the program is incompatible or something like that.
    And always on just forces it on all programs.
     
    Last edited: Jun 17, 2011
  7. lordraiden

    lordraiden Registered Member

    Joined:
    Jan 30, 2006
    Posts:
    3,066
    Ok, thanks I will try Opt-out in the global settings for DEP and SEHOP to see what happens, I'm going to left ASLR opt-in
     
  8. funkydude

    funkydude Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    6,851
    That's some terrible advice. Injecting DLL's into games is a sure way to trigger ban systems.
     
  9. Divenow

    Divenow Registered Member

    Joined:
    Sep 18, 2010
    Posts:
    37
    I used Max Security on EMET and it caused Java to crash on install. I took a while to realize that EMET was causing this.
     
  10. cm1971

    cm1971 Registered Member

    Joined:
    Oct 22, 2010
    Posts:
    727
    Thanks for the URL. I just used it to set up EMET on my laptop and so far everything is working great. :thumb:
     
  11. AlexC

    AlexC Registered Member

    Joined:
    Apr 4, 2009
    Posts:
    1,280
    Is really needed to add specifically flash player and java? Or adding IE9 is enough?
     
  12. cm1971

    cm1971 Registered Member

    Joined:
    Oct 22, 2010
    Posts:
    727
    This is an interesting video about EMET.

    -http://www.youtube.com/watch?v=iOpcwEz0b1A
     
  13. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,516
    It is that simple. Only known issue of DEP Always On is broken Java installers. The extracted .msi still works.
     
  14. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    I thank everyone for their answers so far, and an especial thanks to lordraiden for providing me with that detailed but easy to follow guide for EMET.
     
  15. lordraiden

    lordraiden Registered Member

    Joined:
    Jan 30, 2006
    Posts:
    3,066
    You are welcome, I was messing around with EMET until I discover the guide :D
     
  16. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,148
    Yes, normally it's that simple. I know some programs have issues with this though and therefor you need to force the individual applications instead of making a system wide setting.

    Make sure that you're using UAC with EMET. You don't want a program like EMET to be accessible by malware.
     
  17. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    For usability I do have UAC disabled, I know the risks with that and I'm willing to take them. Only setting that isn't max in EMET is DEP which is set to opt out for my game which doesn't support it being max.
     
  18. raven211

    raven211 Registered Member

    Joined:
    May 4, 2005
    Posts:
    2,567
    I have enabled Max Security effective next boot for testing because Dragonica was the game messing up whatever I tried to do, so with that uninstalled I will test other games.
     
Loading...
Thread Status:
Not open for further replies.