ZeroVulnerabilityLabs ExploitShield
See my new post on the matter: http://www.insanitybit.com/2013/06/22/exploitshield-smart-antiexecutable/
A recent CNET article has praised an up and coming security product called ExploitShield. Though no real explanation is given as to how the product works the author has stated:
“It is not blacklisting, not whitelisting, and not sandboxing. We call it ‘application shielding,’ and it’s basically a pro-active way of preventing vulnerability exploits. It blocks 100 percent of the exploits it protects against, 100 percent of the time. I think it’s a new type of security software category, i.e., ‘anti-exploits’,”
The article is incredibly optimistic to the point where I think it’s both overselling and inaccurate. At one point stating:
“Ninety-five percent of successful exploits are Java- or PDF-based,” said Bustamante in a meeting at CNET’s San Francisco offices last June. “ExploitShield protects against exploit-delivered malicious payload,” he said. “It’s vulnerability-agnostic.”
The indication here is that they’re protecting against Java exploits and, as they claim, 100% of the time (to be clear they said it’s worked 100% of the time tested, which is a critical difference).
The interesting thing here is that Java attacks are typically attacks on the design of the program – they aren’t buffer overflows, they just trick it into doing what they want. They’re much more difficult to prevent.
Yet there’s a video of of preventing a java exploit. So there’s likely a HIPS component. No details are given as to how it manages to do this, but it’s simply to guess.
One thing worth noting is it says “update.exe blocked from executing through Java” – it’s unclear what this means. It sounds a lot like a sandbox if they’re denying Java from executing files, which is perfectly fine except they say it isn’t a sandbox so I’m wondering if there’s some other component at work here. I’m currently going to go ahead and guess that this is how it works. I actually think that’s pretty cool though not exactly bullet proof by any means.
It essentially seems like a ‘smart’ per-application (ie: decision based) antiexecutable. Now, that’s not super impressive. It’s definitely way better than your typical antiexecutable, but it’s just as easy to bypass, and the decision making leaves it even more vulnerable to bypasses.
ExploitShield seems to work by ‘profiles’ ie: there’s a list of apps that are protected. I assume this is for both security (more fine grained) and compatibility.
The list of ‘shielded’ applications included:
Firefox
Google Chrome
Internet Explorer
Opera
Java
WebBrowser Components (PDF, FLASH, JAVA …)
Adobe Acrobat*
Adobe Reader*
Foxit Reader*
Microsoft Office Word*
Microsoft Office Excel*
Microsoft Office PowerPoint*
Windows Media Player (wmplayer)*
Windows Media Player (wmplayer2)*
VLC Player*
Winamp Player*
QuickTime Player**
I have starred entries that have an ‘unlock’ next to them. Quicktime has a blue ‘unlock’ next to it. It seems they may be corporate edition only.
There is a ‘Log’ tag that shows the following:
I am not sold on the product. I wouldn’t add it on my system, because I think that AE is too easily bypassed, and the benefits do not outweigh the attack surface.
ExploitShield claims to prevent exploits, and even APT. Yet, based on a rudimentary overview of its feature it seems clear that it does not stop exploits, only their payloads, and it is very ill equipped for APT (APT assuming that the attacker has any knowledge that the program is installed) as it does not drive up the cost of attack significantly.
It is currently in beta and only available from CNET. (Here)
Follow me on Twitter – I’ll have more to say later.
blog comments powered by Disqus