3 ms·
1. Really? I've been using it for a while, and no breakage. Sure, I just use the default rulelist instead of applying rules to everything (which imo is what mos
by Spittie 12y ago
1. Really? I've been using it for a while, and no breakage. Sure, I just use the default rulelist instead of applying rules to everything (which imo is what most people should do).
2. Sure, but it's better than nothing. As parent said, this exploit is mitigated by EMET. See http://rationallyparanoid.com/articles/emet-testing.html http://rationallyparanoid.com/articles/emet-testing.html for more tests
Yes, it's a bandaid. But since it help and it's free, why not?
- bananas 12y agoWe've had a couple of older COM-based applications that target Windows 5.1 (2003/XP) platforms fail unpredictably with it on later operating systems. Whether these are just badly behaved applications or compilers or a faulty design in EMET we don't know as it's all closed source and when you're left with a steaming minidump (because you can't catch these unless you use ADplus) it's not easy to work out why a process failed from that if EMET shot it. As for the better than nothing, yes until your phone starts ringing like a cheesy sci-fi flick because half your MSMQ sinks are crashing... My comment above probable shouldn't have been: no you shouldn't use it until you've soak tested your applications on it.
- noinsight 12y agoEMET should show a notification when it blocks something and it should also make an event log entry. (These are configurable iirc.)