查看: 4485|回复: 4
收起左侧

[一般话题] EMET 5.2检测到ASR mitigation

[复制链接]
EnyieLau
发表于 2015-3-24 21:09:46 | 显示全部楼层 |阅读模式
我在正常使用IE 11看网易(或者搜狐)新闻的时候突然冒出这个提示,TechNet上面有人说和Flash有关。求教详细说明!
驭龙
发表于 2015-3-25 08:47:21 | 显示全部楼层
正常现象,凡是浏览器调用ASR保护的组件,ASR就会有提示,你在网页上右键菜单→属性,也会有连接到脚本插件的提示
EnyieLau
 楼主| 发表于 2015-3-25 12:24:08 | 显示全部楼层
驭龙 发表于 2015-3-25 08:47
正常现象,凡是浏览器调用ASR保护的组件,ASR就会有提示,你在网页上右键菜单→属性,也会有连接到脚本插件 ...

冒昧问一下ASR保护是什么?不懂啊
驭龙
发表于 2015-3-25 12:45:32 | 显示全部楼层
EnyieLau 发表于 2015-3-25 12:24
冒昧问一下ASR保护是什么?不懂啊

就是阻止某些程序调用特定的模块,简单的说就是这样
Attack Surface Reduction (ASR)

The ASR is a mechanism to block the usage of a specific modules or plug-ins within an application. For example, you can configure EMET 5.0 to prevent Microsoft Word from loading the Adobe Flash Player plug-in, or, with the support of security zones, you can use EMET 5.0 to prevent Internet Explorer from loading the Java plug-in on an Internet Zone website while continuing to allow Java on Intranet Zone websites.

During the preview period we have performed several tests and collected your feedback to finalize the default configuration for this mitigation. We aimed at having a configuration that provided security, and at the same time, did not limit the user experience with the applications protected by EMET 5.0. By default, EMET 5.0 is configured to block some modules and plug-ins from being loaded by Internet Explorer while navigating to websites belonging to the Internet Zone, and to also block the Adobe Flash plug-in from being loaded by Microsoft Word, Excel, and PowerPoint. We have chosen modules that are commonly used in certain exploitation scenarios, but like all EMET features and mitigations, the ASR is completely configurable to satisfy everybody’s needs and to be tailored to specific systems’ requirements.
EnyieLau
 楼主| 发表于 2015-3-26 10:34:21 | 显示全部楼层
驭龙 发表于 2015-3-25 12:45
就是阻止某些程序调用特定的模块,简单的说就是这样

谢谢大神!
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-11-24 07:57 , Processed in 0.117070 second(s), 16 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表