RE: [Full-Disclosure] MyDoom download info

From: first last (randnut_at_hotmail.com)
Date: 01/30/04

  • Next message: vuln: "Re: [Full-Disclosure] Script Kiddies [OT]"
    To: full-disclosure@lists.netsys.com
    Date: Fri, 30 Jan 2004 22:26:15 +0000
    
    

    >Given that its possible for a program to detect that its being run under
    >a debugger,
    >wouldn't it be possible for a virus to behave differently in the debug
    >environment?

    Yes. But todays computer viruses are very simple and very weak. Wait a few
    years and they should be a lot more powerful.

    [...]
    >IE: how do you know that the behavior you see in the lab reflects
    >behavior in
    >the real world? (I get a kind of 'schrodingers cat' deja vu).

    You can always disassemble the virus, which is what people will do if it's a
    real "popular" one such as MyDoom. Then you know for sure what it's going to
    do. Viruses are very easy to understand because they're so small compared to
    the average windows program.

    _________________________________________________________________
    What are the 5 hot job markets for 2004? Click here to find out.
    http://msn.careerbuilder.com/Custom/MSN/CareerAdvice/WPI_WhereWillWeFindJobsIn2004.htm?siteid=CBMSN3006&sc_extcmp=JS_wi08_dec03_hotmail1

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: vuln: "Re: [Full-Disclosure] Script Kiddies [OT]"

    Relevant Pages

    • Re: Cannot Close Excel Automation Process
      ... (Since the Debugger is a special environment, ... the majority of my execution time would be taken ... to stop it from doing that Virus check. ... My workaround is that I do a SaveAS after each bit of data logging. ...
      (alt.comp.lang.borland-delphi)
    • Re: Gamma Function
      ... I have made fun of because it's very careless to analyse a virus with a ... debugger alone. ... Small uncomplicated viruses might be analysed using a ... Also there is a probability the virus takes over while being analysed with a ...
      (sci.physics.relativity)
    • Re: Cannot Close Excel Automation Process
      ... (Since the Debugger is a special environment, ... the majority of my execution time would be taken ... to stop it from doing that Virus check. ... force a different logic path. ...
      (alt.comp.lang.borland-delphi)
    • Re: WinIce/SoftIce
      ... > When I debug the source from DShow and there the method ... > installed means that you ary running a debugger! ... No it's not a virus. ... Various DShow filters check for the presence of low ...
      (microsoft.public.win32.programmer.mmedia)