RE: [Full-Disclosure] MyDoom download info

From: first last (randnut_at_hotmail.com)
Date: 01/31/04

  • Next message: John Vill: "Re: [Full-Disclosure] Script Kiddies [OT]"
    To: full-disclosure@lists.netsys.com
    Date: Sat, 31 Jan 2004 00:28:44 +0000
    
    

    > > to successfully unpack the program. All they really needed to
    > > do was dump it from memory while it was running and they could've
    >analyzed
    > > it immediately with any disassembler.
    >
    >Forgive me, I am no assembly hacker nor much of a programmer,
    >but would it be possible for a program to 'react' in some way
    >were one to try to dump it from memory?

    The program would have to use a device driver to protect itself from not
    being dumped from memory to disk. But there are ways around that as well.

    _________________________________________________________________
    Get a FREE online virus check for your PC here, from McAfee.
    http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: John Vill: "Re: [Full-Disclosure] Script Kiddies [OT]"

    Relevant Pages

    • Problems installing 5.1A on XP1000
      ... The drive I'm attempting an install to is an IBM ... 640 MBytes of System Memory ... isa0 at pci0 ... DUMP: Warning: no disk available for dump. ...
      (Tru64-UNIX-Managers)
    • Booting 4.0 on XP1000
      ... available memory from 0x2ef8000 to 0x7ffec000 ... isp0 at pci1 slot 6 ... gpc0 at isa0 ... DUMP: No primary swap, no explicit dumpdev. ...
      (Tru64-UNIX-Managers)
    • Re: LIVEDUMP
      ... LIVEDUMP came about as a side-effect of analyzing ... snapshot of memory is taken in a reserved memory area). ... happens if we analyze LIVE memory instead of a copy of it. ... medium systems had 0DM long before that (dump memory for mix-id 0, ...
      (comp.sys.unisys)
    • SUMMARY: Problems installing 5.1A on XP1000
      ... The drive I'm attempting an install to is an IBM ... 640 MBytes of System Memory ... isa0 at pci0 ... DUMP: Warning: no disk available for dump. ...
      (Tru64-UNIX-Managers)
    • RE: Hangs during "dump" with 6.0 and current ports
      ... Due to lack of memory I had added an additional swap-file via mdconfig 3 ... filesystem with snapshots active and the swapfile is in the same filesystem ... Hangs during "dump" with 6.0 and current ports ... Maybe you need some more swap space? ...
      (freebsd-questions)