FW: [Full-Disclosure] JPEG AV Detection

From: Todd Towles (toddtowles_at_brookshires.com)
Date: 09/28/04

  • Next message: Todd Towles: "RE: [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1933 - 20"
    To: "Mailing List - Full-Disclosure" <full-disclosure@lists.netsys.com>
    Date: Tue, 28 Sep 2004 14:26:26 -0500
    
    

     What exactly are the AV products detecting in the JPEG exploits? Barry
    and I was talking about how impressed we were that the AV companies
    jumped on this one and detection was pretty fast. But is the detection
    so generic that a variant will bypass? Is the detection based on a
    original exploit that could be modified in a way that makes it
    "undetectable" right now?

    -Todd

    -----Original Message-----
    From: Barry Fitzgerald [mailto:bkfsec@sdf.lonestar.org]
    Sent: Tuesday, September 28, 2004 1:55 PM
    To: Todd Towles
    Subject: Re: [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1933 -
    20 msgs

    Todd Towles wrote:

    >Yep, really surprised. Just hopefully the invalid data that is being
    >detected can't be changed or worked in a work that would bypass normal
    >detection. Once the file is renamed to a BMP or a GIF, you confuse the
    >whole thing even more.
    >
    >Are the AV products hitting on a part of the original exploit? Can this

    >part be changed in a future version to make it "undetectable". I am
    >very impressed at the work of the AV companines on this one, but I also

    >know that is this detection is too simple, that it will be bypassed.
    >
    >
    >
    I'm not sure what they're specifically detecting. This may be a good
    question for the list.

                 -Barry

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Todd Towles: "RE: [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1933 - 20"

    Relevant Pages

    • RE: [Full-Disclosure] JPEG AV Detection
      ... > What exactly are the AV products detecting in the JPEG exploits? ... Barry ... > jumped on this one and detection was pretty fast. ... JPEG, not just at the beginning, but I supposed ...
      (Full-Disclosure)
    • Re: [Full-Disclosure] Pentesting an IDP-System
      ... > Well I got an Intrusion Detection and Prevention System from a quite ... > Preferably some GPL or other "free" stuff since i dont have a budget ... > Full-Disclosure - We believe in it. ... > Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • Re: [Full-disclosure] McAfee VirusScan vs Metasploit Framework v2.x
      ... I think most AV today detects any tool wich can also been used by script ... award winning pestpatrol's detection wich find it with the md5 checksum ... > Full-Disclosure - We believe in it. ... > Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
      (Full-Disclosure)
    • Re: 2.6.17-rc5-mm3: bad unlock ordering (reiser4?)
      ... Barry K. Nathan wrote: ... that detection of those doesn't get shut down by the bad-lock-ordering ... lockdep testing for people running reiser4 filesystems. ...
      (Linux-Kernel)
    • Re: [Full-Disclosure] Remote MS03-043 detection for Windows NT
      ... If you're looking for a small spesific purpose tool there's one command line ... [Full-Disclosure] Remote MS03-043 detection for Windows NT ...
      (Full-Disclosure)