[Full-disclosure] RE: Full-Disclosure Digest, Vol 8, Issue 48

From: Stejerean, Cosmin (cosmin_at_cti.depaul.edu)
Date: 10/27/05

  • Next message: Mark Sec: "[Full-disclosure] RFID docs & tools ?"
    Date: Thu, 27 Oct 2005 14:00:04 -0500
    To: <full-disclosure@lists.grok.org.uk>
    
    
    
    

    >> If your altered virus sample
    ?> still executes correctly, you have simply created a new virus
    ?> variant.
    >
    >Not exactly, please look at this virustotal.com log
    >http://www.securityelf.org/updmagic.html
    >
    >The altered (120 bytes prepended) TXT_* variant is STILL detected by your
    >product (CA), but when I change the first byte from "Z" to "M" - your
    >product
    >fails (MZ_* variant).

    The virus scanner determined the type of the file by the header and it
    failed. That's bad news. I am wondering however, when I execute that file,
    how does the OS process the file? I guess my question is, if I have a
    modified version of a virus, with whatever header, if I try to execute that
    file, will the virus code get executed?

    Cosmin Stejerean

    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/



  • Next message: Mark Sec: "[Full-disclosure] RFID docs & tools ?"

    Relevant Pages

    • Re: virusscanner
      ... The simple fact is that a virus written for Linux could not run under ... Unlike with Windows, you could not just click on a virus and allow it to ... execute because you cannot automatically save something with execute ...
      (alt.os.linux.suse)
    • Re: are downloads scanned?
      ... I like the Practice safe Hex idea, ... >> if you receive and execute an attachment which is 1) new enough that it ... >> not been identified and had its signature placed in the virus definitions ... >> a virus or worm or anything else that would be of any interest to the AV ...
      (microsoft.public.security)
    • Re: [opensuse] Who said Linux doesnot get Virus infections
      ... Nothing to "execute" there. ... that most desktop linux users would use. ... Sounds like a virus to me. ... A boot sector virus is executed every time the computer is booted. ...
      (SuSE)
    • RE: [Full-disclosure] RE: Full-Disclosure Digest, Vol 8, Issue 48
      ... > The virus scanner determined the type of the file by ... > the header and it failed. ... > wondering however, when I execute that file, how does ... find "Nihilist" >tmp ...
      (Full-Disclosure)
    • Re: Linux virus question
      ... But a worm can carry a virus and may ... but not "*deliberately* execute the damn thing". ... the USER SAVING a mail attachment. ...
      (alt.os.linux)