[Full-disclosure] RE: Full-Disclosure Digest, Vol 8, Issue 48
From: Stejerean, Cosmin (cosmin_at_cti.depaul.edu)
Date: 10/27/05
- Previous message: Morning Wood: "Re: [Full-disclosure] Question about ethics when discovering a securityfault in system"
- Next in thread: auto445789_at_hushmail.com: "RE: [Full-disclosure] RE: Full-Disclosure Digest, Vol 8, Issue 48"
- Maybe reply: auto445789_at_hushmail.com: "RE: [Full-disclosure] RE: Full-Disclosure Digest, Vol 8, Issue 48"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 27 Oct 2005 14:00:04 -0500 To: <full-disclosure@lists.grok.org.uk>
>> If your altered virus sample
?> still executes correctly, you have simply created a new virus
?> variant.
>
>Not exactly, please look at this virustotal.com log
>http://www.securityelf.org/updmagic.html
>
>The altered (120 bytes prepended) TXT_* variant is STILL detected by your
>product (CA), but when I change the first byte from "Z" to "M" - your
>product
>fails (MZ_* variant).
The virus scanner determined the type of the file by the header and it
failed. That's bad news. I am wondering however, when I execute that file,
how does the OS process the file? I guess my question is, if I have a
modified version of a virus, with whatever header, if I try to execute that
file, will the virus code get executed?
Cosmin Stejerean
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- application/x-pkcs7-signature attachment: smime.p7s
- Previous message: Morning Wood: "Re: [Full-disclosure] Question about ethics when discovering a securityfault in system"
- Next in thread: auto445789_at_hushmail.com: "RE: [Full-disclosure] RE: Full-Disclosure Digest, Vol 8, Issue 48"
- Maybe reply: auto445789_at_hushmail.com: "RE: [Full-disclosure] RE: Full-Disclosure Digest, Vol 8, Issue 48"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|