[Full-disclosure] Flash that simulates virus scan



List,

Some time ago I remember that someone posted a PoC of a small site that
had a really nice looking flash animation that "performed a virus scan" and
after the "virus scan" was finished, the user was prompted for a "Download
virus fix?" question. After that, of course, a file is sent to the user and
he got infected with some malware. Right now I'm performing a penetration
test, and I would like to target some of the users of the corporate LAN, so
I think this approach is the best in order to penetrate to the LAN.

I searched google but failed to find the URL, could someone send it to
me ? Thanks!

Cheers,
--
Joshua Tagnore
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Relevant Pages

  • Re: [Full-disclosure] Flash that simulates virus scan
    ... had a really nice looking flash animation that "performed a virus scan" and ... after the "virus scan" was finished, the user was prompted for a "Download ... Right now I'm performing a penetration ... test, and I would like to target some of the users of the corporate LAN, so ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Flash that simulates virus scan
    ... after the "virus scan" was finished, the user was prompted for a "Download ... Right now I'm performing a penetration ... test, and I would like to target some of the users of the corporate LAN, so ... This usually does the trick if autorun is ...
    (Full-Disclosure)
  • Enforce Virus Scanning software on home PCs
    ... We want to prevent users from connecting to the corporate LAN if they ... We use Cisco VPN 3000 concentrators with the 3.6x vpn client. ... We use Zone Labs Zone Alarm Pro 3.7 ... We use McAfee virus scan 4.5.1 with latest super dats. ...
    (Security-Basics)
  • Re: phish.com/halloween....Virus?
    ... No virus from what I can see. ... It seems to be common in Panda Antivirus with Flash animation. ...
    (rec.music.phish)