Re: [Full-disclosure] Flash that simulates virus scan
- From: jf <jf@xxxxxxxxxxxxxxxxxxxx>
- Date: Thu, 1 Nov 2007 06:04:42 +0000 (UTC)
must be on one of the .gov red teams ;]
On Wed, 31 Oct 2007, reepex wrote:
Date: Wed, 31 Oct 2007 16:56:20 -0500
From: reepex <reepex@xxxxxxxxx>
To: Joshua Tagnore <joshua.tagnore@xxxxxxxxx>,
full-disclosure@xxxxxxxxxxxxxxxxx
Subject: Re: [Full-disclosure] Flash that simulates virus scan
resulting to se in a pen test cuz you cant break any of the actual machines?
lulz
On 10/31/07, Joshua Tagnore <joshua.tagnore@xxxxxxxxx> wrote:
List,
Some time ago I remember that someone posted a PoC of a small site that
had a really nice looking flash animation that "performed a virus scan" and
after the "virus scan" was finished, the user was prompted for a "Download
virus fix?" question. After that, of course, a file is sent to the user and
he got infected with some malware. Right now I'm performing a penetration
test, and I would like to target some of the users of the corporate LAN, so
I think this approach is the best in order to penetrate to the LAN.
I searched google but failed to find the URL, could someone send it to
me ? Thanks!
Cheers,
--
Joshua Tagnore
_______________________________________________
Full-Disclosure - We believe in it.
Charter:
http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- References:
- [Full-disclosure] Flash that simulates virus scan
- From: Joshua Tagnore
- Re: [Full-disclosure] Flash that simulates virus scan
- From: reepex
- [Full-disclosure] Flash that simulates virus scan
- Prev by Date: Re: [Full-disclosure] Flash that simulates virus scan
- Previous by thread: Re: [Full-disclosure] Flash that simulates virus scan
- Index(es):
Relevant Pages
- Re: [Full-Disclosure] New Win32 Worm regsvc32.exe offers rootkit features
... (such as Registration Service = "regsvc32.exe") ... [Full-Disclosure]
New Win32 Worm regsvc32.exe offers rootkit features ... worm on her win2k desktop. ...
> I was not able to remove the virus, so i plugged the machine of the net ... (Full-Disclosure) - Re: [Full-disclosure] RE: Panda Antivirus Enterprise Secure, Norton Antivirus 2005 and the virus
... The Orange virus filtering service discovered a virus or unauthorised code in an email
sent to you. ... Message subject: [Full-disclosure] RE: Panda Antivirus Enterprise
... Hosted and sponsored by Secunia - http://secunia.com/ ... (Full-Disclosure) - RE: [Full-disclosure] Someone wasted a nice bug on spyware...
... sent it to Microsoft a few days ago and they're looking into it. ... name to
register a domain for illegal use. ... > windows xp system with a freshly updated norton
anti virus. ... Full-Disclosure - We believe in it. ... (Full-Disclosure) - [Full-disclosure] Help!
... What I would like to ask is whether it is a "common" phenomenon, or does it mean a
virus attack? ... Subject: [Full-disclosure] Shell32.dll.124.config ... Full-Disclosure
is hosted and sponsored by Secunia. ... (Full-Disclosure) - Re: [Full-disclosure] Flash that simulates virus scan
... pdp: "military grade exploits? ... Flash that simulates virus scan ...
Full-Disclosure - We believe in it. ... Hosted and sponsored by Secunia - http://secunia.com/
... (Full-Disclosure)