Re: The Coalition against Personal Firewalls



"Leythos" <void@xxxxxxxxxxx> wrote in message
news:sGehg.54359$P2.51220@xxxxxxxxxxxxxxxxxxxxxxxxx
In article <4ekvotF1fdip4U1@xxxxxxxxxxxxxx>, none@xxxxxxxxxxxxxxx
says...
We'll probably never know why AV vendors included a signature for Volker's
PoC.
As far as I can tell there is no heuristic detection involved.

Sure you will, but you won't get it down the path you are taking - you
see, if something is a good enough example of how to exploit something,
well, it should be detected as such.

Why should a program which tells the browser to connect to www.dingens.org be
detected as a virus? Why should a program which tells the browser to connect to
www.download-more-viruses.com not be detected as a virus?
Making this change to Volker's program will change the signature and then it's
not a virus any more.
If you do not believe this then please do the following before replying.
1. Find a virus scanner which detects Volker's code as a virus.
2. Compile your own code which connects to a different http server.
Is the new code detected as a virus? And if so by which AV product?

Thank you for taking the time to perform this experiment and letting us know the
results.

I don't understand how you can fail
to see/rationalize that concept.

Anything that makes use of an exploit should be detected and
stopped/blocked as malware. AV software does not understand the
"Intenet" of the programmer, it understands the black/white functions of
the application, the vectors, and the actions.

I seriously doubt that any AV vendor has taken the time to put a
definition into their product to specifically detect VB's code, I would
expect, since it used the same method as other exploits, that it's being
detected by that, which is what anyone would expect.

Serious doubts are no good to me; I need facts which speak for themselves.
So please provide proof of your statement that "since it used the same method as
other exploits, that it's being detected by that".
I will accept this as a fact when you have proved that it is a fact.
To prove it as a fact you need only give me one AV tool (virus scanner) which
detects the code I compiled myself as a virus/malware. My code uses exactly the
same method unless there's something seriously wrong with the compiler.
Also I'll want to know when the scanner first detected Volker's code by the
methods it uses instead of by signature alone. It's no good if that's today or
some future time.

Thank you for taking the time to find and provide proof that Volker's code is
being detected (by AV software) by the method it uses and not just a signature.

Have a nice day.

Jason



--

spam999free@xxxxxxxxxx
remove 999 in order to email me


.



Relevant Pages

  • Re: cDc prepares user-friendly stego app!
    ... > scan the webpage for stegged content using your signature and password. ... > it is more likely to have a virus -- which is simply stupid. ... > about a bunch of lies and innuendo just because you can. ...
    (comp.security.misc)
  • Re: Swen annoyances to everyone: wakeup call
    ... LiveUpdate on 9/19 and 9/20 it indicated no new signature ... >| many mail delivery failure messages can infect you. ... The Sobig.F virus was eventually (after ... >| Sobig.F (or the related mail delivery failure messages). ...
    (microsoft.public.security)
  • Re: Antivirus
    ... ceased to be amazed at the attitude some Windows users seem to have. ... call me in desperation upon having one of those programs let a virus through. ... signature, and hopefully you weren't infected by then. ... And you are at the whims of what the AV vendor defines as a threat. ...
    (Ubuntu)
  • Re: Obtaining a "Faux Virus"?
    ... virus but doesn't act like a virus ... That string was designed for exactly that purpose. ... and most AV programs will have the signature in their ... Dustin Cook [Malware Researcher] ...
    (alt.comp.anti-virus)
  • Re: Reducing Load on Amavisd-new/Spamassassin/Antivir
    ... > server and all the recipients would only have to check the signature. ... The idea is not that bad, to rely on a trusted central virus scanning ... The problem with your idea about tagging mail as clean is that "the bad ... legal statement: http://www.uni-x.org/legal.html Fedora Core 2 GNU/Linux on Athlon with kernel 2.6.10-1.14_FC2smp ...
    (Fedora)

Quantcast