republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies

bobince

join:2002-04-19
DE

reply to Smokey Bear

Re: Script fragmentation attacks to bypass anti-virus protection

Well yes, that would be one method of obfuscating exploit scripts. But there are already hundreds of ways of obfuscating exploits and the AVs are already hopeless at keeping up with them.

This attack does not render desktop and gateway anti-virus products useless. Because desktop and gateway anti-virus products have been useless for quite some time now.

bobince

join:2002-04-19
DE

reply to Anon

Re: Script fragmentation attacks to bypass anti-virus protection

JavaScript is a Turing-complete language. It's mathematically impossible to unwrap all possible forms of obfuscation, short of actually running the code in a JS interpreter. (At which point you may become vulnerable to the exploits themselves or non-halting logic bombs.)


jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
kudos:1

said by bobince:

JavaScript is a Turing-complete language. It's mathematically impossible to unwrap all possible forms of obfuscation, short of actually running the code in a JS interpreter. (At which point you may become vulnerable to the exploits themselves or non-halting logic bombs.)
This is true, but IIRC Symantec does have a script execution interrupt hook of some sort that blows the whistle whenever a script tries to touch a sensitive API call or something else suspicious looking. It might actually be pretty difficult to work around this.
--
Ubuntu MOTU Developer and Forums Council


Doobie

@dsl.tele.dk

reply to Anon

said by zteardrop:

I have tried many hundreds of obfuscation attacks using tools we have build inhouse...
You men at Symantec or at home? Have any data to back up that statement?

Thursday, 31-May 22:18:48 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics