 jdongEat A Beaver, Save A Tree.Premium join:2002-07-09 Rochester, MI kudos:1 | reply to bobince
Re: Script fragmentation attacks to bypass anti-virus protection said by bobince:JavaScript is a Turing-complete language. It's mathematically impossible to unwrap all possible forms of obfuscation, short of actually running the code in a JS interpreter. (At which point you may become vulnerable to the exploits themselves or non-halting logic bombs.) This is true, but IIRC Symantec does have a script execution interrupt hook of some sort that blows the whistle whenever a script tries to touch a sensitive API call or something else suspicious looking. It might actually be pretty difficult to work around this. -- Ubuntu MOTU Developer and Forums Council |