Reply to topic  [ 11 posts ] 
Windows XP exploit bypasses AV 
Author Message
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
http://www.zdnet.com/blog/hardware/upda ... oduct/8268

Ouch!

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Tue May 11, 2010 1:36 pm
Profile ICQ
Site Admin
User avatar

Joined: Thu Apr 23, 2009 5:53 pm
Posts: 8603
Location: location, location
Reply with quote
Interesting. Symantic Endpoint wasn't tested.

_________________
Support X404, use our Amazon link
Get your X404 tat here
jonlumb wrote:
I've only ever done it with a chicken so far, but if required I wouldn't have any problems doing it with other animals at all.


Tue May 11, 2010 2:24 pm
Profile WWW
What's a life?
User avatar

Joined: Thu Apr 23, 2009 7:56 pm
Posts: 12030
Reply with quote
saspro wrote:
Interesting. Symantic Endpoint wasn't tested.


Is that different to the Sophos Endpoint Security and Control 9.0.5 mentioned on that list?

_________________
www.alexsmall.co.uk

Charlie Brooker wrote:
Windows works for me. But I'd never recommend it to anybody else, ever.


Tue May 11, 2010 6:55 pm
Profile
I haven't seen my friends in so long
User avatar

Joined: Thu Jun 18, 2009 5:10 pm
Posts: 5836
Reply with quote
:shock:

The One vulnerability to rule them all.

Ouchies

_________________
Jim

Image


Tue May 11, 2010 9:08 pm
Profile
Spends far too much time on here
User avatar

Joined: Thu Apr 23, 2009 11:36 pm
Posts: 3527
Location: Portsmouth
Reply with quote
So is this a bug in the AV software, or Windows?

_________________
Image


Tue May 11, 2010 9:47 pm
Profile
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 6:58 pm
Posts: 8767
Location: behind the sofa
Reply with quote
Sophos wrote:
So the Khobe "attack" boils down to this: if you can write malware which already gets past Sophos's on-access virus blocker, and past Sophos's HIPS, then you may be able to use the Khobe code to bypass Sophos's HIPS - which, of course, you just bypassed anyway.

While it is indeed a clever trick, I think the headline is a little OTT.

_________________
jonbwfc's law: "In any forum thread someone will, no matter what the subject, mention Firefly."

When you're feeling too silly for x404, youRwired.net


Tue May 11, 2010 9:50 pm
Profile WWW
Site Admin
User avatar

Joined: Thu Apr 23, 2009 5:53 pm
Posts: 8603
Location: location, location
Reply with quote
ProfessorF wrote:
saspro wrote:
Interesting. Symantic Endpoint wasn't tested.


Is that different to the Sophos Endpoint Security and Control 9.0.5 mentioned on that list?


One's made by Symantec, the other by Sophos. Similar names, very different products.

_________________
Support X404, use our Amazon link
Get your X404 tat here
jonlumb wrote:
I've only ever done it with a chicken so far, but if required I wouldn't have any problems doing it with other animals at all.


Wed May 12, 2010 10:06 am
Profile WWW
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
Nick wrote:
So is this a bug in the AV software, or Windows?

It is a flaw in Windows, which will allow you to circumvent the AV software - if you can get past the AV software in the first place... :?

I agree with JJW, it is overblown, although it is a serious problem.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Wed May 12, 2010 10:53 am
Profile ICQ
Legend
User avatar

Joined: Fri Apr 24, 2009 2:02 am
Posts: 29240
Location: Guantanamo Bay (thanks bobbdobbs)
Reply with quote
JJW009 wrote:
Sophos wrote:
So the Khobe "attack" boils down to this: if you can write malware which already gets past Sophos's on-access virus blocker, and past Sophos's HIPS, then you may be able to use the Khobe code to bypass Sophos's HIPS - which, of course, you just bypassed anyway.

While it is indeed a clever trick, I think the headline is a little OTT.

Agreed, but is it possible to attack OSX and linux this way?

_________________
Do concentrate, 007...

"You are gifted. Mine is bordering on seven seconds."

https://www.dropbox.com/referrals/NTg5MzczNTk

http://astore.amazon.co.uk/wwwx404couk-21


Wed May 12, 2010 12:43 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
Amnesia10 wrote:
JJW009 wrote:
Sophos wrote:
So the Khobe "attack" boils down to this: if you can write malware which already gets past Sophos's on-access virus blocker, and past Sophos's HIPS, then you may be able to use the Khobe code to bypass Sophos's HIPS - which, of course, you just bypassed anyway.

While it is indeed a clever trick, I think the headline is a little OTT.

Agreed, but is it possible to attack OSX and linux this way?

Theoretically, yes...

But it is pretty moot, because most *NIX machines aren't running AV software, so you don't need to bypass it...

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Wed May 12, 2010 1:07 pm
Profile ICQ
I haven't seen my friends in so long
User avatar

Joined: Thu Apr 23, 2009 7:10 pm
Posts: 5490
Location: just behind you!
Reply with quote
Only xp.. oh well, it wont affect my systems then :lol:

_________________
johnwbfc wrote:
I care not which way round it is as long as at some point some sort of semi-naked wrestling is involved.

Amnesia10 wrote:
Yes but the opportunity to legally kill someone with a giant dildo does not happen every day.

Finally joined Flickr


Wed May 12, 2010 1:39 pm
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 11 posts ] 

Who is online

Users browsing this forum: No registered users and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.