Full Disclosure mailing list archives
RE: Show me the Virrii!
From: "Elsner, Donald, ALABS" <elsner () att com>
Date: Tue, 6 Jan 2004 13:58:39 -0600
-----Original Message----- I like the idea of scanning for valid software. There are some problems with it that would need to be overcome, though: 1. Who makes the list, and keeps it updated? This would be a huge undertaking. ------------------- snip ----------------------------------- The U.S. Government is already doing this...... Please see National Software Reference Library (NSRL) (http://www.nsrl.nist.gov) Overview: The National Software Reference Library (NSRL) provides a repository of known software, file profiles, and file signatures for use by law enforcement and other organizations in computer forensics investigations. Industry Need Addressed: Investigation of computer files requires a tremendous effort to review individual files. A typical desktop computer contains between 10,000 and 100,000 files, each of which may need to be reviewed. Investigators need to eliminate as many known files as possible from having to be reviewed. An automated filter program can screen these files for specific profiles and signatures. If a specific file's profile and signature match the database of known files, then the file can be eliminated from review as a known file. Only those files that do not match would be subject to further investigation. In addition, investigators can search for files that are not what they claim to be (e.g., the file has the same name, size, and date of a common file, but not the same contents) or files that match a profile (e.g., hacking tools). _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- RE: Show me the Virrii!, (continued)
- RE: Show me the Virrii! Paul Niranjan (Jan 04)
- Re: Show me the Virrii! Simon Østengaard (Jan 05)
- Re: Show me the Virrii! Nick FitzGerald (Jan 07)
- Re: Show me the Virrii! Jason Coombs (Jan 05)
- Re: Show me the Virrii! S G Masood (Jan 07)
- Re: Show me the Virrii! Nick FitzGerald (Jan 07)
- Re: Show me the Virrii! Richard Maudsley (Jan 07)
- RE: Show me the Virrii! VBuster (Jan 05)
- RE: Show me the Virrii! Richard Gadsden (Jan 06)
- Re: Show me the Virrii! Donze, Erich (Jan 06)
- RE: Show me the Virrii! Elsner, Donald, ALABS (Jan 06)
- RE: Show me the Virrii! John LaCour (Jan 06)
- RE: Show me the Virrii! John . Airey (Jan 07)
- Re: Show me the Virrii! Exibar (Jan 07)
- Re: Show me the Virrii! michael williamson (Jan 07)
- Re: Show me the Virrii! Exibar (Jan 07)
- RE: [inbox] Re: Show me the Virrii! Curt Purdy (Jan 07)
- Re: [inbox] Re: Show me the Virrii! Exibar (Jan 07)
- Re: Show me the Virrii! Exibar (Jan 07)
- Re: Show me the Virrii! Exibar (Jan 07)