Full Disclosure mailing list archives

Re: Rutkowska faces '100% undetectable malware' challenge, teasing?


From: "Peter Ferrie" <pferrie () symantec com>
Date: Sat, 30 Jun 2007 23:04:24 -0700

The problem is that she wants the money upfront, in order to develop the 100% undetectable thing that she doesn't have 
right now.  So that's a problem.
 

________________________________

From: full-disclosure-bounces () lists grok org uk on behalf of Trey Keifer
Sent: Sat 6/30/2007 1:39 PM
To: Bipin Gautam
Cc: full-disclosure () lists grok org uk
Subject: Re: [Full-disclosure]Rutkowska faces '100% undetectable malware' challenge, teasing?


Joanna has stated her technical requirements for the challenge and Thom and group has accepted them, so why not turn 
this into what it really is... a bet.

The losing team agrees to pay the other $350,000 - if both groups are really so confident there shouldn't be any issue. 




On 6/30/07, Bipin Gautam <gautam.bipin () gmail com> wrote: 

        hi guys,
        
        ref: http://blogs.zdnet.com/security/?p=334
        
        so are they teasing by making her the impossible challenge at this date? :)
        
        honeypot developers have been trying to battle the same issue of 
        making the virtual machine emulate guest OS like the it is run in real
        hardware since some years now.
        
        ref: http://handlers.sans.org/tliston/ThwartingVMDetection_Liston_Skoudis.pdf 
        
        But if Rutkowska or anyone is able to succeed to make it undetectable
        in current hardware that would be genius!
        
        -bipin
        
        _______________________________________________
        Full-Disclosure - We believe in it. 
        Charter: http://lists.grok.org.uk/full-disclosure-charter.html
        Hosted and sponsored by Secunia - http://secunia.com/ 
        


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: