Full Disclosure mailing list archives
RE: Backdoor not recognized by Kaspersky
From: "Jos Osborne" <Jos () meltemi co uk>
Date: Wed, 3 Mar 2004 15:29:49 -0000
Does anyone else find this new development a bad idea? I'm of the mindset that anti-virus companies should stick with what they're good at -- namely, detecting and handling infected files. It seems a bad idea to start down the natural language processing road. Are they scanning just for Bagle/Beagle style e-mail, or are their methods more general? What about messages of the form: 'Password is a long yellow fruit enjoyed by monkeys.'
IMHO, anybody who actually thinks for a second of unzipping an attachment with that kind of message is straying into AskingForItland. Even better how about: 'Password is a long yellow fruit enjoyed by monkeys. FALSE Password: 22103' So the Av software scans the Zip as perfectly safe, and informs the user that all is well.
What about messages in languages other than English? I can easily see this becoming an arms-race, and one the anti-virus folks have no chance of winning.
What about "compression bombs"? Trying to add another task is just opening another vulnerability. Jos _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: Backdoor not recognized by Kaspersky, (continued)
- Re: Backdoor not recognized by Kaspersky Michael Gale (Mar 03)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- SMTP open relays and RFC (was: Backdoor not recognized by Kaspersky) Martin Mačok (Mar 04)
- Message not available
- Re: Backdoor not recognized by Kaspersky Rodrigo Barbosa (Mar 04)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- Re: Backdoor not recognized by Kaspersky Alexander MacLennan (Mar 03)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- SMTP rejecting wrong HELO/EHLO domains will save the world (was: Backdoor in passworded ZIP not recognized by Kaspersky) Martin Mačok (Mar 03)
- Re: Backdoor not recognized by Kaspersky Valdis . Kletnieks (Mar 04)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- Re: Backdoor not recognized by Kaspersky Cael Abal (Mar 03)
- Re: Backdoor not recognized by Kaspersky Stef (Mar 03)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- RE: Backdoor not recognized by Kaspersky Rob Rosenberger (Mar 03)
- RE: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- Re[2]: Backdoor not recognized by Kaspersky Simbabque (Mar 03)