Full Disclosure mailing list archives
Re: RE: when will AV vendors fix this???
From: "Dude VanWinkle" <dudevanwinkle () gmail com>
Date: Mon, 7 Aug 2006 14:48:51 -0400
On 8/7/06, Thomas D. <whistl0r () googlemail com> wrote:
> -----Original Message----- > From: Bipin Gautam > Sent: Saturday, August 05, 2006 9:21 AM > Subject: when will AV vendors fix this??? > > to keep things simple, let me give you a situation; > > if there is a directory/file a EVIL_USER is willing to hide from > antivirus scanner all he has to do is fire up a command prompt & run > the command; > > cacls.exe TORJANED_FILE_OR_DIRECTORY_NAME /T /C /P EVIL_USER:R > > > next time EVEN when the administrator starts the antivirus "system > scan" the TORJANED_FILE_OR_DIRECTORY_NAME will be effectively > bypassed as the ownership of the directory is just of the user account > named; EVIL_USER and the antivirus "manual scan" is running just with > the privilage of ADMINISTRATOR> > > by this way a malicious executable can remain hidden in the system > BYPASSING THE SCAN even when the AV scanner is run by administrator!!! But I cannot execute this file, becaus I have no access. If I get access, the anti-virus program will also get access... So I might be able hide something, but I can't do anything.
Well, there would be an access denied message for most AV scanners when it hit the file in question and couldnt even get a read. -JP _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- when will AV vendors fix this??? Bipin Gautam (Aug 05)
- Re: when will AV vendors fix this??? Denis Jedig (Aug 05)
- Re: Re: when will AV vendors fix this??? <...> (Aug 06)
- Re: when will AV vendors fix this??? Marius Huse Jacobsen (Aug 07)
- Re: when will AV vendors fix this??? Bryan (Aug 07)
- RE: when will AV vendors fix this??? Thomas D. (Aug 07)
- Re: RE: when will AV vendors fix this??? Dude VanWinkle (Aug 07)
- RE: RE: when will AV vendors fix this??? Thomas D. (Aug 07)
- RE: RE: when will AV vendors fix this??? Dmitry Yu. Bolkhovityanov (Aug 11)
- Re: RE: when will AV vendors fix this??? Paul Schmehl (Aug 14)
- Re: RE: when will AV vendors fix this??? Bipin Gautam (Aug 15)
- Re: RE: when will AV vendors fix this??? Dude VanWinkle (Aug 07)
- Re: when will AV vendors fix this??? Denis Jedig (Aug 05)
- Re: when will AV vendors fix this??? Bipin Gautam (Aug 07)
- <Possible follow-ups>
- Re: Re: when will AV vendors fix this??? hatless (Aug 06)
- Re: when will AV vendors fix this??? Andreas Marx (Aug 14)