funsec mailing list archives

Re: Get your computer viruses here!


From: Florian Weimer <fw () deneb enyo de>
Date: Wed, 28 Dec 2005 20:39:30 +0100

* Drsolly:

1.) It requires a login to access samples and the way its configured they
cant be downloaded automatically from worms, etc. (if someone finds a bug in
this let me know, ill fix it)

But Blackhat McNasty can create a login, and download everything he wants.

He can also fire up mwcollect or Nepenthes, with similar results.
Heck, he's probably able to get the source code of that malware, after
asking around a bit.  Since most malware has hard-coded C&C
functionality, the latter is the much better option.

I doubt a malware collection is *that* helpful for offensive purposes.
Sure, there might be some guys who think it's funny to send their
ex-girlfriends some piece of malware, but this is not the group of
evildoers I really care about.  The potential gains from information
sharing outweigh such risks, IMHO.
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: