Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

[Full-Disclosure] RE: On Polymorphic Evasion (an alphanumeric version)

Subject: [Full-Disclosure] RE: On Polymorphic Evasion (an alphanumeric version)
Date: Tue, 05 Oct 2004 01:39:15 +0000
Cool. I will also add to the discussion with an alphanumeric version written with two others for experimentation, though it is limited in it doesn't vary the length of the decoder stubs or encoded shellcode. spoonm is doing a separate version--I think based on Berend's alpha--that will. Also, I did not test it against any of the different shellcode detectors like Fnord, so I would be curious to know if anyone tries. IMO "as to whether the detection of polymorphic shellcode was indeed an appropriate component of an IDS", I think there is enough prior art on it that it's not really a big deal to publish or discuss code implementing it. It most likely better to have a variety of generators to test the effectiveness of a shellcode detector. I added a small blurb on addtional options for OS-independence with alphanumeric shellcode for IA-32e/AMD-64 since it adds the new RIP-relative addressing. See attachment.

"Phantasmal Phantasmagoria" <phantasmal@hush.ai>
10/01/2004 05:28 PM
Please respond to
phantasmal@hush.ai


To full-disclosure@lists.netsys.com, bugtraq@securityfocus.com, focus-ids@securityfocus.com cc

Subject
On Polymorphic Evasion






-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1

- ------------------------------------

On Polymorphic Evasion
by Phantasmal Phantasmagoria
phantasmal@hush.ai

_________________________________________________________________
On the road to retirement? Check out MSN Life Events for advice on how to get there! http://lifeevents.msn.com/category.aspx?cid=Retirement


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

<Prev in Thread] Current Thread [Next in Thread>
  • [Full-Disclosure] RE: On Polymorphic Evasion (an alphanumeric version), m conover <=