Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-Disclosure] Re: Bypass of 22 Antivirus software with GDI+ bug exploit Mutations - part 2 |
|---|---|
| Date: | Sat, 05 Mar 2005 13:05:55 +0100 |
Andrey Bayora wrote:
The first part is here: http://archives.neohapsis.com/archives/fulldisclosure/2004-10/0475.html
First, this post isn’t about “how dangerous GDI+ bug or malicious JPEG image”, but “how good” is your antivirus software.
The issue is: only 1 out of 23 tested antivirus software can detect malicious JPEG image (after 6 month from the public disclosure date).
Here is the link to results, JPEG file and my paper (GCIH practical) that describes how to create this one: http://www.hiddenbit.org/jpeg.htm
This one vendor (Symantec) that can detect it, obviously do it with the “heuristic” detection (I don’t work for them and didn’t send them any file, moreover I know cases when Symantec didn’t detect a virus that “other” vendors do). ClamAV antivirus detected this JPEG file 4 month ago, but strangely can’t detect it now. What happened? What about 22 antivirus software vendors that miss this malicious JPEG? The pattern or problem in these JPEG files is known and still many antivirus software vendors miss it, did it can represent the quality of heuristic engines?
OK, we know that any antivirus software can provide 100% protection…
P.S. After my first post (October 14,2004) about this problem – all antivirus software vendors added detection to the demo file provided by me in couple of hours. Sadly for me, but it seems that they prefer “playing cat and mouse” and not improve heuristic engines…
Regards, Andrey Bayora. CISSP, GCIH
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-Disclosure] Eiríkur Eiríksson/Símstöðvad/Fjarsknet/Síminn is out of the office., Eiríkur Eiríksson |
|---|---|
| Next by Date: | [Full-Disclosure] [HAT-SQUAD] new exploit code, class 101 |
| Previous by Thread: | [Full-Disclosure] Bypass of 22 Antivirus software with GDI+ bug exploit Mutations - part 2, Andrey Bayora |
| Next by Thread: | Re: [Full-Disclosure] Bypass of 22 Antivirus software with GDI+ bug exploit Mutations - part 2, Trog |
| Indexes: | [Date] [Thread] [Top] [All Lists] |