Full Disclosure mailing list archives
RE: when will AV vendors fix this???
From: "Thomas D." <whistl0r () googlemail com>
Date: Mon, 7 Aug 2006 20:20:03 +0200
-----Original Message----- From: Bipin Gautam Sent: Saturday, August 05, 2006 9:21 AM Subject: when will AV vendors fix this??? to keep things simple, let me give you a situation; if there is a directory/file a EVIL_USER is willing to hide from antivirus scanner all he has to do is fire up a command prompt & run the command; cacls.exe TORJANED_FILE_OR_DIRECTORY_NAME /T /C /P EVIL_USER:R next time EVEN when the administrator starts the antivirus "system scan" the TORJANED_FILE_OR_DIRECTORY_NAME will be effectively bypassed as the ownership of the directory is just of the user account named; EVIL_USER and the antivirus "manual scan" is running just with the privilage of ADMINISTRATOR> by this way a malicious executable can remain hidden in the system BYPASSING THE SCAN even when the AV scanner is run by administrator!!!
But I cannot execute this file, becaus I have no access. If I get access, the anti-virus program will also get access... So I might be able hide something, but I can't do anything. Also, to hide something, I have to bypass the autoprotection... You shouldn't be able to do this... -- Whistl0r _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- when will AV vendors fix this??? Bipin Gautam (Aug 05)
- Re: when will AV vendors fix this??? Denis Jedig (Aug 05)
- Re: Re: when will AV vendors fix this??? <...> (Aug 06)
- Re: when will AV vendors fix this??? Marius Huse Jacobsen (Aug 07)
- Re: when will AV vendors fix this??? Bryan (Aug 07)
- RE: when will AV vendors fix this??? Thomas D. (Aug 07)
- Re: RE: when will AV vendors fix this??? Dude VanWinkle (Aug 07)
- RE: RE: when will AV vendors fix this??? Thomas D. (Aug 07)
- RE: RE: when will AV vendors fix this??? Dmitry Yu. Bolkhovityanov (Aug 11)
- Re: RE: when will AV vendors fix this??? Paul Schmehl (Aug 14)
- Re: RE: when will AV vendors fix this??? Bipin Gautam (Aug 15)
- Re: RE: when will AV vendors fix this??? Dude VanWinkle (Aug 07)
- Re: when will AV vendors fix this??? Denis Jedig (Aug 05)
- Re: when will AV vendors fix this??? Bipin Gautam (Aug 07)
- <Possible follow-ups>
- Re: Re: when will AV vendors fix this??? hatless (Aug 06)
- Re: when will AV vendors fix this??? Andreas Marx (Aug 14)