funsec mailing list archives
Re: CME: A Total Failure -- Throw in the Towel
From: Drsolly <drsollyp () drsolly com>
Date: Mon, 13 Mar 2006 23:03:33 +0000 (GMT)
On Tue, 14 Mar 2006, Nick FitzGerald wrote:
Drsolly wrote:That's part of it. Are there any products today that do exact identification by checksumming the static bytes of the malware?Well, I'm sure some parts of what was once your engine still do that in at least some circumstnaces in the McAfee product today.
But is that product doing it for CME-24?
And I was always under the impression that Frisk's engine did this in at least some cases -- with most "old DOS" viruses and much macro malware being (nearly) exactly identified (i.e., as "exactly" as in your former engine).
But is that product doing it for CME-24? _______________________________________________ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.
Current thread:
- Re: CME: A Total Failure -- Throw in the Towel, (continued)
- Re: CME: A Total Failure -- Throw in the Towel Florian Weimer (Mar 11)
- Re: CME: A Total Failure -- Throw in the Towel Nick FitzGerald (Mar 11)
- Re: CME: A Total Failure -- Throw in the Towel Blue Boar (Mar 11)
- RE: CME: A Total Failure -- Throw in the Towel David Harley (Mar 11)
- RE: CME: A Total Failure -- Throw in the Towel Drsolly (Mar 12)
- Re: CME: A Total Failure -- Throw in the Towel Axel Pettinger (Mar 12)
- Re: CME: A Total Failure -- Throw in the Towel Drsolly (Mar 12)
- Re: CME: A Total Failure -- Throw in the Towel Blue Boar (Mar 12)
- Re: CME: A Total Failure -- Throw in the Towel Drsolly (Mar 13)
- Re: CME: A Total Failure -- Throw in the Towel Nick FitzGerald (Mar 13)
- Re: CME: A Total Failure -- Throw in the Towel Drsolly (Mar 13)
- Re: CME: A Total Failure -- Throw in the Towel Blue Boar (Mar 11)
- RE: CME: A Total Failure -- Throw in the Towel Nick FitzGerald (Mar 16)
- RE: CME: A Total Failure -- Throw in the Towel Drsolly (Mar 16)
- Re: CME: A Total Failure -- Throw in the Towel Nick FitzGerald (Mar 12)
- Re: CME: A Total Failure -- Throw in the Towel Nick FitzGerald (Mar 12)
- Virus Info Alliance == "new CME"?? (was: CME: A Total Failure) Young, Keith (Mar 12)
- Re: CME: A Total Failure -- Throw in the Towel Alexander Sotirov (Mar 12)