funsec mailing list archives

Re: write viruses? it's controversy time of the month


From: Blue Boar <BlueBoar () thievco com>
Date: Tue, 29 Aug 2006 17:41:37 -0700

Dude VanWinkle wrote:
What if the viruses you create are programmed to only work on a
private IP range (10.254.127.0/24), or that expire after a certain
date (say 1 week).

Does that remove the unwanted moral hangups?

Most people in the AV industry would say that you created a variant, and now they might not detect it, and that's much worse (than spreading the original.)

Interestingly, I did pretty much exactly that with Nimda.A, in order to test a product I was developing. Afterwards, I thought I would be a good guy, and submit samples to the AV companies. I spelled out what I had done in the email.

I said something to the effect of "I made a variant of Nimda.A".

Most of the responses I got back were "That's a variant of Nimda.A. We detect it as 'Nimda.A'"

Uhh... thanks.

                                        BB
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: