Lincoln Computer Club  Forum
Username:   Password: 
Auto Login
  
Lincoln Computer Club Forum
Meet us at the Bailgate
 
 RegisterRegister 
It is currently Sun Sep 05, 2010 4:26 pm
All times are UTC + 1 Hour
An Internet Help Notice Board for all of Lincolnshire
Want to promote your Sports Club? Check out
www.sporting-lincs..com
--[Interesting Post--] New attack bypasses EVERY Windows security product


Users browsing this topic: 0 Registered, 0 Hidden and 1 Guest
Registered Users: None




View previous topic Printable versionDownload TopicPrivate MessagesRefresh page View next topic
Author Message
divingbrit
Site Admin

divingbrit is offline

↓  details
New attack bypasses EVERY Windows security product
Reply to topic Reply with quote Go to the bottom
PostPosted: Wed May 12, 2010 7:45 am Rate Post

Are you a Windows user? Do you make sure that your antivirus program is updated regularly? Do you feel safe? You shouldn’t! Read on to find out why …

Security researchers at Matousec.com have come up with an ingenious attack that can bypass every Windows security product tested and allow malicious code to make its way to your system.

Yes, you read that right - every Windows security product tested. And the list is both huge and sobering:

    * 3D EQSecure Professional Edition 4.2
    * avast! Internet Security 5.0.462
    * AVG Internet Security 9.0.791
    * Avira Premium Security Suite 10.0.0.536
    * BitDefender Total Security 2010 13.0.20.347
    * Blink Professional 4.6.1
    * CA Internet Security Suite Plus 2010 6.0.0.272
    * Comodo Internet Security Free 4.0.138377.779
    * DefenseWall Personal Firewall 3.00
    * Dr.Web Security Space Pro 6.0.0.03100
    * ESET Smart Security 4.2.35.3
    * F-Secure Internet Security 2010 10.00 build 246
    * G DATA TotalCare 2010
    * Kaspersky Internet Security 2010 9.0.0.736
    * KingSoft Personal Firewall 9 Plus 2009.05.07.70
    * Malware Defender 2.6.0
    * McAfee Total Protection 2010 10.0.580
    * Norman Security Suite PRO 8.0
    * Norton Internet Security 2010 17.5.0.127
    * Online Armor Premium 4.0.0.35
    * Online Solutions Security Suite 1.5.14905.0
    * Outpost Security Suite Pro 6.7.3.3063.452.0726
    * Outpost Security Suite Pro 7.0.3330.505.1221 BETA VERSION
    * Panda Internet Security 2010 15.01.00
    * PC Tools Firewall Plus 6.0.0.88
    * PrivateFirewall 7.0.20.37
    * Security Shield 2010 13.0.16.313
    * Sophos Endpoint Security and Control 9.0.5
    * ThreatFire 4.7.0.17
    * Trend Micro Internet Security Pro 2010 17.50.1647.0000
    * Vba32 Personal 3.12.12.4
    * VIPRE Antivirus Premium 4.0.3272
    * VirusBuster Internet Security Suite 3.2
    * Webroot Internet Security Essentials 6.1.0.145
    * ZoneAlarm Extreme Security 9.1.507.000
    * probably other versions of above mentioned software
    * possibly many other software products that use kernel hooks to implement security features

The attack is a clever “bait-and-switch” style move. Harmless code is passed to the security software for scanning, but as soon as it’s given the green light, it’s swapped for the malicious code. The attack works even more reliably on multi-core systems because one thread doesn’t keep an eye on other threads that are running simultaneously, making the switch easier.

The attack, called KHOBE (Kernel HOok Bypassing Engine), leverages a Windows module called the System Service Descriptor Table, or SSDT, which is hooked up to the Windows kernel. Unfortunately, SSDT is utilized by antivirus software.

source: news.zdnet.com
_________________
Divers do it deeper, would you agree AnonymousPosted image may have been reduced in size. Click image to view fullscreen.
checkout www.lincolnshire2012.com
Back to top See my Info Personal Gallery of divingbrit
divingbrit
Site Admin

divingbrit is offline

↓  details
Re: New attack bypasses EVERY Windows security product
Reply to topic Reply with quote Go to the bottom
PostPosted: Thu May 13, 2010 8:51 pm Rate Post

Lynn emailed Avast to get a comment

Quote:
> From: support@support.avast.com
> To: lynn
> Hello Lynn!
> Thank you for contacting ALWIL Software company with your concerns.
> My name is Michal and I am happy to assist you today.
>
> For a broader understanding of the problem, I'd recommend reading this thread:
> http://www.wilderssecurity.com/showthread.php?t=271968
> It's a long read, but describes the situation were well.
>
> Let me just add that the problem only affects systems that are already running the malicious code. It doesn't affect, in any way, the AV's ability to detect or block malware.
>
> If you need further assistance, don't hesitate to contact me again.
> Best regards
> Michal Zrubecky
> ALWIL Software a.s.


So to quote an old soldier
'Don't panic Mr Mannering! !!!!!!!!'.....................................yet
_________________
Divers do it deeper, would you agree AnonymousPosted image may have been reduced in size. Click image to view fullscreen.
checkout www.lincolnshire2012.com
Back to top See my Info Personal Gallery of divingbrit
Display posts from previous:   
   Board Index
   -> This Internet Board, News and Views
View previous topic Printable versionDownload TopicPrivate MessagesRefresh page View next topic

Page 1 of 1  [ 2 Posts ]
 


Jump to:   
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot post attachments in this forum
You can download attachments in this forum

Similar Topics
Topic Forum Author Replies Posted
No new posts Beta for Next Version of Microsoft Se... News and Views divingbrit 0 Thu Jul 22, 2010 6:24 am View latest post
No new posts What’s Taking So Long? How to Fight S... Windows 7 Discussion divingbrit 0 Fri Jun 11, 2010 12:04 pm View latest post
No new posts nLite allows you to customize your in... Tutorials divingbrit 0 Tue Jun 01, 2010 11:37 am View latest post
No new posts How To Burn your Windows 7 .ISO to DV... Tutorials divingbrit 1 Tue May 25, 2010 7:32 am View latest post
No new posts Download Windows 7 RTM Download Manager News and Views divingbrit 0 Sat May 22, 2010 6:58 am View latest post