Author Topic: Downfalls of AntiVirus Software  (Read 285 times)

0 Members and 1 Guest are viewing this topic.

Online Axon

  • 0x1337
  • *****
  • Posts: 511
  • Karma: +49/-11
    • View Profile
Downfalls of AntiVirus Software
« on: February 14, 2012, 12:49:30 AM »
Anti-Virus Software detects viruses by searching an executable program for a specific signature; signatures are strings of code that the Anti-Virus Software considers malicious. This video describes how to locate this signature, and how to manipulate the executable’s assembly code so that the Anti-Virus Software does not flag the executable as a virus. We will modify a program called NetCat and edit its signature by changing NOP (No Operation) instructions to INT3 (software interrupt used by debuggers) instructions.


Credits: Override

Part 1
http://www.mediafire.com/download.php?hbag21fiwsx7orx

Part 2
http://www.mediafire.com/download.php?lyvbr3fb0ybyf97

Online ande

  • Administrator
  • 0x13338
  • *
  • Posts: 1421
  • Karma: +81/-7
  • Gender: Male
    • View Profile
    • Evilzone
Re: Downfalls of AntiVirus Software
« Reply #1 on: February 14, 2012, 01:17:52 AM »
If they are smaller than 30mb I do recommend you use upload.evilzone.org instead ;)

Online Axon

  • 0x1337
  • *****
  • Posts: 511
  • Karma: +49/-11
    • View Profile
Re: Downfalls of AntiVirus Software
« Reply #2 on: February 14, 2012, 01:19:58 AM »
If they are smaller than 30mb I do recommend you use upload.evilzone.org instead ;)

Unfortunately they are all > 30mb

Offline I_Learning_I

  • VIP
  • Short
  • *
  • Posts: 213
  • Karma: +18/-0
  • Gender: Male
  • Nor black or white, not even grey. What hat am I?
    • View Profile
    • Hacking F0r Fr33
Re: Downfalls of AntiVirus Software
« Reply #3 on: February 14, 2012, 09:20:44 AM »
Although this might be useful we cannot forget that AV do not work basing themselves ONLY in signatures.
AV's also analyze the way the program works, it's the "crawler" (that's not the correct name, cannot remember the right one).
So even though this works in many situations, if you copy another well known virus and run it, many AV's will still detect it.
Thanks for reading,
I_Learning_I


Online Axon

  • 0x1337
  • *****
  • Posts: 511
  • Karma: +49/-11
    • View Profile
Re: Downfalls of AntiVirus Software
« Reply #4 on: February 14, 2012, 10:36:59 AM »
Although this might be useful we cannot forget that AV do not work basing themselves ONLY in signatures.
AV's also analyze the way the program works, it's the "crawler" (that's not the correct name, cannot remember the right one).
So even though this works in many situations, if you copy another well known virus and run it, many AV's will still detect it.

Thank you for the input, am well aware of the various methods used by AV's to detect malicious files.
 
http://www.gohacking.com/2011/01/how-antivirus-software-works.html
 
This article explains it 

Offline I_Learning_I

  • VIP
  • Short
  • *
  • Posts: 213
  • Karma: +18/-0
  • Gender: Male
  • Nor black or white, not even grey. What hat am I?
    • View Profile
    • Hacking F0r Fr33
Re: Downfalls of AntiVirus Software
« Reply #5 on: February 14, 2012, 08:27:40 PM »
That's a good, simple, quick reading that should break it down. For that link ---> +1.
I would like to ask ande to consider make a pinned topic with this kind of links that show up every now in discussions that can be handy. They're not worth a post themselves, but with many like this would make a great repo.
Thanks for reading,
I_Learning_I


 



Intern0t SoldierX py1337 SecurityOverride programisiai
Want to be here? Contact Ande or Satan911 on the forum or at IRC.