Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 11-05-2010, 05:23 AM   #1 (permalink)
Linoob
 
celldweller1591's Avatar
 
Join Date: Mar 2010
Location: ambala, haryana
Posts: 705
Default New attack bypasses virtually all AV protection


New attack bypasses virtually all AV protection

Researchers say they've devised a way to bypass protections built in to dozens of the most popular desktop anti-virus products, including those offered by McAfee, Trend Micro, AVG, and BitDefender.

The method, developed by software security researchers at matousec.com, works by exploiting the driver hooks the anti-virus programs bury deep inside the Windows operating system. In essence, it works by sending them a sample of benign code that passes their security checks and then, before it's executed, swaps it out with a malicious payload.

The exploit has to be timed just right so the benign code isn't switched too soon or too late. But for systems running on multicore processors, matousec's "argument-switch" attack is fairly reliable because one thread is often unable to keep track of other simultaneously running threads. As a result, the vast majority of malware protection offered for Windows PCs can be tricked into allowing malicious code that under normal conditions would be blocked.

All that's required is that the AV software use SSDT, or System Service Descriptor Table, hooks to modify parts of the OS kernel.

"We have performed tests with [most of] today's Windows desktop security products," the researchers wrote. "The results can be summarized in one sentence: If a product uses SSDT hooks or other kind of kernel mode hooks on similar level to implement security features it is vulnerable. In other words, 100% of the tested products were found vulnerable."

The researchers listed 34 products that they said were susceptible to the attack, but the list was limited by the amount of time they had for testing. "Otherwise, the list would be endless," they said.

The technique works even when Windows is running under an account with limited privileges.

Still, the exploit has its limitations. It requires a large amount of code to be loaded onto the targeted machine, making it impractical for shellcode-based attacks or attacks that rely on speed and stealth. It can also be carried out only when an attacker already has the ability to run a binary on the targeted PC.

Still, the technique might be combined with an exploit of another piece of software, say, a vulnerable version of Adobe Reader or Oracle's Java Virtual Machine to install malware without arousing the suspicion of the any AV software the victim was using.

"Realistic scenario: someone uses McAfee or another affected product to secure their desktops," H D Moore, CSO and Chief Architect of the Metasploit project, told The Register in an instant message. "A malware developer abuses this race condition to bypass the system call hooks, allowing the malware to install itself and remove McAfee. In that case, all of the 'protection' offered by the product is basically moot."

A user without administrative rights could also use the attack to kill an installed and running AV, even though only admin accounts should be able to do this, Charlie Miller, principal security analyst at Independent Security Evaluators, said.

Matousec.com's research is here.
__________________
root@Celldweller#ping www.linoob.com

Ubuntu User # 31222
Linux User # 516252
celldweller1591 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 11-05-2010, 03:16 PM   #2 (permalink)
Alpha Geek
 
CA50's Avatar
 
Join Date: May 2007
Location: GraveYard
Posts: 918
Default Re: New attack bypasses virtually all AV protection

Eekkk...:O :*
Thanks for sharing, thats an important piece of info
__________________
| A Bit IP35-Pro | E8400 | GTS250 | Gskill 2x2GB | 1.9 TB | CM EP+ 460W | 2x DVD-RW|
| Win XP x86 | Win 7 Ult x86 | LinuxMint |
| Nokia 2700c |
CA50 is offline  
Old 11-05-2010, 05:58 PM   #3 (permalink)
Linoob
 
celldweller1591's Avatar
 
Join Date: Mar 2010
Location: ambala, haryana
Posts: 705
Default Re: New attack bypasses virtually all AV protection

hmm..i was shocked too thats why i prefer linux safe and easy .
__________________
root@Celldweller#ping www.linoob.com

Ubuntu User # 31222
Linux User # 516252
celldweller1591 is offline  
Old 11-05-2010, 08:23 PM   #4 (permalink)
Alpha Geek
 
CA50's Avatar
 
Join Date: May 2007
Location: GraveYard
Posts: 918
Default Re: New attack bypasses virtually all AV protection

Maybe someday people will say that linux is unsafe and they will ask for a better os.
__________________
| A Bit IP35-Pro | E8400 | GTS250 | Gskill 2x2GB | 1.9 TB | CM EP+ 460W | 2x DVD-RW|
| Win XP x86 | Win 7 Ult x86 | LinuxMint |
| Nokia 2700c |
CA50 is offline  
Old 11-05-2010, 09:03 PM   #5 (permalink)
Married!
 
Rahim's Avatar
 
Join Date: Apr 2007
Location: Calcutta
Posts: 1,524
Default Re: New attack bypasses virtually all AV protection

^I would say "safer" as compared to other OSes.
__________________
|| GNU/Linux User || PCLOS KDE 4.6 || 17" DELL Studio ||

topdocumentaryfilms.com
Rahim is offline  
Old 11-05-2010, 09:18 PM   #6 (permalink)
Linoob
 
celldweller1591's Avatar
 
Join Date: Mar 2010
Location: ambala, haryana
Posts: 705
Default Re: New attack bypasses virtually all AV protection

Quote:
Originally Posted by a_rahim View Post
^I would say "safer" as compared to other OSes.
+1 to that !
__________________
root@Celldweller#ping www.linoob.com

Ubuntu User # 31222
Linux User # 516252
celldweller1591 is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Audio CD Protection rohanmathew Software Q&A 34 06-07-2010 08:48 AM
Is it worth taking Dell Service: Hardware Maintenance Accidental Damage Protection mack1983 Mobiles and Tablets 10 03-05-2010 08:39 PM
Symantec Endpoint Protection or Microsoft Security Essentials ? aQi_g Reviews 3 14-04-2010 12:16 PM
Make Copy Protected CD khattam_ Tutorials 37 17-02-2007 11:59 PM
TCP/IP attack: read to protect anomit QnA (read only) 1 05-05-2005 01:25 PM

 
Latest Threads
- by Charan
- by gforz
- by abhidev

Advertisement




All times are GMT +5.5. The time now is 12:18 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2