Full Disclosure mailing list archives
Re: Sophos Antivirus Advisory
From: "Morning Wood" <se_cur_ity () hotmail com>
Date: Thu, 16 Jun 2005 07:04:57 -0700
= Advisory: Sophos doesn't recognize keylogger after string alteration =
this technique is not new, and is quite commonly used to fool AV engines, not just Sophos. ( and yes, Morphine works as well as commercial "executable packers") If I recall, a certain trojan group ( now defunct ) used a simple string change to change their standard releases to that of undetected versions they sold ( for up to $300). I realy dont know why this is being reported here. my2bits, mw _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Sophos Antivirus Advisory patrickhof (Jun 16)
- Re: Sophos Antivirus Advisory class (Jun 16)
- Re: Sophos Antivirus Advisory Robert Perriero (Jun 16)
- Re: Sophos Antivirus Advisory class (Jun 16)
- Re: Sophos Antivirus Advisory Robert Perriero (Jun 16)
- Re: Sophos Antivirus Advisory Morning Wood (Jun 16)
- <Possible follow-ups>
- RE: Sophos Antivirus Advisory Todd Towles (Jun 16)
- Re: Sophos Antivirus Advisory class (Jun 16)
