Welcome, Guest. Please login or register.
July 24, 2008, 07:53:27 AM

Login with username, password and session length

176651 Posts
20891 Topics
50680 Members

Latest Member: romeo

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Melih's Corner - CEO Talk/Discussions/Blog
| | |-+  Botnets! Ever increasing Threat!!
« previous next »
Pages: 1 ... 4 5 [6] Go Down Print
Author Topic: Botnets! Ever increasing Threat!!  (Read 10499 times)
Little Mac
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6003



« Reply #75 on: February 06, 2008, 09:29:50 PM »

I think this idea is part of what Comodo is doing when users use the file submission process.  They analyze and create the signature for it.  Not sure the format of the signature, but even if it were something as "simple" as an md5 hash, the odds of there being an illegitimate match are 2128 against.  Go to some other stronger crypto sig and the odds go even higher.  If you wonder how big that number is, put it in a scientific calculator...  Wink

LM
Logged

date
dcfldd split=2G conv=noerror hashwindow=0 hash=md5 hashlog=/mnt/sda1/images/hash.log if=/dev/hda of=/mnt/sda1/images/LM.dd
date
cat LM.dd.* | md5sum > verify.log
date
Burillo
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 324


Bunghole


« Reply #76 on: February 07, 2008, 06:47:06 AM »

you can't hash polymorphic and metamorphic viruses since they always change their contents :-)))
Logged

Some people are dumb... (c) Butt-head

Remember! CIA is watching you!
venom_zx
Newbie
*
Offline Offline

Posts: 8


« Reply #77 on: February 07, 2008, 09:31:44 AM »

[ at ]Burillo
well the idea was that if the hash was not recognizable, the program would be seen as suspect.

[ at ]gibran
but i guess it's true that programs can be exploited while running ( forgot about that ). well i thought that atleast, more detailed messages could be avoided for users that don't get those.

behavioural fingerprinting sounds more in the direction of leak protection or possible virus scanners.

yea, if software authors made a behavioural signature and code signature. then it would make it even harder to exploit. first exploits would have to be found where these signatures can't change. but programs with plugins might have some pretty varried behaviour.

but i guess it's always nice to not fully have to trust applications.
« Last Edit: February 07, 2008, 09:33:19 AM by venom_zx » Logged
Tags:
Pages: 1 ... 4 5 [6] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.098 seconds with 18 queries.
Powered by SMF 1.1.5 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com