OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-disclosure] Sophos Antivirus Advisory

From: Morning Wood (se_cur_ityhotmail.com)
Date: Thu Jun 16 2005 - 09:04:57 CDT


> = Advisory: Sophos doesn't recognize keylogger after string alteration =
>

this technique is not new, and is quite commonly used to fool AV engines,
not just Sophos.
( and yes, Morphine works as well as commercial "executable packers")
If I recall, a certain trojan group ( now defunct ) used a simple string
change to change their standard releases to that of undetected versions they
sold ( for up to $300). I realy dont know why this is being reported here.

my2bits,
mw
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/