Focus on Microsoft
More along the lines of malware disinfection Mar 18 2008 01:33PM
Mike Moratz-Coppins (mike mikeymike org uk) (3 replies)
RE: More along the lines of malware disinfection Mar 18 2008 06:08PM
Express Web Systems, Inc. (mailinglist expresshosting net) (1 replies)
Re: More along the lines of malware disinfection Mar 18 2008 06:28PM
Mike Moratz-Coppins (mike mikeymike org uk) (1 replies)
RE: More along the lines of malware disinfection Mar 28 2008 01:46AM
Murda Mcloud (murdamcloud bigpond com)
RE: More along the lines of malware disinfection Mar 18 2008 05:46PM
Devin Ganger (DevinG 3sharp com)
Re: More along the lines of malware disinfection Mar 18 2008 05:46PM
Jon R. Kibler (Jon Kibler aset com) (3 replies)
RE: More along the lines of malware disinfection Mar 18 2008 07:57PM
Wayne S. Anderson (wfrazee wynweb net) (2 replies)
RE: More along the lines of malware disinfection Mar 18 2008 09:07PM
Monahan, Jim (MONAHAJ ccf org)
Re: More along the lines of malware disinfection Mar 18 2008 08:56PM
Mike Moratz-Coppins (mike mikeymike org uk) (3 replies)
Re: More along the lines of malware disinfection Mar 19 2008 04:03PM
Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net) (1 replies)
Re: More along the lines of malware disinfection Mar 19 2008 05:31PM
Mike Moratz-Coppins (mike mikeymike org uk) (2 replies)
Re: More along the lines of malware disinfection Mar 20 2008 09:21AM
Vincent Archer (archer tms frmug org)
Re: More along the lines of malware disinfection Mar 19 2008 08:33PM
Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net) (2 replies)
RE: More along the lines of malware disinfection Mar 19 2008 11:21PM
Mark Brunner (mark_brunner hotmail com) (1 replies)
RE: More along the lines of malware disinfection Mar 28 2008 02:22AM
Murda Mcloud (murdamcloud bigpond com)
Re: More along the lines of malware disinfection Mar 19 2008 09:12PM
Mike Moratz-Coppins (mike mikeymike org uk) (3 replies)
Re: More along the lines of malware disinfection Mar 23 2008 01:06AM
pinowudi (pinowudi gmail com)
RE: More along the lines of malware disinfection Mar 20 2008 08:34AM
John Lightfoot (jlightfoot gmail com) (1 replies)
Re: More along the lines of malware disinfection Mar 20 2008 04:54PM
Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net) (1 replies)
On 2008-03-20 John Lightfoot wrote:
> I agree with Mike.

Then you failed to understand the problem.

> While it's true that you can never be absolutely certain that a system
> is safe once it has been compromised by malware, if you're able to
> identify the infection or at least the attack vector, chances are
> pretty good that you can eliminate the problem and secure your system
> without a total re-wipe.

Correct. IF you can identify the infection vector AND the infection time
AND all modifications that were done afterwards. Then (and only then)
you an avoid re-installing the system.

> I use antivirus software, a software firewall, Windows Defender and my
> router to protect my home network, but occasionally my kids download a
> questionable toolbar from a game site.

So? Don't give them admin privileges. Problem solved.

> If I Google for a script to get rid of it, I feel quite confident that
> the malware ended there.

This confidence is entirely unsubstantiated.

- Even though your tools identified the malware as "X", it may be a (yet
unknown) variant "Xa", which is sufficiently different from malware
"X" to render your script useless.
- In case malware "X" opened a backdoor (there are various ways to do
that even through a firewall) or loaded additional code after being
executed, your script may remove malware "X", but leave the additional
malware "Y" untouched.
- Unless you know exactly how malware "X" works even auditing the script
won't tell you whether it will actually remove the infection entirely.
- Unless you audit the script first, you may just have installed another
malware by running it.
...

> If the antivirus, antispyware, firewalls and logs don't turn up
> anything, the 100% undetectable rootkit the malware installed doesn't
> concern me very much, and if you're worried about a 100% undetectable
> rootkit you should probably be worried about the 100% undetectable
> 0-day attack vector it's already used to install itself on your
> computer.

Unless the tools you use have 100% detection rate (which they don't),
the rootkit doesn't need to be 100% undetectable.

What you and Mike keep ignoring is, that in one case there was an actual
infection vector, whereas in the other case there wasn't (no, your
hypthetical 0-day attack does not count unless you can show an actual
attack vector).

> Maybe that's leaving my computers as potential spam-bots, but what are the
> chances of that? 1%? .01%? .0000000001%? What's an acceptable risk vs.
> the cost of rebuilding from scratch?

Do you have any numbers do base your calculation on? Unless you do, the
risk may be 0.001% as well as 99.999%. Meaning there is no such thing as
an "acceptable risk".

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

[ reply ]
Re: More along the lines of malware disinfection Mar 23 2008 04:26AM
pinowudi (pinowudi gmail com)
Re: More along the lines of malware disinfection Mar 20 2008 12:41AM
Geekwench (geekwench hotmail com)
RE: More along the lines of malware disinfection Mar 18 2008 11:55PM
Devin Ganger (DevinG 3sharp com)
RE: More along the lines of malware disinfection Mar 18 2008 11:31PM
Wayne S. Anderson (wfrazee wynweb net)
Re: More along the lines of malware disinfection Mar 18 2008 07:26PM
M Lists (m-lists lucretia ca)
Re: More along the lines of malware disinfection Mar 18 2008 06:26PM
Mike Moratz-Coppins (mike mikeymike org uk) (2 replies)
RE: More along the lines of malware disinfection Mar 19 2008 01:39PM
Devin Ganger (DevinG 3sharp com)
Re: More along the lines of malware disinfection Mar 18 2008 09:51PM
Colin Copley (colin 75 btinternet com) (1 replies)
RE: More along the lines of malware disinfection Mar 28 2008 01:55AM
Murda Mcloud (murdamcloud bigpond com)


 

Privacy Statement
Copyright 2010, SecurityFocus