a virus that defies current sandbox/virtualization programs

Hackers, get in and start your attacks...

Moderators: edifier, sbargay, tsahi1

a virus that defies current sandbox/virtualization programs

Postby zopzop on Tue May 23, 2006 7:03 pm

hello does bufferzone defend against the "killdisk" virus? the reason why i ask is, this virus was tested against vmware, sandoxie, and defensewall and they all could not stop it from infecting the MBR and wrecking the system.

edit:

i removed the link to the malware because a poster reminded me it's against the board guidelines. i will PM the link to the red team members.
zopzop
 
Posts: 27
Joined: Fri May 19, 2006 4:51 am

Killdisk virus

Postby Uriel on Sun May 28, 2006 9:37 am

Dear Zopzop and all,

I am happy to announce that after having tested this virus inside BufferZone, the only thing it does is post an unreadable error message, nothing more.

Sincerely,
Uriel Ginsburg
Uriel Ginsburg
BufferZone:Labs
Security through Virtualization

Image
Uriel
 
Posts: 19
Joined: Sat Sep 10, 2005 1:36 pm
Location: Israel

Postby zopzop on Sun May 28, 2006 1:49 pm

hello uriel, what version of bufferzone did you test it in: freeware, home (beta), or corporate (beta)? thanks
zopzop
 
Posts: 27
Joined: Fri May 19, 2006 4:51 am

Killdisk

Postby Uriel on Mon May 29, 2006 11:01 am

Hello, zopzop and all.

I have tested it with BufferZone HomePro v1.90-11. However, the protection scheme which prevents the Killdisk virus from working is common to the home and corporate versions.

Sincerely,
Uriel Ginsburg
Uriel Ginsburg
BufferZone:Labs
Security through Virtualization

Image
Uriel
 
Posts: 19
Joined: Sat Sep 10, 2005 1:36 pm
Location: Israel

Postby zopzop on Mon May 29, 2006 12:55 pm

thanks uriel, but can you tell me if the "Free" versions of bufferzone will defend against it? this is very important to know.
zopzop
 
Posts: 27
Joined: Fri May 19, 2006 4:51 am

BufferZone free version

Postby Uriel on Mon May 29, 2006 2:49 pm

Dear Zopzop,

That is a very important question. The answer is simply this: if you run BufferZone for Internet Explorer and you have downloaded the virus with Internet Explorer - BufferZone will protect against it. But if you run BufferZone for Internet Explorer and have downloaded the virus with eMule - BufferZone will absolutely NOT protect against it.

For short, BufferZone will protect against this virus, if you download it with an application already protected by BufferZone (Internet Explorer, P2P applications, eMail readers, etc.).

My advice, of course, is to have the complete version of BufferZone... :D

Sincerely,
Uriel Ginsburg.
Uriel Ginsburg
BufferZone:Labs
Security through Virtualization

Image
Uriel
 
Posts: 19
Joined: Sat Sep 10, 2005 1:36 pm
Location: Israel

Postby zopzop on Mon May 29, 2006 7:54 pm

thank you for that reply uriel. yes i agree with you, obviously the full version (home) of bufferzone will protect better. i was worried that if i ran internet explorer and some webpage tried a drive by download of malware like that virus, that i'd be protected. this is good to know. thanks again.
zopzop
 
Posts: 27
Joined: Fri May 19, 2006 4:51 am

Postby Guest on Mon Jun 19, 2006 12:46 pm

zopzop wrote:thank you for that reply uriel. yes i agree with you, obviously the full version (home) of bufferzone will protect better. i was worried that if i ran internet explorer and some webpage tried a drive by download of malware like that virus, that i'd be protected. this is good to know. thanks again.
Guest
 

repeat

Postby INSANE_ORACLE on Sun Feb 11, 2007 8:33 am

stop repeating the post what he said... hes right what he said
INSANE_ORACLE
 
Posts: 1
Joined: Sun Feb 11, 2007 8:24 am

Postby xaozon on Fri Feb 16, 2007 5:15 pm

Sorry for off-topic, but does it really bypass vmware? I find this hard to believe.
xaozon.echoz.com
xaozon
 
Posts: 28
Joined: Tue Jun 06, 2006 5:22 am

Postby zopzop on Sat Feb 17, 2007 12:03 am

@xaozon

yes it does (or it did as of the date i posted). if you want, i can PM you a link to the virus. but i warn you, you'd better try it on a test system. it will destroy your MBR and make all partitions and the information on them unrecoverable.
zopzop
 
Posts: 27
Joined: Fri May 19, 2006 4:51 am

Re: a virus that defies current sandbox/virtualization programs

Postby hamelame on Tue Nov 22, 2011 12:58 am

kindly sent me that link by PM !
hamelame
 
Posts: 2
Joined: Thu Nov 17, 2011 7:03 pm


Return to Red Team Attacks

Who is online

Users browsing this forum: No registered users and 0 guests

cron

Fatal error: Not able to open ./cache/data_global.php in /home/trustw5/public_html/forum/includes/acm/acm_file.php on line 107