[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-disclosure] KHOBE - 8.0 earthquake for Windows desktop security software
- To: Juha-Matti Laurio <juha-matti.laurio@xxxxxxxx>
- Subject: Re: [Full-disclosure] KHOBE - 8.0 earthquake for Windows desktop security software
- From: Marsh Ray <marsh@xxxxxxxxxxxxxxxxxx>
- Date: Thu, 13 May 2010 16:06:19 -0500
Nice research! Thanks hmatousec.com for putting up the hard work of
testing all those products.
Anyone else notice the connection with the Systrace badness from a while
back?
http://www.watson.org/~robert/2007woot/
'Exploiting Concurrency Vulnerabilities in System Call Wrappers'
Perhaps Windows AV developers need to get out more.
- Marsh
On 5/13/2010 3:04 PM, Juha-Matti Laurio wrote:
> Some AV vendors have posted their 'is-the-game-over-or-not' type
> response.
>
> F-Secure: http://www.f-secure.com/weblog/archives/00001949.html
>
> Trend:
> http://countermeasures.trendmicro.eu/you-just-cant-trust-a-drunk/
>
> Sophos:
> http://www.sophos.com/blogs/gc/g/2010/05/11/khobe-vulnerability-game-security-software/
>
> ESET:
> http://www.eset.com/blog/2010/05/11/khobe-wan-these-arent-the-droids-youre-looking-for
>
> Juha-Matti
>
> Jeffrey Walton [noloader@xxxxxxxxx] kirjoitti:
>>
>> Hi , Also known as a TOCTOU binding flaw (thanks GDM).
>> http://nob.cs.ucdavis.edu/bishop/papers/1996-compsys/racecond.pdf
>> (dated 1996).
>>
>> Jeff
>>
> On Wed, May 5, 2010 at 3:14 AM, www.matousec.com - Research
> <researchmatousec.com> wrote:
>>> Hello,
>>>
>>> We have found number of vulnerabilities in implementations of
>>> kernel hooks in many different security products.
>>>
> --clip--
>
> _______________________________________________ Full-Disclosure - We
> believe in it. Charter:
> http://lists.grok.org.uk/full-disclosure-charter.html Hosted and
> sponsored by Secunia - http://secunia.com/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/