lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri Nov 11 14:28:31 2005
From: toddtowles at brookshires.com (Todd Towles)
Subject: the "Sony/BMG" virus

How to use Sony cloaking

1) Write standard virus/trojan
2)  Trick poor person to run on computer (easy right?)
3) Name it with $sys$
4) It is now cloaked by the Sony DRM.

Isn't too hard...you will see more and more, it won't be long before
spyware is using it to hide as well. Is it good? No, any virus or
spyware can have it's own rootkit hooks if they wanted. But if they use
Sony, they can claim they weren't not trying to hide..."some other
software" was hiding them. Botnet admins like smaller coded bot...no
need to add any code...just a file renamed...man even a folder rename
for that matter

Thanks Sony...

> -----Original Message-----
> From: full-disclosure-bounces@...ts.grok.org.uk 
> [mailto:full-disclosure-bounces@...ts.grok.org.uk] On Behalf 
> Of Michael Holstein
> Sent: Friday, November 11, 2005 8:23 AM
> To: Fergie
> Cc: full-disclosure@...ts.grok.org.uk
> Subject: Re: [Full-disclosure] the "Sony/BMG" virus
> 
> > Insofar as [just] yesterday's RootkitGate media blitz, let's review:
> 
> Those lawsuit links refer to the class-action suit related to 
> the rootkit + DRM install itself.
> 
> I'm more interested in it's use to cloak a virus, and the 
> potential legal liability that might create for the authors.
> 
> 15 seconds on Google can provide a variety of rootkits .. I 
> suspect this is one of the first developed by a big-name 
> company (versus the customization you can get from some 
> hacker groups for a little donation).
> 
> ~Mike.
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
> 

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ