Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 19 guests and 3 members online
EH-Net Donations

Enter Amount:
$

Google Ads
ChicagoCon 2008f
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow Tutorialsarrow Please help
Ethical Hacker Community Forums
September 05, 2008, 04:54:31 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Registration Now Open for ChicagoCon 2008f Oct 27 - Nov 2! Visit www.chicagocon.com.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Please help  (Read 3741 times)
0 Members and 1 Guest are viewing this topic.
rok
Newbie
*
Offline Offline

Posts: 35


View Profile
« on: April 27, 2008, 02:31:22 AM »

I want to know how to make any programme undetecteble from avs??Please help me!!As from this question you can guess that I am a noob and gathering  knowledge about these things!!But I am totally ethical,I don't believe on hacking things without permission as like black hats!!And if you still thinking that I am lieing  then you can ban me rite away!I have asked it for my interest and knowledge!!Please help!!

Thanx in advance!!
I ebg your pardon for bad English!!! Smiley
Logged
RoleReversal
Sr. Member
****
Offline Offline

Posts: 397


View Profile WWW
« Reply #1 on: April 27, 2008, 03:47:52 AM »

Rok,

Muts over at Offensive Security has released a video of a presentation at Shmoo-con where he demos exactly this practice. Taking a well known piece of malware and in a matter of minutes (scared the bejesus out of me when I saw it) created something with the exact same functionalilty that AV missed.

http://www.offensive-security.com/cons/shmoo2008/muts_at_shmoo.html

Hopefully this will answer your questions and give you plenty more to go exploring from there. Happy Hunting Cheesy
Logged

A little bit of sanity:
http://www.infosanity.co.uk
rok
Newbie
*
Offline Offline

Posts: 35


View Profile
« Reply #2 on: April 27, 2008, 06:21:58 AM »

Can't I have a tutorial for it,as it's taking loads of time to load!! Sad
Logged
Kev
Sr. Member
****
Offline Offline

Posts: 310


View Profile
« Reply #3 on: April 27, 2008, 09:59:40 AM »

Basically he is encrypting part of the code of the malware in order to hide it from the AV. He uses a decoding stub to reference the source that needs to be encoded so it can function under the radar. This is similar to the way a packer/crypter works. He does it manually, which is a better way but more tedious.  Crypters will do it for you automatically, but you will have less control. The better known crypters will be spotted by many AVs, but the more obscure ones still can fool a number of them. Usually small hacker groups have their own specially written crypter that is passed among its members, that is if they happen to have a decent coder in their ranks. This way of defeating AV is well known amongst hackers but really only works against simple AVs.  I wrote something about this on this forum a while back when I playing around with them in my lab:
http://www.ethicalhacker.net/component/option,com_smf/Itemid,49/topic,821.0/
Logged
rok
Newbie
*
Offline Offline

Posts: 35


View Profile
« Reply #4 on: April 28, 2008, 01:03:25 AM »

Thank you very much and I promise you next time I will use search option first!!!

And is there any good crypters out there which can fool avs!!I have tried many in my lab,but each and every has been detected by avs or blocked by firewalls!!
Logged
Kev
Sr. Member
****
Offline Offline

Posts: 310


View Profile
« Reply #5 on: April 28, 2008, 08:56:58 AM »

The best solution is to write your own and its not hard. If you cant then find someone that can do it for you.
Logged
RoleReversal
Sr. Member
****
Offline Offline

Posts: 397


View Profile WWW
« Reply #6 on: April 28, 2008, 10:24:01 AM »

Kev,

I've just read the link you posted (nice work). One aspect that you picked up on was AV's inability to 'find' a uniquely packed packed virus.

As your initial post is now over a year old, from your experience is this still the case or is coverage just as poor as it was previously?

Logged

A little bit of sanity:
http://www.infosanity.co.uk
Kev
Sr. Member
****
Offline Offline

Posts: 310


View Profile
« Reply #7 on: April 28, 2008, 10:50:31 AM »

Thanks RoleReversal. Its getting harder to fool an enterprise level AV with a cyrpter, but simple home versions are still easy target. Email AVs that are used by Yahoo,etc are  the easiest to slip through. They are almost a joke so please no one reading this rely on them. When I refer to home versions, I am referring to AVs like AVG free,etc... Enterprise level requires writing a complete new signature that is nothing at all like what might be found in the AV's signature base, so you better be on top of your programming skills or have a friend that is. If it is even slightly  similar, it will trigger the AV and thats why we are seeing more and more false positives popping up today. This is due to their so called "heuristic" function, which can work well on some versions and very poorly on others.  Attacking an enterprise level AV with a simple encoding stub is a waste of time, at least thats my humble experience.
Logged
RoleReversal
Sr. Member
****
Offline Offline

Posts: 397


View Profile WWW
« Reply #8 on: April 28, 2008, 11:49:36 AM »

Thanks Kev,

exactly the 'on-the-ground' view point I was looking for. Especially after Muts' presentation frightened me so much. Much appreciated
Logged

A little bit of sanity:
http://www.infosanity.co.uk
rok
Newbie
*
Offline Offline

Posts: 35


View Profile
« Reply #9 on: April 30, 2008, 09:53:09 AM »

I have seen all the posts but I want little help to build crypters and another thing cryptovirology that technique  can't help in this case?
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.5 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.047 seconds with 23 queries.
 
Polls
Best for daily desktop use:
 
Support EH-Net
chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

chicagocon2008f_125x200banner.jpg
ChicagoCon 2008f
 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.