Re: Re: Problem solved, bug in sophie found
Bill Earle <[email protected]>
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 26 Jan 2004, Markus Stumpf wrote: > On Mon, Jan 26, 2004 at 02:53:21PM +0100, L. Jankok wrote: > > Ok.. If I change my sophie.savi a bit as suggested then it will > > not detect the following virus : > > > > NOTICE : Scanning file '/home/xinu/Mime.822' > > WARNING : Scan result => '/home/xinu/Mime.822' infected with virus 'W32/Dumaru-Y' > > > > Only with mime enabled it will detect Dumaru-Y but then it will not detect Sefex-A. > > Sefex-A is a "general dropper". The ZIP file which initiated all the > discussion is now scanned without problems using my 1-line modification, > SAVI 3.78 and the sophie.savi I have posted earlier. > > HOWEVER: It does not detect Sefex-A but a Troj/Tofger-H (I got the IDE > from Sophos per email). I don't know why, but it looks like it was not > incorporated in the additional IDE.zip for 3.78 Sophos has also sent me the tofger-a.ide file. My concern is missing the delivery / wrapper in the 1st place. What would the proper detection be? A. Detect ONLY the payload, skip if unknown B. Detect the sefex-a delivery wrapper and not care what the specific payload is? I would feel better with option B., detect the known delivery / wrapper. - Bill > \Maex > > -- > SpaceNet AG | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0 > Research & Development | D-80807 Muenchen | Fax: +49 (89) 32356-299 > "The security, stability and reliability of a computer system is reciprocally > proportional to the amount of vacuity between the ears of the admin" > _______________________________________________ > vtools mailing list > [email protected] > http://www.vanja.com/list/listinfo.cgi/vtools >