16 Replies - 1146 Views - Last Post: 29 September 2012 - 11:25 PM
#1
This is genius... Sophos Antimalware Discovers Itself
Posted 21 September 2012 - 03:19 AM

POPULAR
Link to the full article
Replies To: This is genius... Sophos Antimalware Discovers Itself
#2
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 21 September 2012 - 03:25 AM
Quote
We learned of the error at about 8:30 this morning when we received over 1500 system messages regarding the Shh/Updater-B threat. Their official release is included below.
I’ve gotten the fixes from Sophos and have made most of them.
Again, DO NOT be concerned with Shh/Updater-B messages.
You’re computer has not been infected, hacked, or otherwise attacked as a result of Sophos’ error.
#3
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 21 September 2012 - 03:34 AM
#4
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 21 September 2012 - 04:30 AM
This post has been edited by raziel_: 21 September 2012 - 04:31 AM
#5
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 21 September 2012 - 01:11 PM
BenignDesign, on 21 September 2012 - 05:25 AM, said:
Quote
We learned of the error at about 8:30 this morning when we received over 1500 system messages regarding the Shh/Updater-B threat. Their official release is included below.
I’ve gotten the fixes from Sophos and have made most of them.
Again, DO NOT be concerned with Shh/Updater-B messages.
You’re computer has not been infected, hacked, or otherwise attacked as a result of Sophos’ error.
I spy with my little eye "you're" being used incorrectly.
#6
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 21 September 2012 - 01:22 PM
#7
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 23 September 2012 - 10:24 PM
#8
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 23 September 2012 - 10:40 PM
By the way, this thread my my day. Thank you.
#9
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 24 September 2012 - 04:15 PM
Something I just learned about 3-4 weeks ago when Chrome Beta was going nuts on me. Apparently Avast uses DLL code injection, and in the process of injecting code into Chrome, they broke Chrome Beta. Consider that doing DLL code injection a common malware practice that most normal programs wouldn't be doing. I'm willing to bet that if somebody asks in DIC C# or C/C++ sections about how to do DLL code injection, the thread will be closed along the same lines that we don't help people write a keylogger.
So if your antivirus program goes and scans files and it discovers a byte pattern that looks like the byte codes for doing DLL injection, won't the file go into the suspicious pile the requires more scanning? The "more scanning" process will likely do more extensive analysis, and potentially have heuristics including a white list. Unless you have a comprehensive white list of all files that use DLL injection, then you'll be forced to make a decision: "the file is good" or "the file is bad." I think as a antivirus program writer, I would lean towards "the file is bad."
Apart from the DLL injection specific issue, other AV software also does the same things that malware would do including installing device drivers, hooking API calls, opening ports, etc. So unless every AV writer has an up-to-date library of every other AV software ever released so that they can do extensive testing, and building of white lists, then there will always be a chance of false positives.
There are also some bits of malware that go around and mask themselves by actually exploiting bugs in brand name AV software and installing themselves into that AV software.
I do find it particularly hilarious that Sophos classified itself to be malware. A tester and/or test manager will likely be getting a stern talking to, if not be losing a job.
#10
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 25 September 2012 - 04:14 AM
TLDR: You there, HAL?
#11
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 25 September 2012 - 04:44 AM
#12
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 25 September 2012 - 04:59 AM
To be honest, at least their code was working fine, it did in fact detect several updaters including their own, Sage's and Adobe's. The detection was technically correct
#13
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 25 September 2012 - 08:02 PM
I detect myself
I want you to find me
When I'm feelin' down
I want to alert me
I search myself
I want you to find me
I delete myself
I want you to remove me
#14
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 27 September 2012 - 12:56 PM
This post has been edited by nK0de: 27 September 2012 - 08:57 PM
#15
Re: This is genius... Sophos Antimalware Discovers Itself
Posted 27 September 2012 - 01:03 PM
|
|

New Topic/Question


MultiQuote










|