Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
a cyberpunk goose
May 21, 2007

OSI bean dip posted:

Sandboxing is useful to me because I can run the malware within a controlled environment to determine what the ramifications are, but there are solutions that will run malware at the perimeter and will react after the fact if it does something that is discovered to be malicious. You just have to hope that the box doesn't get compromised because of a a vulnerability.

can you comment on malicious code that stays benign when it notices it's in a sandbox? detecting sandboxing seems like it's really easy, or at least noticing you're in a virtualbox vm

Adbot
ADBOT LOVES YOU

a cyberpunk goose
May 21, 2007


hahaha jesus christ:

code:
// wait out the AV vm
sleep( TEN_MINUTES );
win32CompromiseSystem( *attack_vector );
done. dusts hands

a cyberpunk goose
May 21, 2007

Khablam posted:

You seem to be desperately reaching for some sort of "gotcha" where you can point that you know something more than me (and anyone else reading) and not in any way suggesting anything useful.

all your posts along this topic reek of ... insecurity, shall we say.

please go take a walk. nobody cares, nobody respects you at this point. OSI is posting not to attack you, but rather to make sure someone reading this thread doesn't take someone like you or your misinformation seriously

a cyberpunk goose
May 21, 2007


i've read it as OSI & co attacking the lovely mindset of computer janitors who think that you can solve computer security issues with extremely high doses of homeopathic software. OSI's last post was totally reasonable and khablam's childish attempt at a repartee is both pathetic and uninteresting to anyone but themselves. but now i too am making GBS threads up the place so :tipshat:

  • Locked thread