Search Members Help

» Welcome Guest
[ Log In :: Register ]

Page 1 of 212>>

[ Track This Topic :: Email This Topic :: Print this topic ]

reply to topic new topic new poll
Topic: The Anti-Virus Software Lie< Next Oldest | Next Newest >
 Post Number: 1
Jynx Search for posts by this member.
resident n0b0dy
Avatar



Group: Members
Posts: 333
Joined: Dec. 2000
PostIcon Posted on: Sep. 23 2001,20:16  Skip to the next post in this topic. Ignore posts   QUOTE

I've spent the last three days dancing with that most devious of new virus creations, Nimda. It took our entire company's network down.

During this most enjoyable of times, I've realized a certain truth:

Anti-Virus programs are, by and large, useless for preventing attacks from new viruses.

Let's think about it--McAfee, our company's choice, didn't have a correct definition set until fully 30 hours after our company's network was taken down because of this beast! That means that I could've been updating those freaking definitions every 2 hours, and I still wouldn't have been safe.

It is my opinion that antivirus software provides a certain false sense of security for folks, and is really only good for preventing old viruses from infecting computers, most of which are dead. I am angry at the entire antivirus software community for fostering this false sense of security, instead of educating the Ignorant Masses on proper habits that impair virus spreading.

Discussion, if anyone cares, is welcome.

------------------
--Jynx

I used to be a kleptomanicac, but I took something for it.

Offline
Top of Page Profile Contact Info 
 Post Number: 2
Frosty Search for posts by this member.
FNG
Avatar



Group: Members
Posts: 162
Joined: Nov. 2000
PostIcon Posted on: Sep. 23 2001,21:23 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

Wasn't this obvious? The problem is that all the ways to inhibit virus spreading nowadays mean hardcore disrupting the way you do things. Didn't this Nimda thing get onto the Microsoft web server and infect everyone who visited their site? You can't say "don't surf the net, you might get a virus." There really isn't much that can be done, at least not that I can think of. Ideas?
Offline
Top of Page Profile Contact Info 
 Post Number: 3
damien_s_lucifer Search for posts by this member.
Emperor of Detnet
Avatar



Group: Members
Posts: 33
Joined: Jan. 1970
PostIcon Posted on: Sep. 23 2001,21:42 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

Symantec had a signature update for NAV a few hours after one of my machines got hit... not soon enough to keep me from getting chewed out by The Boss (who thinks ANY breach must be my fault), but soon enough to keep it from killing the whole campus network.

And in light of all this B.S., I am slowly but surely moving ALL of my department's Web stuff to Apache. I can't handle IIS any more.

hax0rs : 1, MS : 0

Offline
Top of Page Profile Contact Info WEB 
 Post Number: 4
just_dave Search for posts by this member.
Town Naysayer, and court jester..
Avatar



Group: Members
Posts: 535
Joined: Apr. 2001
PostIcon Posted on: Sep. 23 2001,21:49 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

It took out our webserver and out Anti-Virus Scanning server, yeah it scans email for virii before it hits the email server. The webserver got it IIS of course and it spread via the mapped drive to the AV Gateway... its norton they didnt have a fix until 22 hours I think I am not totally sure. I agree goes to show ya how stupid AV Software makes people appear.
Offline
Top of Page Profile Contact Info 
 Post Number: 5
Observer Search for posts by this member.
I once watched, but I have left.
Avatar



Group: Members
Posts: 912
Joined: May 2000
PostIcon Posted on: Sep. 23 2001,22:20 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

Though usually by the time they hit most of the faculty computers here and start calling the helpdesk, there's an update available.

But this Nimda worm has brought to light something I didn't think was allowed at a University. Who the fuck runs Win98 on a P-133 with 16MB of RAM and is ok with that? I hate the fact that people aren't more careful about opening their email. I hate the fact that they leave their systems wide open with sharing then yell about how critical it is we get over there to patch it all up!

Tip to those in the field who may suddenly find the installed AV software can't be updated. http://housecall.antivirus.com

Web-based scans can help a lot in a jam.

edit: Something else I just thought over. What about those routines in the AV software that's supposed to detect unknown viruses? Has anyone actually seen them work?

------------------
When 1337 hax0rs start impaling each other with swords and typing code with a hook on one hand, then they can modify the term "pirate."

This message has been edited by Observer on September 24, 2001 at 05:21 PM

Offline
Top of Page Profile Contact Info 
 Post Number: 6
Wolfguard Search for posts by this member.
Flyswatter of the Apocalypse
Avatar



Group: Members
Posts: 1696
Joined: May 2000
PostIcon Posted on: Sep. 24 2001,10:28 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

quote:
Originally posted by Observer:

edit: Something else I just thought over. What about those routines in the AV software that's supposed to detect unknown viruses? Has anyone actually seen them work?


Yep, i may be one of the reasons that symantec had a patch out so quick. the bloodhound sniffed this little bugger out trying to plant itself into one of my servers and shot me a warning. I found the file in question and sent it to symantec. litte bastard spread quick but i was able keep a lid on things by closing a firewall i have between here and Corp HQ. Seams that i have my shit together more than they do.

Nice little worm if i do say so myself. Like to find the guy that made it and set him on fire to show my thanks for it...asshole.


------------------
Fucknuggets flamed while you wait.TeamWolfguard.com
Robot Conflict

Offline
Top of Page Profile Contact Info WEB 
 Post Number: 7
Dark Knight Bob Search for posts by this member.
qunt
Avatar



Group: Members
Posts: 2180
Joined: Sep. 2001
PostIcon Posted on: Sep. 24 2001,10:46 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

isn't the term for that process of finding unknown viruses heuristics or something?

------------------
simultaneity is not absolute. So just because you think i'm wrong, from my frame of reference i'm right!

Offline
Top of Page Profile Contact Info 
 Post Number: 8
Greasemonk Search for posts by this member.
I am almost one of Us.
Avatar



Group: Members
Posts: 440
Joined: Sep. 2000
PostIcon Posted on: Sep. 24 2001,11:50 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

Thank god we dont use Outlook Express or MS Exchange. We use Lotus Notes for just about everything. Its ok and gets the job done, we havent really had a bad virus problem since Funlove last fall.

------------------
All that I know there was no God for me
Force that shatters all, absence of mortality

Offline
Top of Page Profile Contact Info 
 Post Number: 9
L33T_h4x0r_d00d Search for posts by this member.
IT terrorist
Avatar



Group: Members
Posts: 1203
Joined: Sep. 2000
PostIcon Posted on: Sep. 24 2001,13:59 Skip to the previous post in this topic. Skip to the next post in this topic. Ignore posts   QUOTE

quote:
Originally posted by Observer:
edit: Something else I just thought over. What about those routines in the AV software that's supposed to detect unknown viruses? Has anyone actually seen them work?


Norton has an excellent heuristical scanner. 9 out of 10 times norton will pick up what mcaffee, fsecure, thunderbyte, pc-cillion, etc wont befor the patch.

*edit* but you have to be actually running it to get the benefits. Damn you hybriss. DAMN YOU TO HELL.

------------------
"Kenny called, hes in jail"
-The guy on the couch.

This message has been edited by L33T_h4x0r_d00d on September 25, 2001 at 09:00 AM

Offline
Top of Page Profile Contact Info 
 Post Number: 10
Observer Search for posts by this member.
I once watched, but I have left.
Avatar



Group: Members
Posts: 912
Joined: May 2000
PostIcon Posted on: Sep. 24 2001,15:29 Skip to the previous post in this topic.  Ignore posts   QUOTE

Hehe, Hybris. There's a guy who works at the helpdesk around here who would get his jollies asking people what was in the email that started that virus infection. Getting University people to read the sexual innuendo content of the Snow White email can be quite amusing, I suppose.

------------------
When 1337 hax0rs start impaling each other with swords and typing code with a hook on one hand, then they can modify the term "pirate."

Offline
Top of Page Profile Contact Info 
11 replies since Sep. 23 2001,20:16 < Next Oldest | Next Newest >

[ Track This Topic :: Email This Topic :: Print this topic ]


Page 1 of 212>>
reply to topic new topic new poll

» Quick Reply The Anti-Virus Software Lie
iB Code Buttons
You are posting as:

Do you wish to enable your signature for this post?
Do you wish to enable emoticons for this post?
Track this topic
View All Emoticons
View iB Code