Wifi Password Recovery - UTM - Vulnerability Scanning


VIP LOUNGE
CLOUD LOGIN
Sun Sun Sun

You are here: News > News > Latest breed of threat avoids the watchful protections

» IT Security NEWS
 
» 09 May 2010
Latest breed of threat avoids the watchful protections

 

The group of security experts found another method of evading the state-of-the-art defense systems that are incorporated into the various anti-virus scanners created by the most popular firms such as McAfee, AVG, Trend Micro, and BitDefender.
Easier method of evading anti-virus scanner
The new scheme, which was discovered by the software security experts representing matousec.com, functions in such a way that it can find its way around the anti-virus application and it is also capable of hiding within the system files of the Windows OS. This newly-founded process truly works even if the Windows OS installed in the computer has restricted privileges.
Various processes can sidestep security programs
In addition, the method bypasses the security system by launching a trial benign code. And then, once it gains permission for entry from the security product, the benign code will be switched with a malicious code and the following code will be executed within the computer system.
The method was designed in an intricate manner that the swapping of the two different codes is done in perfect timing and it happens neither rapidly nor slowly. The attack is also successful even with the machines with multi-core processors. This is possible since the argument-switch attack made by matousec works effectively because a single thread is not capable of watching other working threads all at the same time. Hence, the anti-malware products intended for the Windows-operated computers are most probably vulnerable to malicious attacks.
Problem lies on the kernels being utilized
The security software experts did tests on most of the Windows-compatible security programs presented in the market today. And, as summed up by the security software experts, programs that are integrated with SSDT hooks or kernel mode hooks possessing the same quality, which are used on executing the security functions make the system vulnerable to attacks.
The security threat still has inadequacies although it appears to work productively. Enormous quantity of code must be injected into a system so as to make this method operate well. Another way to make this attack flourish is by making a person perform the malicious activity only if he or she has the right knowledge on executing binary into a system.
Read some valuable text by viewing the following SecPoint links: SecPoint Products, SecPoint Press, and SecPoint Awards.

 


Reviews of SecPoint.com
 
 
 
 
 

Awards & Reviews
  

  


Subscribe to our Mailing List

Customer References



Encyclopedia | Free Scan Statement | Link Policy | Privacy Statement | Resources | Sitemap | User Policy
© Copyright 1999-2012: SecPoint®
SecPoint ApS Noerregade 7B - 1165 Copenhagen K - Denmark
US Toll free: +1-888-704-7297 - EU: +45-70-235-245