6 ms·
So if I download (which I already did) and install this file, how can I know it's not going to inject code into my own computer?
by skcin7 15y ago
So if I download (which I already did) and install this file, how can I know it's not going to inject code into my own computer?
- chopsueyar 15y agoTrust no one.
- skcin7 15y agoWhat's the best way to scan a file (Windows) then to ensure it's clean? I believe this file to be clean, I suppose I'm just asking to better understand the theory.
- chopsueyar 15y agoSpecifically for poisonivy, off the top of my head, I would run a virtualized instance of windows inside of a different OS, and then monitor all network activity between the virtualized OS and the host system and verify every IP it is connecting to during installation and once installed. Maybe somebody else can jump in here and offer better advice?
- oconnore 15y agoThe virtual machine isn't guaranteed to work: http://www.zdnet.co.uk/news/security-threats/2009/06/09/virtual-machine-exploit-lets-attackers-take-over-host-39661637/ http://www.zdnet.co.uk/news/security-threats/2009/06/09/virt... Unless you know exactly what it can do, you should probably run it on an old machine without [direct] internet access.
- chopsueyar 15y agoFrom your link: Cloudburst uses a vulnerability in the virtual-machine display functions of VMware Workstation that can be exploited by a specially crafted video file. and... However, the Cloudburst exploit currently has certain limitations: it will only succeed on Workstation 6.5.0 or 6.5.1 or the associated Player versions. In addition, the guest and host must be Windows-based, among other requirements, Immunity said in its release notes.
- count 15y agoRemember, that's a publicly released exploit that's not even very new. Assume that if that's been publicly released, more advanced stuff has already been seen in the wild.
- skcin7 15y agoMakes sense. That is good advice but as oconnore pointed out that even a VM can be exploited, though I think your solution would work well in the majority of cases. I suppose using a virtual copy of Windows in my OS X wouldn't be 100% safe because of the exploit. I suppose I'll be getting out my old Dell Windows XP machine then to test this out until I am sure it is safe (which I imagine it is but who knows), and if something happens to it then I'll just wipe the drive and re-install Windows. Poison Ivy seems like it would be an awesome tool to know which would be worth my time.
- chopsueyar 15y agoDid you read the actual article about the VM exploit? It requires both OSs to be Windows based AND the use of a malformed video file. But, yeah, paranoia is healthy in this circumstance.
- mambodog 15y agoI think you're missing the point of "Trust no one". You don't scan it, just use it in a disposable environment (usually a VM, on a non-valuable machine) and see what it does.
- andrewcooke 15y agoyou can't, obviously. so start up a virtual machine, run a new version of your OS, and install it there. you should also take care to isolate the network connection of your vm as much as possible (and/or monitor it). i'm not promising this is sufficient - good luck :o) ps to answer your other question - antivirus scanners look for patterns in the file itself, so they don't need to install it, but are vulnerable to alternative packaging, modified code, etc etc (of course, scanners also check for problems with installed files, but the first line of defense is to inspect the data - including unpacking zip files etc).