3 ms·
What's the best way to scan a file (Windows) then to ensure it's clean? I believe this file to be clean, I suppose I'm just asking to better understand the theo
by skcin7 15y ago
What's the best way to scan a file (Windows) then to ensure it's clean? I believe this file to be clean, I suppose I'm just asking to better understand the theory.
- chopsueyar 15y agoSpecifically for poisonivy, off the top of my head, I would run a virtualized instance of windows inside of a different OS, and then monitor all network activity between the virtualized OS and the host system and verify every IP it is connecting to during installation and once installed. Maybe somebody else can jump in here and offer better advice?
- oconnore 15y agoThe virtual machine isn't guaranteed to work: http://www.zdnet.co.uk/news/security-threats/2009/06/09/virtual-machine-exploit-lets-attackers-take-over-host-39661637/ http://www.zdnet.co.uk/news/security-threats/2009/06/09/virt... Unless you know exactly what it can do, you should probably run it on an old machine without [direct] internet access.
- chopsueyar 15y agoFrom your link: Cloudburst uses a vulnerability in the virtual-machine display functions of VMware Workstation that can be exploited by a specially crafted video file. and... However, the Cloudburst exploit currently has certain limitations: it will only succeed on Workstation 6.5.0 or 6.5.1 or the associated Player versions. In addition, the guest and host must be Windows-based, among other requirements, Immunity said in its release notes.
- count 15y agoRemember, that's a publicly released exploit that's not even very new. Assume that if that's been publicly released, more advanced stuff has already been seen in the wild.
- skcin7 15y agoMakes sense. That is good advice but as oconnore pointed out that even a VM can be exploited, though I think your solution would work well in the majority of cases. I suppose using a virtual copy of Windows in my OS X wouldn't be 100% safe because of the exploit. I suppose I'll be getting out my old Dell Windows XP machine then to test this out until I am sure it is safe (which I imagine it is but who knows), and if something happens to it then I'll just wipe the drive and re-install Windows. Poison Ivy seems like it would be an awesome tool to know which would be worth my time.
- chopsueyar 15y agoDid you read the actual article about the VM exploit? It requires both OSs to be Windows based AND the use of a malformed video file. But, yeah, paranoia is healthy in this circumstance.
- mambodog 15y agoI think you're missing the point of "Trust no one". You don't scan it, just use it in a disposable environment (usually a VM, on a non-valuable machine) and see what it does.