hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

sk3tch
This is all very preliminary...but I've now had two incidents where my Kaspersky Personal 5.0 (actually Defender Pro 2005 which is just a re-brand) honeypot has been infected by malware that the app knows about, i.e. it slips right through the realtime scanning engine. So once I notice the infection (usually due to a lot of network traffic coming from the infected honeypot) I check the box and all the malware processes are in memory and running and kavsvc.exe is utilizing 100% CPU (or as much as it can get as it fights with the malware for CPU time). As you guys probably know, kavsvc.exe is their realtime scanning engine, and the process cannot be killed (at least with Task Manager and kill.exe). I also was not able to stop the service...only a power off or reboot stops it.

The first incident happened on 11/26 and now one just happened today (11/28). In both cases, when I discovered the system the definitions were up-to-date within a few hours (the honeypot AV is set to default KAV values, so every three hours it checks for new stuff).

I've submitted both cases to Kaspersky and I'm working on resolving what happened. The nice thing is that I'm using VMware for my honeypots so I can compress them and FTP them around. Only problem was that last time I had issues getting it to Russia and ended up just giving them my personal FTP..but they haven't picked up the 700MB zip of the VMware files yet. Now I've got a second one to send them.

Has anyone seen anything like this? I'm just really concerned because in the time I've used KAV in my honeypot I have began to worry more and more that their application is crap (but, as we all know, their definitions are excellent)!

I'm going to begin testing Kaspersky Personal Pro 5.0 tonight.
strohunter
i know this problem too, it seems to be a correlation between VMWare and KAV

It happens to me when my VMWare crashes, when i reboot them, KAV eats up 100% of my cpu. After a while everything returns to normal, except that i have lost some gigabytes on the harddrive that have VMWare installed (KAV seems to dump the whole VMWare image on the harddrive in order to scan it)
sk3tch
Thanks for the response.

OK - so you're talking about your host system running VMware systems running KAV and causing issues?

I think my case may be slightly different, as it is VMware GSX running on Red Hat Enterprise Linux 3...there is no AV scanner on my Linux box.

However, the VMware direction is an interesting one. May have to setup a physical system to test this.

Thanks!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.