Forums: Compressed Files Fly By Av - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

Compressed Files Fly By Av "new" attack vector

#1 User is offline   beardednose 

  • Forum Moderator
  • Icon
  • Group: First Lieutenant
  • Posts: 1,834
  • Joined: 23-May 03

Posted 17 February 2005 - 11:14 AM

Unexpected Attack Vectors
A new round of attacks and phishing attempts use some unexpected attack vectors that we should have been paying attention to, but weren't.

By Scott Granneman Feb 09 2005 02:33PM PT

Back in 1882, Los Angeles was a rough, dry town of 12,000 people that had been an incorporated municipality for a little over 3 decades. 1882 also saw the introduction of telephone service and electric streetlights. At the time there were several newspapers in town, including the Los Angeles Tribune and the Los Angeles Times. Competition between newspaper rivals was fierce, but no one at the time realized where the biggest threat would come from: a young 19-year-old sharpie named Harry Chandler, who had just moved to Los Angeles and had started working for the Times.

---------------------
This starts a little slow, but it's worth it. Looks like compressed file types like GZ, SIT, and RAR can get by AV software with infected files. BN

Read the rest at http://securityfocus.../columnists/298
Don't post just a THANKS! Here's why...

Forum Rules you need to know...RuLeS
0

#2 User is offline   belgther 

  • Master Sergeant
  • Icon
  • Group: Specialist
  • Posts: 650
  • Joined: 06-October 04

Posted 18 February 2005 - 05:49 AM

well, i don't know if i understood it well, but i had some compressed files, infected, too, so DrWeb detected and cured them...
"The wisest one is the one who knows himself/herself." Quote of the life
belgther... aka... belgther
0

#3 User is offline   Tyrano 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 296
  • Joined: 13-February 04

Posted 18 February 2005 - 11:45 PM

The archived extensions was news to me, but the IDN vector? Cmon now. Granted I didn't know IDN was available, but it seems pretty logical this would have been the next phishing scheme.
0

Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting