Hackers' project hides browser-busting code
- 18 October, 2006 14:05
- Comments
Hackers are developing new software that will help hide browser attack code from some types of security software.
The software, called VoMM (eVade o' Matic Module), uses a variety of techniques to mix up known exploit code so as to make it unrecognizable to some types of antivirus software.
Using these techniques, VoMM "can create an endless number of variants of an exploit," said Aviv Raff, one of the developers behind the project.
"It aims to provide several techniques out of the box to make browser exploits (mostly) undetectable," according to a blog posting by one of the project's founders, a hacker going by the name of "LMH." That posting can be found target=_blank">here.
The software users server-side scripting technology to create new versions of the exploit code, which then get delivered to browser users when they visit the attacker's Web site. By making a number of cosmetic changes to the code that do not affect its functionality, VoMM creates a new version of the malicious software that cannot be detected by "signature-based" techniques.
Signature-based antivirus products analyze known malware and then create a digital fingerprint that allows the antivirus software to identify malicious code. By adding extra components -- tabs and spaces, and random comments and variable names -- that are not included in known signatures, VOMM creates software that can evade detection.
The VoMM code is expected to be included in a new module for the upcoming 3.0 version of the widely used Metasploit hacking toolkit, Raff said. Metasploit developer HD Moore is also developing the VoMM software. Raff's blog posting on the project can be found target=_blank">here.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- HP Managed Print Services solutioning methodology
- IBM PureFlex System - The infrastructure system with integrated expertise
- 5 Best Practices for Achieving Peak Performance in SAP Environments
- Case Study: Danske Bank Group improves efficiency and reduces time to market
- Forrester Research | Your Enterprise Database Security Strategy 2010
-
Samsung Galaxy S II vs. Samsung Galaxy Nexus
-
Amazon Web Services personalizes CloudFront web hosting service
-
Analysis: Microsoft - Too old and too big to survive?
-
A comparison of Telstra's 4G phones
-
Drupal gains ground down under
-
Windows 7 for Dummies® Dvd+book Bundle
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7
-
Office 2007 All-In-One Desk Reference for Dummies
-
MYOB Software for Dummies 6E Australian Edition
-
Computers for Seniors for Dummies, 2nd Edition
-
Windows 7 for Seniors for Dummies®
-
Microsoft Office
-
Office 2007 for Dummies









Comments
Post new comment