Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. h/t @nyanbinary

h/t @nyanbinary

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
33 Indlæg 18 Posters 133 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • _greywolf@kinkycats.org_ _greywolf@kinkycats.org

    @Viss
    Though that kinda is always the risk
    Antivirus just had the biggest attack surface
    @nyanbinary

    nyanbinary@infosec.exchangeN This user is from outside of this forum
    nyanbinary@infosec.exchangeN This user is from outside of this forum
    nyanbinary@infosec.exchange
    wrote sidst redigeret af
    #24

    @_GreyWolf @Viss yip, that is correct & you arent going to see me jump the bandwagon of "AV is bad". imo the conclusion then needs to be beyond-rigorous QC. Unfortunately that is something MS has very much lost my trust there, even for components like Defender.

    viss@mastodon.socialV 1 Reply Last reply
    0
    • viss@mastodon.socialV viss@mastodon.social

      h/t @nyanbinary

      so let me get this straight
      microsoft defender, the built-in antivirus tool for windows

      has a heap based buffer overflow that leads to remote code execution

      if you get it to scan a file, and that file is crafted the right way.

      the antivirus tool is the carrier for the execution of malware.

      mobidic@mastodon.socialM This user is from outside of this forum
      mobidic@mastodon.socialM This user is from outside of this forum
      mobidic@mastodon.social
      wrote sidst redigeret af
      #25

      @Viss @nyanbinary
      Since I turned off Defender – I've gotten back 1GB of RAM and 15% blocked CPU power – and replaced it with my brain. That's all.

      viss@mastodon.socialV 1 Reply Last reply
      0
      • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

        @_GreyWolf @Viss yip, that is correct & you arent going to see me jump the bandwagon of "AV is bad". imo the conclusion then needs to be beyond-rigorous QC. Unfortunately that is something MS has very much lost my trust there, even for components like Defender.

        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.social
        wrote sidst redigeret af
        #26

        @nyanbinary @_GreyWolf the chief component here is that its microsofts av and microsofts os.

        they have the sourcecode. they have limitless resources. they print money.

        but even with all that, they wrote av for their own os.

        other vendors dont have anywhere near the same resources, or access to all the sourcecode. its way harder for other vendors

        1 Reply Last reply
        0
        • mobidic@mastodon.socialM mobidic@mastodon.social

          @Viss @nyanbinary
          Since I turned off Defender – I've gotten back 1GB of RAM and 15% blocked CPU power – and replaced it with my brain. That's all.

          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.socialV This user is from outside of this forum
          viss@mastodon.social
          wrote sidst redigeret af
          #27

          @mobidic @nyanbinary i wish avg didnt go shitty. it was pretry good for a while

          1 Reply Last reply
          0
          • catsalad@infosec.exchangeC catsalad@infosec.exchange

            @Viss @nyanbinary Sufficiently advanced Windows services are indistinguishable from malware

            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.socialV This user is from outside of this forum
            viss@mastodon.social
            wrote sidst redigeret af
            #28

            @catsalad @nyanbinary my favorite is when defender decides another piece of windows is bad and attacks it

            catsalad@infosec.exchangeC 1 Reply Last reply
            0
            • viss@mastodon.socialV viss@mastodon.social

              @catsalad @nyanbinary my favorite is when defender decides another piece of windows is bad and attacks it

              catsalad@infosec.exchangeC This user is from outside of this forum
              catsalad@infosec.exchangeC This user is from outside of this forum
              catsalad@infosec.exchange
              wrote sidst redigeret af
              #29

              @Viss @nyanbinary I mean, it's not wrong... 😹

              gnate@ohai.socialG viss@mastodon.socialV 2 Replies Last reply
              0
              • catsalad@infosec.exchangeC catsalad@infosec.exchange

                @Viss @nyanbinary I mean, it's not wrong... 😹

                gnate@ohai.socialG This user is from outside of this forum
                gnate@ohai.socialG This user is from outside of this forum
                gnate@ohai.social
                wrote sidst redigeret af
                #30

                @catsalad
                Ah, autoimmune issues...
                @Viss @nyanbinary

                1 Reply Last reply
                0
                • viss@mastodon.socialV viss@mastodon.social

                  h/t @nyanbinary

                  so let me get this straight
                  microsoft defender, the built-in antivirus tool for windows

                  has a heap based buffer overflow that leads to remote code execution

                  if you get it to scan a file, and that file is crafted the right way.

                  the antivirus tool is the carrier for the execution of malware.

                  sassdawe@infosec.exchangeS This user is from outside of this forum
                  sassdawe@infosec.exchangeS This user is from outside of this forum
                  sassdawe@infosec.exchange
                  wrote sidst redigeret af
                  #31

                  @Viss @nyanbinary this remind me of the old days when I tricked a Next Gent AV into code execution in very simple way in the same day the vendor was on site for a purple team exercise.

                  viss@mastodon.socialV 1 Reply Last reply
                  0
                  • sassdawe@infosec.exchangeS sassdawe@infosec.exchange

                    @Viss @nyanbinary this remind me of the old days when I tricked a Next Gent AV into code execution in very simple way in the same day the vendor was on site for a purple team exercise.

                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.socialV This user is from outside of this forum
                    viss@mastodon.social
                    wrote sidst redigeret af
                    #32

                    @sassdawe @nyanbinary i got arcticfox to run meterpreter for me once

                    1 Reply Last reply
                    0
                    • catsalad@infosec.exchangeC catsalad@infosec.exchange

                      @Viss @nyanbinary I mean, it's not wrong... 😹

                      viss@mastodon.socialV This user is from outside of this forum
                      viss@mastodon.socialV This user is from outside of this forum
                      viss@mastodon.social
                      wrote sidst redigeret af
                      #33

                      @catsalad @nyanbinary true

                      1 Reply Last reply
                      0
                      • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                      Svar
                      • Svar som emne
                      Login for at svare
                      • Ældste til nyeste
                      • Nyeste til ældste
                      • Most Votes


                      • Log ind

                      • Har du ikke en konto? Tilmeld

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      Graciously hosted by data.coop
                      • First post
                        Last post
                      0
                      • Hjem
                      • Seneste
                      • Etiketter
                      • Populære
                      • Verden
                      • Bruger
                      • Grupper