We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

40+ av scanners miss flash exploit

Virustotal uses 43 different av scanners,
they all missed this recent one. (march 2011)

this is the reference for the adobe exploit 'cve-2011-0609' and there is a very detailed report on FireEye.

(I can't post the link yet, not enough posts)

I like a layered approach just in case you might run into a nasty like this one.

Comments

  • waddler_8
    waddler_8 Posts: 3,588 Forumite
    A bit misleading....

    It refers to the payload of a flash exploit from back in March. The exploit vulnerability has since been fixed & Adobe flash has been updated many times since then even - It's now on version 11.0.1.152

    http://get.adobe.com/flashplayer/


    The VT report for the payload at the time of the blog post showed there was a more up to date report that showed 7/43 detecting it, not zero as claimed. That is now 37/43

    http://www.virustotal.com/file-scan/report.html?id=62db3743cc62c66a4b8806d8fe23966472b9841b7d91e9025f474990bd88cc89-1311806866
  • Perhaps I should have been clearer about the reason why I posted this item?

    'A good example of why it isn't a good idea to rely soley on AV for security.'

    The liklyhood there will be something similar to this exploit is high.

    At the time of first detection, according to the article no scanner detected it.

    The article reads as of the 15 march it was zero detection.
    The screen shot showed, looks like it was taken at a later date when detection was 7, (still low)

    This looks like a scan that has been saved at VT and re-opened at a later date when detection has improved, hence the note about 'up to date report, 7/43'

    Agreed, the article could have been a bit clearer.

    To summarize,
    You can't get a more classic example of the need for a layered approach.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455.1K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 603K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.