deepzero Posted November 5, 2012 Posted November 5, 2012 AbstractBy design, antivirus products introduce a vast attack surface to a hostile environment. The vendors of theseproducts have a responsibility to uphold the highest secure development standards possible to minimise the potentialfor harm caused by their software. This second paper in a series on Sophos internals applies the results previouslypresented in [2] to assess the increased threat Sophos customers face. This paper is intended for a technical audience,and describes the process a sophisticated attacker would take when targeting Sophos users.WarningActive Sophos users should refrain from testing the examples described in this paper on production systems.Disk I/O on Sophos installations is intercepted by a minifilter that requires a userspace process to permit the operation.Interfering with the userspace process will cause I/O to fail systemwide, panic your machine and cause irretrievable dataloss.https://lock.cmpxchg8b.com/sophailv2.pdfThat`s some nice stuff, right there. :S
kao Posted November 5, 2012 Posted November 5, 2012 Ironically, I saw Sophos blogpost about the same subject today: http://nakedsecurity...ormandy-sophos/ For each vulnerability they had the same comment: Sophos has seen no evidence of any of these vulnerabilities being exploited in the wild. Reading the same sentence seven times was hilarious..
Teddy Rogers Posted November 9, 2012 Posted November 9, 2012 I have just read this paper and apart from it being damning it is quite shocking to read about some of the basic errors being made. No wonder "they were clearly ill-equipped to handle the output of one co-operative security researcher working in his spare time", after being shown all this evidence I wouldn't be surprised to find out some of the Sophos team losing their jobs over it.Surely they had some form of internal and external code and security auditing?Ted.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now