Kaspersky releases free tool that scans Linux for known threats
Kaspersky releases free tool that scans Linux for known threats
Kaspersky has released a new virus removal tool named KVRT for the Linux platform, allowing users to scan their systems and remove malware and other known threats for free.
You're viewing a single thread.
I HIGHLY doubt that they would detect the XZ backdoor
24 4 Replyxz --version
34 0 Reply22 0 ReplyBöhmermann in freier Wildbahn gesichtet
2 0 ReplyWar auch überrascht
1 0 Reply
Even if it did, what would you do? rm -rf /?
XZ is part of the core system
4 0 ReplyWhy? It's not hard. They typically hash files and look for hits against a database of known vulnerabilities.
4 1 ReplyYes and if viruses use something like base64 encoding or other methods, the hashes dont match anymore.
As far as I understood it, it is pretty easy to make your virus permanently un-hashable by just always changing some bits
7 0 ReplyThe xz backdoor was a packaged file distributed with the standard packages though. It would be trivial to find.
2 0 ReplyThis is obviously not about this known file.
It is about "would this scanner detect a system package from the official repos opening an ssh connection"
1 0 ReplySorry, I was responding to:
I HIGHLY doubt that they would detect the XZ backdoor
1 0 Reply
That doesn't work against polymorphic malware
I think the best way is to monitor calls and behavior. Doing that is a privacy nightmare
2 0 ReplyWho's talking about polymorphic malware? We were talking about the xz backdoor.
1 0 ReplyOh well in that case there is no chance
1 0 Reply