Symantec i njihov sajt za testiranje bezbednosti

3

Symantec i njihov sajt za testiranje bezbednosti

offline
  • Puky  Male
  • Scottish rebel
  • Pridružio: 18 Apr 2003
  • Poruke: 5815
  • Gde živiš: u Zmajevom gnjezdu

Toliko o cuvenom Nortonu. Evo jedne vesti koja se i dotice teme a i ne dotice, ali je poenta da Norton ume da brljavi. (ne kazem da ne radi posao ali jednostavno ... ko radi - taj i gresi)



Even Antivirus Scanners Make Mistakes
By Larry Seltzer


Security fundamentally requires trust. You can't function without trusting some other users and some programs. On the other hand, you can't completely trust everything, and that includes normally trustworthy software, such as Symantec's Norton AntiVirus.

A couple of months ago I began receiving virus notifications about a file that had been on my hard disk for a while. At that time, I was testing spyware removal tools for PC Magazine and this was the install file for one of the products. NAV reported that it found Backdoor.IRC.dr in the file. The suspicion about this infection was either inaccurate or newsworthy.

ADVERTISEMENT


While Symantec was checking on it, I decided to double-check their results. Several antivirus vendors have a Web page where you can upload a file for them to scan (see Kaspersky's page for example).

Trend Micro takes this a step further and lets you scan whole drives through an ActiveX control version of their PC scanner called Trend HouseCall. The software is pretty neat, but be advised that it's also very slow, and that's not counting the time it takes to download, which wasn't a short while for me.

Housecall's scan is also slow, but at least Trend provides some entertainment in the form of a "Virus Knowledge Quiz" while the scan runs. However, I suggest that you answer "no" to the fifth and final question: Is HouseCall all you need for virus protection?

If a real infected file gets onto your system to the point where you have to find it with a manual scan like this, the barn door's already open and the horse is in the next county. You need live protection. But if all you need is a quickie scan of a file or drive, HouseCall can be just what the doctor ordered.

In addition, if you suspect spyware has found its way onto your system but don't want to install a whole scanning application, there's now an online spyware scanner, PestPatrol's PestScan. Like HouseCall, this is an ActiveX control.

Meanwhile, neither HouseCall nor any of the other scanners I tried found anything really wrong with that suspect file. Symantec got back to me to say that the code resulting in the false positive was fixed in the next day's definitions.

But even if I hadn't had the other scanners to use, there were plenty of common sense reasons to suspect that the report was false. This file had been on my system for some time. If it was the only infected file on my system—as the reports indicated—then it must have come to my system infected. And it didn't make sense that such an infection could have been out in the wild for that length of time without making its way into NAV's set of virus definitions.

Every time I've seen a real virus get through Norton's protections (it's happened a couple of times recently), the culprit has been a new, fast-spreading outbreak like Sobig.E. So once again, common sense is your most important resource when it comes to your ongoing security.

Security Supersite Editor Larry Seltzer has worked in and written about the computer industry since 1983.


Preuzeto sa [Link mogu videti samo ulogovani korisnici]



Registruj se da bi učestvovao u diskusiji. Registrovanim korisnicima se NE prikazuju reklame unutar poruka.
offline
  • Pridružio: 26 Apr 2003
  • Poruke: 1947
  • Gde živiš: Srbija

Novi virusi uvek u prvom naletu mogu proci pored Nortona, i blaster je prosao, ali nakon toga tezi slucaj. Odmah sutra ujutru je izdata definicija...



offline
  • SINGI
  • Pridružio: 22 Avg 2003
  • Poruke: 787
  • Gde živiš: Beograd

Symantec je u antivirus alijansi sa Microsoft-om, a tu su i McAffee, TrendMicro i silom prilika RAV Wink
Moguce je da stoga "preferiraju" MS resenja

offline
  • SINGI
  • Pridružio: 22 Avg 2003
  • Poruke: 787
  • Gde živiš: Beograd

Trebalo bi da nadje virus i bez definicije, preko heuristike...bar kao nepoznat. Naravno da moze da se desi da omane heuristika, ali ne sme bas sve da zavisi od definicija u bazi Wink

offline
  • Peca  Male
  • Glavni Administrator
  • Predrag Damnjanović
  • SysAdmin i programer
  • Pridružio: 17 Apr 2003
  • Poruke: 23211
  • Gde živiš: Niš

zato sam ja ljudima uvek preporucivao AVP (sadasnji KAV) Smile

offline
  • Pridružio: 26 Apr 2003
  • Poruke: 1947
  • Gde živiš: Srbija

Heuristic mi je jedino na KAV-u radio kako valja.... svi ostali su nista, ali 100% nista bez definicija.

offline
  • SINGI
  • Pridružio: 22 Avg 2003
  • Poruke: 787
  • Gde živiš: Beograd

U prilog ovome govori i cinjenica da je KAV jedini AV na svetu koji je uspesno odolevao svim varijacijama “ILOVEYOU” virusa i bez osvezavanja baze definicija. Very Happy

offline
  • Pridružio: 26 Apr 2003
  • Poruke: 1947
  • Gde živiš: Srbija

Al nije mi jasno zasto ga je tako KLEZ klao...

offline
  • Pridružio: 17 Apr 2003
  • Poruke: 488
  • Gde živiš: Niš

Samo da razjasnimo - i heuristika se dobrim delom oslanja na definicije, pa tako bez azurnog softvera nema zastite, makar imao on "savrsen" algoritam za heuristiku.

offline
  • Zoran Bujandric
  • Programer
  • Pridružio: 18 Apr 2003
  • Poruke: 152
  • Gde živiš: Podgorica

Kao prilog diskusiji, moje skorasnje iskustvo sa BugBear virusom na jednoj "neupdatovanoj" mrezi sa instalisanim Nortonom i ZoneAlarmom.
Kao sto i pise u opisu gorenavedenog gospodina virusa, prosto kolje vecinu antivirusa i firewalla i gotovo da imate vezane ruke....Pa vam padne na pamet spasonosna ideja sa Symantec-ovog sajta skinete free removal tool za ovaj virus....I on nesto drnda, drnda i javi utjesnu poruku kako na vasem racunaru na postoji doticni virus. ( nije iskljuceno da se kamuflirao pod skenerom....)

Pravi spas je AntiBugBear_en sa lokacije [Link mogu videti samo ulogovani korisnici] Jednostavno brzo i cisto. Prijavi, ocisti i aufiderzen. Tek tada mozete uraditi update baze i prepustiti Nortonu da radi to sto radi.

Zaista je dobra preporuka imati nekoliko rezervnih varijanti.Jedna od njih je svakako i bitdefender.

Ko je trenutno na forumu
 

Ukupno su 911 korisnika na forumu :: 69 registrovanih, 7 sakrivenih i 835 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: Apok, B61, Ba4e, bigvlada, Bluper, Bo96, bobomicek, Bobrock1, bojcistv, Boris BM, ccoogg123, d bos, Djota1, dule10savic, elenemste, GeoM, goranjovic, Griffon vulture, Hans Gajger, HrcAk47, IAR80, Jose, karevski, kovinacc, kybonacci, ljuba, M74AB3, MarkoD, markomacii9, MB120mm, Milan A. Nikolic, mile33, Milos ZA, milos97, Mineral, Mirage 2000N, mishkooo, Neutral-M, Nikolajevic, Pavle29L, Primus17, raketaš, raso76, Ray1973, Razdroid, rodoljub, ruma, ruso, samojednoimeznam, savaskytec, solic, sspp, starlights, superwhy, synergia, Tihi86, tmanda323, Tribal, trutcina, tubular, Tvrtko I, Vlada1389, vuksa72, x011, zgoljo, Zorge, zrno, šumar bk2, 79693