View Full Version : any opinions on Mandiant RC or ZA ForceField?
jfd15
October 25th, 2007, 04:28 PM
hi,
was wondering if anyone was using Mandiant Red Curtain or the ZA ForceField
beta?
Mandiant app. only scans .exe type files....i wanted it to scan my Limewire downloads, but it wouldnt...
The Mole
October 26th, 2007, 12:17 PM
{QUOTE-> hi,
was wondering if anyone was using Mandiant Red Curtain or the ZA ForceField
beta?
Mandiant app. only scans .exe type files....i wanted it to scan my Limewire downloads, but it wouldnt... <-QUOTE}
I am using the ZA ForceField beta and imo it's excellent. Sure it has some minor problems, like FP's on some sites, which will be hopefully fixed.
lucas1985
October 26th, 2007, 11:35 PM
{QUOTE-> was wondering if anyone was using Mandiant Red Curtain <-QUOTE}
Red Curtain isn't your regular malware scanner. It's a research tool and it only rates executables based on a fixed criteria.
jfd15
October 30th, 2007, 05:49 PM
thanks for the replies...
on Mandiant RC, i thought viruses, malware etc could exist in a non-executable
file? this is not the case? i thought the regular AVG, ST, SAS types scanned
all files on the HDD by default...
lucas1985
October 30th, 2007, 07:42 PM
Yes, there are macro (Word/Excel/Powerpoint) viruses and script (scripting languages) viruses.
jfd15
November 2nd, 2007, 02:54 PM
{QUOTE-> Yes, there are macro (Word/Excel/Powerpoint) viruses and script (scripting languages) viruses. <-QUOTE}
thats not as bad as i thought then...i figured malware could hide in just about any file, i was scanning everything...
does the actual file extension matter, like if its an .mp3 or .wma, could it still harbor a virus/malware that would be released
on opening the file?
lucas1985
November 2nd, 2007, 03:04 PM
You can hide anything in everything (steganography (http://en.wikipedia.org/wiki/Steganography)). But, an .exe hidden in a .mp3 file won't do any harm. On the other hand, data filetypes might have vulnerabilities (buffer overflows (http://en.wikipedia.org/wiki/Buffer_overflow) for instance) which can be used to execute shellcode (http://en.wikipedia.org/wiki/Shellcode)
vBulletin® Copyright ©2000-2009, Jelsoft Enterprises Ltd.