![]() |
|
#1
|
|||
|
|||
|
hi,
was wondering if anyone was using Mandiant Red Curtain or the ZA ForceField beta? Mandiant app. only scans .exe type files....i wanted it to scan my Limewire downloads, but it wouldnt... |
|
#2
|
||||
|
||||
|
Quote:
I am using the ZA ForceField beta and imo it's excellent. Sure it has some minor problems, like FP's on some sites, which will be hopefully fixed. |
|
#3
|
||||
|
||||
|
Quote:
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder". "Perfect is the enemy of good enough". Voltaire. |
|
#4
|
|||
|
|||
|
thanks for the replies...
on Mandiant RC, i thought viruses, malware etc could exist in a non-executable file? this is not the case? i thought the regular AVG, ST, SAS types scanned all files on the HDD by default... |
|
#5
|
||||
|
||||
|
Yes, there are macro (Word/Excel/Powerpoint) viruses and script (scripting languages) viruses.
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder". "Perfect is the enemy of good enough". Voltaire. |
|
#6
|
|||
|
|||
|
Quote:
thats not as bad as i thought then...i figured malware could hide in just about any file, i was scanning everything... does the actual file extension matter, like if its an .mp3 or .wma, could it still harbor a virus/malware that would be released on opening the file? |
|
#7
|
||||
|
||||
|
You can hide anything in everything (steganography). But, an .exe hidden in a .mp3 file won't do any harm. On the other hand, data filetypes might have vulnerabilities (buffer overflows for instance) which can be used to execute shellcode
__________________
"Pouvoir ŕ l'Imagination. Power to the imagination. La imaginación al poder". "Perfect is the enemy of good enough". Voltaire. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|