Why NOD32 not verify the existence of the Code Signing certificate ?

Discussion in 'ESET NOD32 Antivirus' started by Eugene Lachinov, Oct 15, 2008.

Thread Status:
Not open for further replies.
  1. The Hammer

    The Hammer Registered Member

    Joined:
    May 12, 2005
    Posts:
    5,752
    Location:
    Toronto Canada
    Only Nod flags it?
     
  2. Eugene Lachinov

    Eugene Lachinov Registered Member

    Joined:
    Oct 15, 2008
    Posts:
    21
    1/41 - NOD32
     
  3. estbird

    estbird Eset Staff

    Joined:
    Feb 19, 2009
    Posts:
    97
    To Eugene Lachinov:
    Do you talk about managed file (strong names) or native file verification(authenticode)?

    Microsoft implementation can be slow because it can go online and ask certification authority (CA) thought OCSP protocol or by https to verify revocation list. Of course you can attack it by adding root certificate to trusted root of local machine.

    It was made successful attak to MD5 digest algorithm a few months ago. A few weeks ago was published article which describe way how to decrease complexity of attacking sha-1.
    http://www.theregister.co.uk/2009/06/10/digital_signature_weakness/

    I thing 99% of root CA using MD5 or SHA-1. So do you thing that is still good idea.
     
  4. Eugene Lachinov

    Eugene Lachinov Registered Member

    Joined:
    Oct 15, 2008
    Posts:
    21
    Native file verification
    Optional
    I think that the codesigned file - it is a virus (description, actions) or not. Not "probably unknown NewHeur_PE virus".
     
  5. Eugene Lachinov

    Eugene Lachinov Registered Member

    Joined:
    Oct 15, 2008
    Posts:
    21
    Last edited by a moderator: Aug 26, 2009
  6. Eugene Lachinov

    Eugene Lachinov Registered Member

    Joined:
    Oct 15, 2008
    Posts:
    21
  7. agoretsky

    agoretsky Eset Staff Account

    Joined:
    Apr 4, 2006
    Posts:
    4,033
    Location:
    California
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.