When I found a malicious script riddled with 0×00 bytes, SANS handler Bojan
Zdrnja explained to me that this was an old trick. When rendering an HTML
page, Internet Explorer will ignore all zero-bytes (bytes with value zero,
0×00). Malware authors use this to obscure their scripts. But this old
trick still packs a punch.
All of the interesting technological, artistic or just plain fun subjects I'd investigate if I had an infinite number of lifetimes. In other words, a dumping ground...
Tuesday, 30 October 2007
Null bytes to fool virus detection
http://blog.didierstevens.com/2007/10/23/a000n0000-0000o000l00d00-0i000e000-00t0r0000i0000c000k/
Subscribe to:
Post Comments (Atom)
tim's shared items
Blog Archive
-
▼
2007
(118)
-
▼
October
(31)
- haacked blog
- Null bytes to fool virus detection
- Virus Total
- Hash functions
- GIMP 2.4 preview
- Fail2ban
- Ohloh
- shipping container stacking strategy
- python genetic programming
- travelling salesman problem
- Arbitrage view in the US
- Arbitrage
- Pasha bulker
- Postgres explain analyse
- Javascript library - jQuery
- Gantt project charting for Linux
- Part image - save a partition
- Aircrack-ng & Airsnort & Kismet
- GDB reference card
- The Pedal-to-the-Metal, Totally Illegal, Cross-Cou...
- bin packing
- Elastic compute clouds and internet storage
- Books to buy - Code Complete, The Mythical Man-Month
- Harvard scientists predict the future of the past ...
- ANT Censuses of the Internet Address Space
- Windows - Speeding up filesystems
- Adobe Flex Builder for Linux Alpha
- New York Times - The Next Leap for Linux
- Linkers documented
- 5 Great (And Free) Games You’re Not Playing Now
- Server logging visualisation using Ruby and OpenGL
-
▼
October
(31)
No comments:
Post a Comment