<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Multiple Bugs In Anti-Virus Software Revealed</title>
	<atom:link href="http://www.darknet.org.uk/2009/04/multiple-bugs-in-anti-virus-software-revealed/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2009/04/multiple-bugs-in-anti-virus-software-revealed/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:04:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Darknet</title>
		<link>http://www.darknet.org.uk/2009/04/multiple-bugs-in-anti-virus-software-revealed/#comment-144021</link>
		<dc:creator>Darknet</dc:creator>
		<pubDate>Fri, 17 Apr 2009 07:55:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1688#comment-144021</guid>
		<description>Thanks for your interesting and well thought out comment, I agree with what you say - it is a complex area. But still they should try and control the updates as best they can.

It&#039;s not easy sending out updates for multiple OS versions/architectures/update levels.

Thanks for the compliment, keep reading and keep commenting and I&#039;ll keep publishing :)</description>
		<content:encoded><![CDATA[<p>Thanks for your interesting and well thought out comment, I agree with what you say &#8211; it is a complex area. But still they should try and control the updates as best they can.</p>
<p>It&#8217;s not easy sending out updates for multiple OS versions/architectures/update levels.</p>
<p>Thanks for the compliment, keep reading and keep commenting and I&#8217;ll keep publishing <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: nubanx</title>
		<link>http://www.darknet.org.uk/2009/04/multiple-bugs-in-anti-virus-software-revealed/#comment-143863</link>
		<dc:creator>nubanx</dc:creator>
		<pubDate>Thu, 16 Apr 2009 20:12:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1688#comment-143863</guid>
		<description>Its the nature of the beast.   
As of this year, the tipping point between white listed software and blacklisted software will tilt towards black listed for the first time (ever).  This means that there is now actually more malicious software created than &quot;&quot;&quot;good&quot;&quot;&quot; software.   
More and more companies will begin working from the whitelisted software models.  

The complexity of the AV  solutions out there have had no choice but to play catch up, and move towards signature based attacks and other heuristic based protection. Throw this elevated complexity into the ever increasing complexity of the windows environment, and.. well..  you have today. 

Antivirus updates don&#039;t just always mean adding defs to the database for the local client.  It could be engine updates and other components as well.  Pushing these types of updates to the world of windows machines (running version X with software Y on hardware Z)is an extremely complex mechanism.  Updates do &quot;odd&quot; things all the time from a corporate standpoint. Most corporations invest in the support services from the AV vendor.  Home users?  well..  some pay for the support, others probably don&#039;t even need it. (MAC and GNU/Linux users don&#039;t require much in this arena, and they are gaining market share into home computing use. 

also - currently most AV products (depending on how its configured, of course) do not experience the old recursive zip bomb, and limit their nested file scanning limit to ~9 deep. 
and...  everytime i read bomb, i dont know why but i always think of :(){ :&#124;:&amp; };:    

:-P

please keep up the good work you do with this site.  
i enjoy it. 

-nubanx</description>
		<content:encoded><![CDATA[<p>Its the nature of the beast.<br />
As of this year, the tipping point between white listed software and blacklisted software will tilt towards black listed for the first time (ever).  This means that there is now actually more malicious software created than &#8220;&#8221;"good&#8221;"&#8221; software.<br />
More and more companies will begin working from the whitelisted software models.  </p>
<p>The complexity of the AV  solutions out there have had no choice but to play catch up, and move towards signature based attacks and other heuristic based protection. Throw this elevated complexity into the ever increasing complexity of the windows environment, and.. well..  you have today. </p>
<p>Antivirus updates don&#8217;t just always mean adding defs to the database for the local client.  It could be engine updates and other components as well.  Pushing these types of updates to the world of windows machines (running version X with software Y on hardware Z)is an extremely complex mechanism.  Updates do &#8220;odd&#8221; things all the time from a corporate standpoint. Most corporations invest in the support services from the AV vendor.  Home users?  well..  some pay for the support, others probably don&#8217;t even need it. (MAC and GNU/Linux users don&#8217;t require much in this arena, and they are gaining market share into home computing use. </p>
<p>also &#8211; currently most AV products (depending on how its configured, of course) do not experience the old recursive zip bomb, and limit their nested file scanning limit to ~9 deep.<br />
and&#8230;  everytime i read bomb, i dont know why but i always think of <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> ){ <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_neutral.gif' alt=':|' class='wp-smiley' /> :&amp; };:    </p>
<p> <img src='http://www.darknet.org.uk/wp-includes/images/smilies/icon_razz.gif' alt=':-P' class='wp-smiley' /> </p>
<p>please keep up the good work you do with this site.<br />
i enjoy it. </p>
<p>-nubanx</p>
]]></content:encoded>
	</item>
</channel>
</rss>
