<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New Argument Switch Attack Bypasses Windows Security Software</title>
	<atom:link href="http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 14 Feb 2012 00:17:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Morgan Storey</title>
		<link>http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/#comment-162855</link>
		<dc:creator>Morgan Storey</dc:creator>
		<pubDate>Wed, 26 May 2010 06:47:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2691#comment-162855</guid>
		<description>@bews: I take it as they can actually look like legit code and the Av app will let it past. So it may not disable the AV just simply bypass it.</description>
		<content:encoded><![CDATA[<p>@bews: I take it as they can actually look like legit code and the Av app will let it past. So it may not disable the AV just simply bypass it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bews</title>
		<link>http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/#comment-162838</link>
		<dc:creator>bews</dc:creator>
		<pubDate>Fri, 14 May 2010 01:23:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2691#comment-162838</guid>
		<description>Does this not mean that the malware or whatever has to be able to bypass the AV client to disable the AV client??

To me that means that their job was already done before they disabled the AV client with the kernel hook stuff anyway *shrugs*</description>
		<content:encoded><![CDATA[<p>Does this not mean that the malware or whatever has to be able to bypass the AV client to disable the AV client??</p>
<p>To me that means that their job was already done before they disabled the AV client with the kernel hook stuff anyway *shrugs*</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keane Matthews</title>
		<link>http://www.darknet.org.uk/2010/05/new-argument-switch-attack-bypasses-windows-security-software/#comment-162835</link>
		<dc:creator>Keane Matthews</dc:creator>
		<pubDate>Thu, 13 May 2010 14:21:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2691#comment-162835</guid>
		<description>KHOBE (Matousec) article indicates this is attack vector is valid for all versions of Windows, up to and including Windows 7 for both 32- and 64-bit OSs.

&lt;blockquote&gt;
The research was done on Windows XP Service Pack 3 and Windows Vista Service Pack 1 on 32-bit hardware. However, it is valid for all Windows versions including Windows 7. Even the 64-bit platform is not a limitation for the attack. It will work there against all user mode hooks and it will also work against the kernel mode hooks if they are installed, for example after disabling the PatchGuard. 
&lt;/blockquote&gt;</description>
		<content:encoded><![CDATA[<p>KHOBE (Matousec) article indicates this is attack vector is valid for all versions of Windows, up to and including Windows 7 for both 32- and 64-bit OSs.</p>
<blockquote><p>
The research was done on Windows XP Service Pack 3 and Windows Vista Service Pack 1 on 32-bit hardware. However, it is valid for all Windows versions including Windows 7. Even the 64-bit platform is not a limitation for the attack. It will work there against all user mode hooks and it will also work against the kernel mode hooks if they are installed, for example after disabling the PatchGuard.
</p></blockquote>
]]></content:encoded>
	</item>
</channel>
</rss>

