Quantcast
0
0

Hackers' Project Hides Browser-Busting Code

Robert McMillan, IDG News Service

Wednesday, October 18, 2006 5:00 AM PDT

Hackers are developing new software that will help hide browser attack code from some types of security software.

The software, called eVade o' Matic Module (VoMM), uses a variety of techniques to mix up known exploit code so as to make it unrecognizable to some types of antivirus software.

Using these techniques, VoMM "can create an endless number of variants of an exploit," said Aviv Raff, one of the developers behind the project.

"It aims to provide several techniques out of the box to make browser exploits (mostly) undetectable," according to a blog posting by one of the project's founders, a hacker going by the name of "LMH."

Delivered Via Web Site

The software users server-side scripting technology to create new versions of the exploit code, which then get delivered to browser users when they visit the attacker's Web site. By making a number of cosmetic changes to the code that do not affect its functionality, VoMM creates a new version of the malicious software that cannot be detected by "signature-based" techniques.

Signature-based antivirus products analyze known malware and then create a digital fingerprint that allows the antivirus software to identify malicious code. By adding extra components--tabs and spaces, and random comments and variable names--that are not included in known signatures, VOMM creates software that can evade detection.

The VoMM code is expected to be included in a new module for the upcoming 3.0 version of the widely-used Metasploit hacking toolkit, Raff said. Metasploit developer HD Moore is also developing the VoMM software. Raff describes the project in his blog posting.

.
Community Comments
Recommend this story?

PC World's Marketplace

PC World's Free Whitepapers

Security News
More

Latest Expert Blogs

All Blogs
Featured Resources

Premier Content From Our Sponsors

Featured Whitepapers

White papers, case studies and product info from top brands

  • The 5 Reasons to Worry about Your DNS DNS servers are one of the most critical, yet vulnerable, network infrastructure applications. Because of their exposure to the Internet, they are among the most vulnerable computers that an organization deploys. This whitepaper explains the top fi...
Featured Webcasts

Watch webcast presentations and videos from industry thought leaders on today's most important business and technology topics. For free.