This forum is in archive mode. You will not be able to post new content.

Author Topic: evil AV (on development)  (Read 9741 times)

0 Members and 1 Guest are viewing this topic.

Offline xzid

  • Knight
  • **
  • Posts: 329
  • Cookies: 41
    • View Profile
Re: evil AV (on development)
« Reply #15 on: August 05, 2011, 10:20:21 AM »
http://98.15.202.89/

Holy shit, I cannot believe this site is still up. Used to visit it in my first few months of hacking, has some virus code. Looking back, some of it is pretty good.

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: evil AV (on development)
« Reply #16 on: August 05, 2011, 11:19:51 AM »
http://98.15.202.89/

Holy shit, I cannot believe this site is still up. Used to visit it in my first few months of hacking, has some virus code. Looking back, some of it is pretty good.


Indeed that site is pretty awesome. Lots and lots of really useful stuff :)
I knew it for a long time, though haven't bookmarked it until now for some reason :D

Offline petermlm

  • Knight
  • **
  • Posts: 226
  • Cookies: 7
  • Information is Power
    • View Profile
    • Security Check
Re: evil AV (on development)
« Reply #17 on: August 05, 2011, 12:47:18 PM »
http://98.15.202.89/

Holy shit, I cannot believe this site is still up. Used to visit it in my first few months of hacking, has some virus code. Looking back, some of it is pretty good.

Great resource! Thank you very must!

xor

  • Guest
Re: evil AV (on development)
« Reply #18 on: August 05, 2011, 04:46:09 PM »
There's no point in using a users HOME or PROFILE directory because on servers, this can be on a remote location and is thus unreliable to get the local machine path.

xor

  • Guest
Re: evil AV (on development)
« Reply #19 on: August 05, 2011, 04:47:06 PM »

If this is correct(untested, have no linux except android at the moment), then my box would show a partition for /, /boot, /home(gentoo). Would also have a swap partition. Would also have many usb drives(which would be worth option searching). This may cause problems, unless by partitions xor means actual "root drives", like your linux filesystem + any extra external/internal drive mounted in /mnt.


Actually I misread. In linux, it will only EVER return / it won't return the other partitions.

Offline Mellow

  • Knight
  • **
  • Posts: 151
  • Cookies: -24
    • View Profile
Re: evil AV (on development)
« Reply #20 on: August 05, 2011, 11:58:51 PM »
http://98.15.202.89/

Holy shit, I cannot believe this site is still up. Used to visit it in my first few months of hacking, has some virus code. Looking back, some of it is pretty good.
Thanks

Offline gh0st

  • Sir
  • ***
  • Posts: 575
  • Cookies: 8
  • #DEDSec
    • View Profile
Re: evil AV (on development)
« Reply #21 on: August 06, 2011, 03:59:48 AM »
There's no point in using a users HOME or PROFILE directory because on servers, this can be on a remote location and is thus unreliable to get the local machine path.
xor maybe I didnt explained it very well if so I apologize .
look what Im doing is to set the path of the user for scanning and Im looking for a method to start the scan but in all the HDs of the user without the knowing them for example once the module is ended(the scanning for malicius strings of bytes is compleded)
the user clicks onto the button and the program automatically start the scan on the HD I think that I will have to set up 2 scanning methos for linux and for windows but thats what I want to avoid

xor

  • Guest
Re: evil AV (on development)
« Reply #22 on: August 06, 2011, 06:00:30 AM »
again, why, like normal anti-virus', don't you just allow the user to select what they want to scan?

Offline gh0st

  • Sir
  • ***
  • Posts: 575
  • Cookies: 8
  • #DEDSec
    • View Profile
Re: evil AV (on development)
« Reply #23 on: August 06, 2011, 06:23:02 AM »
again, why, like normal anti-virus', don't you just allow the user to select what they want to scan?

its the button of full scan

Offline xzid

  • Knight
  • **
  • Posts: 329
  • Cookies: 41
    • View Profile
Re: evil AV (on development)
« Reply #24 on: August 06, 2011, 06:28:59 AM »
drop linux, linux users don't use AVs anyway.

I'm very curious to see your "scan module", considering how much trouble you're having with this.

Who exactly is "evil AV" designed for? hackers? average end-users? system admins? I don't think you have a chance with any of 'em. Would rethink the name btw, may scare ppl off.

If this is simply a learning experience, then perhaps focusing on the UI and directory scanning is a mistake. Maybe you could start with a command line program that takes a PE file(exe, dll) as an argument. Then parses that file, to see if it's evil.


Offline gh0st

  • Sir
  • ***
  • Posts: 575
  • Cookies: 8
  • #DEDSec
    • View Profile
Re: evil AV (on development)
« Reply #25 on: August 06, 2011, 07:49:52 AM »
@xor: hey dude getpath is just to display its name right? should I go straight to read*? sorry I know that Im nwebie a bit of understanding :P

Offline xzid

  • Knight
  • **
  • Posts: 329
  • Cookies: 41
    • View Profile
Re: evil AV (on development)
« Reply #26 on: August 06, 2011, 07:53:18 AM »
@xor: hey dude getpath is just to display its name right? should I go straight to read*? sorry I know that Im nwebie a bit of understanding :P

y'know this is easier for me than you, respond to me. tell me I'm an asshole, defend yourself pussy.

Offline Kulverstukas

  • Administrator
  • Zeus
  • *
  • Posts: 6627
  • Cookies: 542
  • Fascist dictator
    • View Profile
    • My blog
Re: evil AV (on development)
« Reply #27 on: August 06, 2011, 09:34:20 AM »
Well I just remembered something.
Why the fuck keep it up to date yourself when there are already people using other AV updates for their own apps.

Like that HackHound (I think...) multi AV scanner. The first versions was using stuff straight... I think later version was using command line scanners to scan stuff and then grab the output to display it on a GUI.

http://www.briteccomputers.co.uk/forum/virustrojanspywaremalware/multi-av-scan-v1-6-1-multiple-antivirus-software-on-windows-computer/

xor

  • Guest
Re: evil AV (on development)
« Reply #28 on: August 06, 2011, 09:42:30 AM »
I agree with xzid on dropping Linux support.

Other than that, you have the code sample to return all of the local drives. Next step will be to write a function to iterate through them and all the subfolders and files.

Offline gh0st

  • Sir
  • ***
  • Posts: 575
  • Cookies: 8
  • #DEDSec
    • View Profile
Re: evil AV (on development)
« Reply #29 on: August 08, 2011, 07:51:05 AM »
k guys I think that I got how to do this following this useful post that I did on another site http://www.javaprogrammingforums.com/file-i-o-other-i-o-streams/10266-analizing-bytes-files-av.html#post38913 so I will need to make a statement of if or a read() method to scan for malicius bytes and bring those bytes conditionals from a database any suggestion? http://pastebin.com/nGnTffbd you can add to the source code so I will do the upgrade on the main post give me links or more opinions doesnt matter if you dont know I started java last week  ;D  so you are not the only noob
« Last Edit: August 08, 2011, 07:56:27 AM by gh0st »

 



Want to be here? Contact Ande, Factionwars or Kulverstukas on the forum or at IRC.