Open Source Malware Search Engine
chr0.ot writes "Metasploit creator HD Moore has released an open-source search engine that finds live malware samples through Google queries. From the article: 'The new Malware Search project provides a Web interface that allows anyone to enter the name of a known virus or Trojan and find Google results for Web sites hosting malicious executables.' The tool then searches for actual malware signatures and uses the signature output from ClamAV to find the name of the malware. This is then used in conjunction with a PE signature matching method to form a Google query. Afterwards the malware can then be downloaded directly from Google."
Let me get this straight.. now Google is good for porn AND viruses?
How do the other engines stay in business?!?
I wonder how they got that idea. I've never heard of it before.
Clippy:
It looks like your searching for viruses,
well your in the right place.
ps, anyone else notice that slashdot is like waiting for a bus, you wait for hours with no updates then 4 come along all at once.
Hope the problems have been fixed now.
liqbase
I in no way think that google should block sites, but it would be nice if they would scan sites witht this -- especially for sites that install stuff through holes in IE -- and put a little icon on search results that return an infected site. That way you could at least have a heads up before you clicked on a search result about what you were getting into. It would also be great for Firefox, when everyone gets to see how many sites are exploiting IE.
Transporter_ii
Doctors destroy health, lawyers destroy justice, universities destroy knowledge, religion destroys spirituality
that snags a random payload off this site! Thanks Metasploit!
BTW, Dupe, Dupity Dupe, Dupe.
Comparing it to Windows will be a moot point, since El Dorado is going to have a 40% larger code base than XP.
Sorry Google can't do it, McAfee already bought that startup - http://www.siteadvisor.com/.
I just bought a new PC, and i have no viruses yet.
what MS has to say about this.
This is outright competition for their closed source malware search engine IE.
I don't need a search engine to find malware.
Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
"to enter the name of a known virus or Trojan and find Google results for Web sites hosting malicious executables" we should be able to do it the other way around too. enter the url for websites we suspect first then list if the websites host malicious executables. imo its more useful that way :)
Everything is possible. The impossible just takes longer.
I've got in the habit now when reading slashdot of if I can't understand a post, reading it as if i was speaking it (but silently of course).
I'm trying to read this sentence as if you were speaking it. And you sound sort of silly.
When the policeman of the tie, rule you violate, hello punishment of the kitty?
I've got in the habit now when reading slashdot of if I can't understand a post, reading it as if i was speaking it.
Didja read or speak this before posting? Improper verb usage, mangled propositional phrase, missing punctuation.
FTR, I'm not a grammar nazi, but you, by claiming such, opened you'reself up for a little good-natured criticism.
Regards.
You really should try the excelent ProcessExplorer from SysInternals.
factor 966971: 966971
Your being too kind.
Since I don't normally like to engage in the karma-damaging activity of trolling, I was hoping to get some bang-for-the-buck out of my post. Thus, I left two juicy pieces of bait (i.e., grammatical errors) in my post, and promptly started meta-moderating my heart out to counter the impending down-mod.
BTW, "my particular dialect" must mean english is an auxiliary language for you. Kudos on that and never apologize for the occasional mess-up. I am not among those who are multilingual, so I envy you.
Regards.
Actually, no it isnt. Although morons who dont read the full article might thinks it was.
2 53240 and http://it.slashdot.org/article.pl?sid=06/07/11/131 220)
The previous stories
(http://it.slashdot.org/article.pl?sid=06/07/15/1
were referring to another security research co who did something similar and then refused to share it.
This story is about someone not liking that they wont share, going a little bit further than they did and then putting it on a website and enabling it to the full.
I looked at the previous (Websense) story on friday or whenever but found it a little annoying that there was nothing to back up the article. This time someone has actually posted a working link to a project and source code.
I dont read
Your being too kind.
Usually it's not worth the effort, but given this thread I just had too...
That should be:
You're being too kind.
William of Ockham had no beard. The most likely explanation is that it was chewed off by squirrels every morning.
Yep, it is. Congrats, you win the prize: a PS3 running Vista. This offer expires in 30 days.