Open Source Malware Search Engine 123
chr0.ot writes "Metasploit creator HD Moore has released an open-source search engine that finds live malware samples through Google queries. From the article: 'The new Malware Search project provides a Web interface that allows anyone to enter the name of a known virus or Trojan and find Google results for Web sites hosting malicious executables.' The tool then searches for actual malware signatures and uses the signature output from ClamAV to find the name of the malware. This is then used in conjunction with a PE signature matching method to form a Google query. Afterwards the malware can then be downloaded directly from Google."
So.. (Score:5, Funny)
How do the other engines stay in business?!?
Re:So.. (Score:2)
Re:So.. (Score:1)
Re:So.. (Score:5, Funny)
So, basically, the Internet is exactly like real sex now, only easier to get.
Re:So.. (Score:3, Funny)
Re:So.. (Score:2)
Re:So.. (Score:2)
Finding malware with search engine? (Score:5, Insightful)
Re:Finding malware with search engine? (Score:4, Funny)
Re:Finding malware with search engine? (Score:5, Informative)
Also, this program supposedly highlights how relatively little malware Google actually indexes, contrary to the two earlier articles you cite. Thus this is an additional development, not a dupe.
Re:Finding malware with search engine? (Score:2)
Re:Finding malware with search engine? (Score:3, Informative)
Re:Finding malware with search engine? (Score:2, Funny)
Microsoft Version! (Score:3, Funny)
It looks like your searching for viruses,
well your in the right place.
ps, anyone else notice that slashdot is like waiting for a bus, you wait for hours with no updates then 4 come along all at once.
Hope the problems have been fixed now.
About the bus metaphor (Score:1, Funny)
Only if you mean the same one comes along four times.
Re:Microsoft Version! (Score:1)
Re:Microsoft Version! (Score:1, Funny)
Re:Since we're off on a tangent anyway (Score:1, Insightful)
I've got in the habit now when reading slashdot of if I can't understand a post, reading it as if i was speaking it (but silently of course).
I just can't read as fast when I have to do that.
Re:Since we're off on a tangent anyway (Score:4, Funny)
I'm trying to read this sentence as if you were speaking it. And you sound sort of silly.
Re:Since we're off on a tangent anyway (Score:1, Offtopic)
Re:Since we're off on a tangent anyway (Score:2, Funny)
Didja read or speak this before posting? Improper verb usage, mangled propositional phrase, missing punctuation.
FTR, I'm not a grammar nazi, but you, by claiming such, opened you'reself up for a little good-natured criticism.
Regards.
Re:Since we're off on a tangent anyway (Score:1)
That's the reason I'm a silent Grammar Nazi - my particular dialect means I mess up many othe things - I'm just saying that some incorrect grammar usage make me cringe.
I always welcome advice on how I could improve my communication provided people tell me why I've gone wrong, rather than just saying I am wrong.
Re:Since we're off on a tangent anyway (Score:2, Funny)
Since I don't normally like to engage in the karma-damaging activity of trolling, I was hoping to get some bang-for-the-buck out of my post. Thus, I left two juicy pieces of bait (i.e., grammatical errors) in my post, and promptly started meta-moderating my heart out to counter the impending down-mod.
BTW, "my particular dialect" must mean english is an auxiliary language for you. Kudos on that and never apologize for the occasional mess-up. I am not among those who are multilingual, s
Re:Since we're off on a tangent anyway (Score:3, Funny)
Usually it's not worth the effort, but given this thread I just had too...
That should be:
You're being too kind.
Re:Since we're off on a tangent anyway (Score:2)
Re:Since we're off on a tangent anyway (Score:2)
But pretending I'm all knowing and stuff and that I make no mistakes:
Just replace the ellipsis with "much beer"
Re:Since we're off on a tangent anyway (Score:1)
Re:Since we're off on a tangent anyway (Score:1)
"BTW, "my particular dialect" must mean english is an auxiliary language for you"
ROTFL
I am actually English as far back as we can trace the geneaology. Just from the north of England mixed with some Cornwall, combined with Mancunian with some Essex and London thrown in; so my upbringing WRT language is not the same as the Queen's English. hence correct grammar for my peers is not the same as the textbook definition. I still support correct usage of your/you're thei
Re:Since we're off on a tangent anyway (Score:2)
There is a word for a language as used by a specific individual
speaker, and that word is "idiolect". Wars are fought because
particularly stupid people cannot accept the inescapable fact
that words *intend* (meaning 1) precisely what their speaker intends,
and regardless of what they *convey* (meaning 2) in the interpretation
of a listener or *connote* (meaning 3) in the instantaneous context
of the present evolutionary state of the dialect, which is in turn
distinct from the canonical
Re:Since we're off on a tangent anyway (Score:1)
Propositional Phrase (Score:1)
You win! (Score:2, Funny)
Re:Since we're off on a tangent anyway (Score:2)
SO, how did your reply to me make YOU feel?
Re:Microsoft Version! (Score:1)
Re:Microsoft Version! (Score:1)
Just be thankful that you're not a subscriber. Then they'd all come early, and you'd miss them!
- RG>
Re:Microsoft Version! (Score:1)
I usually get to see them coming in the mysterious future and occasionally your right, just before they arrive at my bus stop, they turn off and vanish again.
The frustrating part is it normally only happens with the articles I really want to post something in.
First it was a dupe... (Score:1, Funny)
Re:First it was a dupe... (Score:1, Offtopic)
Re:First it was a dupe... (Score:1, Offtopic)
since:
2 == Duplicate [answers.com] (Dupe!)
3 == triplicate [answers.com] (Tripe)
4 == Quadraplicate [answers.com] (Quad!)
X == Make-up-your-own-plicate (Enough Already!)
Re:First it was a dupe... (Score:1, Offtopic)
And I get modded offtopic? The freaking story was posted three times, I think that is relevant.
Is there more original ontopic stuff to say about a story we have seen THREE TIMES?
Re:First it was a dupe... (Score:3, Informative)
The previous stories
(http://it.slashdot.org/article.pl?sid=06/07/15/12 53240 and http://it.slashdot.org/article.pl?sid=06/07/11/131 220 [slashdot.org])
were referring to another security research co who did something similar and then refused to share it.
This story is about someone not liking that they wont share, going a little bit further than they did and then putting it on a website and enabling it to the full.
I looked at the previo
Headline can be misread as... (Score:1)
-phozz
Can also be misread as... (Score:2)
I wish google would incorporate this into searches (Score:5, Interesting)
Transporter_ii
Re:I wish google would incorporate this into searc (Score:3, Informative)
Re:I wish google would incorporate this into searc (Score:2)
I see that they fit into McAfee's quality pretty well.
Re:I wish google would incorporate this into searc (Score:2)
McAfee's automated scans can't and won't red-flag a corporate home page simply because the company is on your personal black list. You might, however, take the time to post a comment.
Re:I wish google would incorporate this into searc (Score:1)
McAfee SiteAdvisor (Score:2)
Sounds rather like McAfee SiteAdvisor [siteadvisor.com] for IE and Firefox.
SiteAdvisor tests e-mail, downloads, and links. Give an e-mail address to Slashdot and you can expect 6.9 e-mails per week. Reports are detailed and comments can be posted.
Th
Move Quickly! (Score:2)
(Unless McAfee has already done so since another poster notes they do something similar.)
So I am going to write a virus (Score:3, Funny)
BTW, Dupe, Dupity Dupe, Dupe.
Re:So I am going to write a virus (Score:4, Informative)
How can an article whose content says the earlier article was bogus be a dupe of the earlier article?
How can the initial announcement of a freely available tool be a dupe of the announcement of something that is not for public release?
Conclusion: there are a lot idjits on slashdot who have learned to waggle their fingers on the keyboard and therefore think they are clever. Oh so clever.
Slashdot has become the proving ground for kids who wanna grow up to be one of the million monkeys...
Re:So I am going to write a virus (Score:1)
This latest parlor trick will allow kids who can't write viruses to at least be able to collect them. Their very own petting zoo -- complete with some of the exotics -- and some new friends to play with!
Re:So I am going to write a virus (Score:2)
Pshaw.
(Always wanted to say that. Wonder what it sounds like?)
You can buy anything online these days, including low number slashdot IDs, ibetcha.
And anyway I'm living proof that the mind of a toddler can exist in an aging, decrepit body.
Re:Ducking Fupes (Score:1)
Personally, I'm rather tired of reading comment after comment pointing out that a given article is a dupe - I think the tagging system is sufficient to identify dupitude (hey, you're allowed to make up words in english). If the article's a dupe, don't read it, and by all means, don't comment - just ignore it like the articles that don't interest you.
Re:Ducking Fupes (Score:2)
Thank God! (Score:3, Funny)
Comment removed (Score:5, Insightful)
Re:Thank God! (Score:1, Funny)
Re:Thank God! (Score:1)
or
Because he never turned it on yet.
or
Because it runs Linux xyz/xyz BSD/...
Re:Thank God! (Score:3, Informative)
How do you know?
How could [arstechnica.com] he know?
Microsoft Malware Remover says so! (Score:2)
Re:Thank God! (Score:1)
I wonder... (Score:3, Funny)
This is outright competition for their closed source malware search engine IE.
I use Windows (Score:5, Funny)
Re: (Score:3, Funny)
Re:I use Windows (Score:4, Funny)
Just click start - search...
and coming soon... (Score:1)
- the shard of glass necktie finder
- the kick in the crotch searcher
Seriously, if this were part of your search results as a heads up of what to avoid I can see it being quite valuable. But, short of research or bad intentions... why do i want to find live malware?
Re:and coming soon... (Score:2)
On the broaders scale, IHPs will be able to keep an eye on their customers to see if any servers are hosting malwar
I guess I don't understand (Score:1, Redundant)
Re:I guess I don't understand (Score:2)
Re:I guess I don't understand (Score:3, Informative)
You really should try the excelent ProcessExplorer from SysInternals [sysinternals.com].
Re:I guess I don't understand (Score:2)
Re:I guess I don't understand (Score:1)
Either way, I sort of enjoy the torture of fixing the thing, you learn a lot that way. That and I enjoy the interrogation bit, she comes up with some great excuses that I sometimes use later at my job.
Careful...Skynet...Matrix...DupeDot... (Score:2, Funny)
Sounds like this thing's just a few modules short of obsoletizing us all; give this thing a "beowulf cluster" module and a "in Soviet Russia" module and it'd be pretty well self-contained. Any day now it'll be welcoming it's overlord self...
the other way around? (Score:2, Interesting)
What agreement? (Score:1)
*sniff* (Score:2)
Re:*sniff* (Score:1)
Re:I'm feeling Lucky (Score:1)
AWRIGHT!! an OS infector! w00t! (Score:2)
Re:AWRIGHT!! an OS infector! w00t! (Score:1)
--C
gcc, worm, trojan (Score:1)
gcc.gnu.org / ml/gcc-prs/2004-05/msg00008 / the_message.scr
(don't open the URL from Windows, or at all. My AV detected the file as "W32.Beagle.gen", right after I downloaded it).
2. Search the engine for "worm" or "trojan" and you'll get tons of them.
Re:gcc, worm, trojan (Score:2)
Re:gcc, worm, trojan (Score:1)
That's obvious if you read the URI. It's a mailing-list archive, and it keeps copies of attachments.
No wrongdoing involved by GNU, tho perhaps they should delete that message.
what is the use case? (Score:2)
Obvious question (Score:2)
Anti-Spyware (Score:1)
As for me, I like professional anti-spy software like PrivacyKeyboard by Raytown Corporation LLC.
You can download it here: http://download.softsecurity.com/1/14/prvkbd.zip [softsecurity.com] (~4MB)
Anti-Spyware: Efficiency of the Means of Defense [trap17.net]
Open Source AV (Score:1)