![]() |
|
MitchE323
|
also Franklin verified that containment here;
http://www.wilderssecurity.com/showpost.php?p=1260674&postcount=45 So that is two completely different users that contained it. |
||||||||||||
|
|
|||||||||||||
|
SnDPhoenix
|
Yeah, as we all figured, he was just trying to spread crap about Sandboxie.
Just another day... |
||||||||||||
|
|
|||||||||||||
|
Buster
|
I believe in the theory of commercial interests moving certain people to post false information in forums.
|
||||||||||||
|
|
|||||||||||||
|
MitchE323
|
No Buster, if it were commercial interests that would at least make a small element of sense. These are just wannabes......
|
||||||||||||
|
|
|||||||||||||
|
SnDPhoenix
|
Hmm guys, it could be both! And yes you're both correct. |
||||||||||||||||
|
|
|||||||||||||||||
|
Oneder
|
Haven't tried to run the below sandboxed as yet and I don't understand how such a small zip can contain that amount of data, unless it's a joke.
Someone may want to play around with it. It does get flagged over at Virus Total. http://www.virustotal.com/analisis/fe25f9898cf1b11f209aea7012671126
hxxp://www.unforgettable.dk/ |
||||||||||||||
|
|
|||||||||||||||
|
SnDPhoenix
|
What the hell? So if you could extract this entire archive, every last zip file, it would take up 4.5 Petabytes? All in a 42 Kb zip? Even I am shocked right now... Only thing I can think is that the "o.dll" although 4Gb in size, is really just nothing but straight zeros! Then the fact that there is a 4Gb dll file (only zeros though) inside of EACH archive, it all adds up to I guess, 4.5PB? If I had enough space I'd try it out haha. |
||||||||||||||||
|
|
|||||||||||||||||
|
Peter2150
|
Actually three. I just didn't bother posting. |
||||||||||||||
|
|
|||||||||||||||
|
street011
|
i can't see how this is a challenge to sandboxie? it does nothing... its just a compressed file with high compression ratio you are going to extract, sure, your sandbox will grow and run out of diskspace.
no challenge, but fun to see |
||||||||||||
|
|
|||||||||||||
|
Buster
|
That kind of malwares are known as archive bombs and they existed already in MS-DOS times.
|
||||||||||||
|
|
|||||||||||||
|
Oneder
|
JPS Virus Maker 3.
Exxied a few of these with Sandboxie stopping all I tried. http://www.virustotal.com/analisis/e6b1195aac95f4900b5f6a12477545f0 hxxp://vx.netlux.org/vx.php?id=tj04 |
||||||||||||
|
|
|||||||||||||
|
PiCo
|
edit://The fact that also 23 out of 35 scanners are able to scan -not to detect- the file is also strange! Does this mean they fail to scan it? AVs usually extract the content in a temp folder and scan it, so they might burst or sth!! |
||||||||||||||
|
|
|||||||||||||||
|
Buster
|
Several approachs can be used by avs to avoid this kind of problematic archives, like having a limit to the extracted files/folders, or having hard-coded the hashes of those archives and skipping their scanning if they are found. |
||||||||||||||||
|
|
|||||||||||||||||
|
PiCo
|
Thanx for the info Buster! This thread "Danger Zone" has all kind of weird stuff in it, I love it
|
||||||||||||
|
|
|||||||||||||
| Danger Zone |
|
||
|


Use the RSS feed to watch this topic for replies