ICT Security-Sécurité PC et Internet
87.1K views | +0 today
Follow
ICT Security-Sécurité PC et Internet
ICT Security + Privacy + Piracy + Data Protection - Censorship - Des cours et infos gratuites sur la"Sécurité PC et Internet" pour usage non-commercial... (FR, EN+DE)...
Curated by Gust MEES
Your new post is loading...
Your new post is loading...
Scooped by Gust MEES
Scoop.it!

AV engines are riddled with exploitable bugs

AV engines are riddled with exploitable bugs | ICT Security-Sécurité PC et Internet | Scoop.it
A security researcher has found a great number of exploitable vulnerabilities in popular security solutions and the AV engines they use, pro...


Most (if not all...) antivirus engines run with the highest privileges: root or local system," he noted. "If one can find a bug and write an exploit for the AV engine, (s)he just won root or system privileges."

Finally, most AVs get updates via HTTP only protocols, which could lead to man-in-the-middle attacks that deliver malware instead of updates.





Gust MEES's insight:

Most (if not all...) antivirus engines run with the highest privileges: root or local system," he noted. "If one can find a bug and write an exploit for the AV engine, (s)he just won root or system privileges."

Finally, most AVs get updates via HTTP only protocols, which could lead to man-in-the-middle attacks that deliver malware instead of updates.


No comment yet.
Rescooped by Gust MEES from 21st Century Learning and Teaching
Scoop.it!

Kopfgeld für Bugs in Antivirensoftware

Kopfgeld für Bugs in Antivirensoftware | ICT Security-Sécurité PC et Internet | Scoop.it
In der Security-Branche ungewöhnlich, bei anderen Produkten längst Usus: Avast führt eine Belohnung für das Melden von Sicherheitslücken in der eigenen Antivirensoftware ein.
Gust MEES's insight:

Ein MUST!