Slashdot Log In
Open Source Malware Search Engine
Posted by
ScuttleMonkey
on Tue Jul 18, 2006 07:06 AM
from the in-case-your-computer-isn't-infected-already dept.
from the in-case-your-computer-isn't-infected-already dept.
chr0.ot writes "Metasploit creator HD Moore has released an open-source search engine that finds live malware samples through Google queries. From the article: 'The new Malware Search project provides a Web interface that allows anyone to enter the name of a known virus or Trojan and find Google results for Web sites hosting malicious executables.' The tool then searches for actual malware signatures and uses the signature output from ClamAV to find the name of the malware. This is then used in conjunction with a PE signature matching method to form a Google query. Afterwards the malware can then be downloaded directly from Google."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
So.. (Score:5, Funny)
How do the other engines stay in business?!?
Re:So.. (Score:2)
Re:So.. (Score:5, Funny)
So, basically, the Internet is exactly like real sex now, only easier to get.
Parent
Re:So.. (Score:3, Funny)
Finding malware with search engine? (Score:5, Insightful)
Re:Finding malware with search engine? (Score:4, Funny)
Parent
Re:Finding malware with search engine? (Score:5, Informative)
Also, this program supposedly highlights how relatively little malware Google actually indexes, contrary to the two earlier articles you cite. Thus this is an additional development, not a dupe.
Parent
Re:Finding malware with search engine? (Score:3, Informative)
Microsoft Version! (Score:3, Funny)
It looks like your searching for viruses,
well your in the right place.
ps, anyone else notice that slashdot is like waiting for a bus, you wait for hours with no updates then 4 come along all at once.
Hope the problems have been fixed now.
Re:Since we're off on a tangent anyway (Score:4, Funny)
I'm trying to read this sentence as if you were speaking it. And you sound sort of silly.
Parent
Re:Since we're off on a tangent anyway (Score:3, Funny)
Usually it's not worth the effort, but given this thread I just had too...
That should be:
You're being too kind.
I wish google would incorporate this into searches (Score:5, Interesting)
Transporter_ii
Re:I wish google would incorporate this into searc (Score:3, Informative)
So I am going to write a virus (Score:3, Funny)
BTW, Dupe, Dupity Dupe, Dupe.
Re:So I am going to write a virus (Score:4, Informative)
How can an article whose content says the earlier article was bogus be a dupe of the earlier article?
How can the initial announcement of a freely available tool be a dupe of the announcement of something that is not for public release?
Conclusion: there are a lot idjits on slashdot who have learned to waggle their fingers on the keyboard and therefore think they are clever. Oh so clever.
Slashdot has become the proving ground for kids who wanna grow up to be one of the million monkeys...
Parent
Thank God! (Score:3, Funny)
Re:Thank God! (Score:5, Insightful)
Parent
Re:Thank God! (Score:3, Informative)
How do you know?
How could [arstechnica.com] he know?
I wonder... (Score:3, Funny)
This is outright competition for their closed source malware search engine IE.
I use Windows (Score:5, Funny)
Re:I use Windows (Score:3, Funny)
Re:I use Windows (Score:4, Funny)
Just click start - search...
Parent
Can also be misread as... (Score:2)
Re:I guess I don't understand (Score:3, Informative)
You really should try the excelent ProcessExplorer from SysInternals [sysinternals.com].
Re:First it was a dupe... (Score:3, Informative)
The previous stories
(http://it.slashdot.org/article.pl?sid=06/07/15/12 53240 and http://it.slashdot.org/article.pl?sid=06/07/11/131 220 [slashdot.org])
were referring to another security research co who did something similar and then refused to share it.
This story is about someone not liking that they wont share, going a little bit further than they did and then putting it on a website and enabling it to the full.
I looked at the previo