Главная
Study mode:
on
1
Intro
2
Breaking antivirus software
3
Attack surface
4
Attacking antivirus engines
5
Vulnerabilities in AV engines
6
Fuzzing statistics
7
Exploiting AV engines (more tips)
8
Exploiting AV engines: Summary
9
Forticlient
10
Kaspersky
11
Comodo Antivirus
12
Notes about decompression bombs
13
BitDefender engine
14
BitDefender bugs
15
BitDefender notes
16
Comodo example vulnerability
17
Comodo Bugs
18
Security enhanced software
19
DrWeb antivirus
20
DrWeb updating protocol vulnerability
21
eScan for Linux remote root
22
Conclusions
23
Recommendations for AV companies
Description:
Explore the vulnerabilities and security issues in antivirus software through this 58-minute conference talk presented by Joxean Koret at the 44CON Information Security Conference. Delve into the often-overlooked aspects of AV software security, from home systems to corporate and government servers. Discover techniques for vulnerability discovery and remote exploitation of AV software, with detailed examples of vulnerabilities in popular antivirus engines. Learn about attack surfaces, fuzzing statistics, and exploitation methods for various AV products including Forticlient, Kaspersky, Comodo, BitDefender, and DrWeb. Gain insights into decompression bombs, security-enhanced software, and remote root vulnerabilities. Conclude with valuable recommendations for AV companies to improve their product security, aiming to raise awareness among both users and vendors about the critical importance of securing antivirus solutions.

Breaking AV Software

44CON Information Security Conference
Add to list
0:00 / 0:00