Ok ha ha ha
just another AV killer
we ( me and my good friend 0x16/7ton ) write POC that can be able kill AV
Securuty flaw allowed total manipulation with av soft. with this trick we able to inject code inside AV processes and for test we target Dr.web , As payload we choose injecting code into the original GUI process and sending special IOCTL to it driver and disable it self-protection ( for fun :mrgreen: we select sending ioctl , although killing it is simple without send anything )
we say this is universal method fro injection code inside AV process but need test over AV's
demo :
http://www.sendspace.com/file/bm7a8i
regard
just another AV killer
we ( me and my good friend 0x16/7ton ) write POC that can be able kill AV
Securuty flaw allowed total manipulation with av soft. with this trick we able to inject code inside AV processes and for test we target Dr.web , As payload we choose injecting code into the original GUI process and sending special IOCTL to it driver and disable it self-protection ( for fun :mrgreen: we select sending ioctl , although killing it is simple without send anything )
we say this is universal method fro injection code inside AV process but need test over AV's
demo :
http://www.sendspace.com/file/bm7a8i
regard
@R00tkitSMM