Jump to content
daatdraqq

Bypassing Avast Sandbox Using Alternate Data Streaming

Recommended Posts

Posted (edited)

Introduction

Alternate data stream is supported by NTFS systems to aid the Macintosh

Hierarchical File System (HFS) that uses resource forks to store icons and other

information from a file.

Basically using Alternate Data Stream, users can easily hide files that go

unnoticed by some system administrators. Alternate Data Strem gives you the ability

to inject / add file data into existing files without affecting their functionality and

size.

This whithepaper will start with the basic use of Alternate Data Stream and

therefore this whitepaper show how to bypass Avast Sandbox.

It is not the focus of this whitepaper how to bypass antivirus using public

knowledge. However, aims to circumvent protection system AvastSandBox.

As a test system we used the operating system WindowsXP service pack2. For

a remote administration program was used metasploit.

Any knowledge found in this whitepaper is used with educational purposes

only and the author is not responsable for damages caused to third parties with

knowledge of this whitepaper.

Thanks, W1ckerMan.

Download:

http://dl.packetstormsecurity.net/papers/bypass/bypass-avast.pdf

Edited by Nytro
  • Upvote 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...