{"id":24,"date":"2007-08-25T20:13:54","date_gmt":"2007-08-26T00:13:54","guid":{"rendered":"http:\/\/www.ragestorm.net\/blogs\/?p=24"},"modified":"2007-08-26T13:33:38","modified_gmt":"2007-08-26T17:33:38","slug":"tinype-made-the-world-a-safer-place-did-it","status":"publish","type":"post","link":"https:\/\/www.ragestorm.net\/blogs\/?p=24","title":{"rendered":"TinyPE Made The World a Safer Place, did it?"},"content":{"rendered":"<p>It&#8217;s pretty cool to see after a long while since I&#8217;ve started that project that many AV&#8217;s now find the concept of Tiny PE as a virus or a risky application. On the other hand, it&#8217;s not a virus, so why do you alert about it? But most people think of the Tiny PE project, specifically what I started &#8211; was to download a file\u00a0from the Internet and execute it. So it\u00a0came out that\u00a0the PE header was really fragile and yet it worked for Windows. So most AV&#8217;s and disassemblers didn&#8217;t even manage to parse it. That was only a side effect, later on, it was used with WebDAV to download the file directly by the Windows Loader using the name of a DLL as a URL(!), a real ownage.<\/p>\n<p>So now I see that the link to the file my proof of concept code downloads is &#8220;censored&#8221; by some AV&#8217;s. My code is really inocent, will open a mere message box. But I guess you can imagine where it can end. Here&#8217;s the output of some AV:<\/p>\n<p>http:\/\/ragestorm.net\/tiny\/_SANITIZED_\u00a0\u00a0\u00a0 # void<br \/>\nWhere the original file URL is: <a href=\"http:\/\/ragestorm.net\/tiny\/tiny3.exe\">http:\/\/ragestorm.net\/tiny\/tiny3.exe<\/a><a href=\"http:\/\/ragestorm.net\/tiny\/f.exe\"><\/a><\/p>\n<p>So it seems like it really made the world, or to be accurate the Internet, a safer place&#8230;although it wasn&#8217;t my real intention, because it was all started as a small bet with a friend and now see where it ended. Respect.<\/p>\n<p>PS: to be really accurate when I say AV I mean malware scanning systems.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s pretty cool to see after a long while since I&#8217;ve started that project that many AV&#8217;s now find the concept of Tiny PE as a virus or a risky application. On the other hand, it&#8217;s not a virus, so why do you alert about it? But most people think of the Tiny PE project, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":""},"categories":[5,4,18],"tags":[],"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbWKd-o","_links":{"self":[{"href":"https:\/\/www.ragestorm.net\/blogs\/index.php?rest_route=\/wp\/v2\/posts\/24"}],"collection":[{"href":"https:\/\/www.ragestorm.net\/blogs\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ragestorm.net\/blogs\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ragestorm.net\/blogs\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ragestorm.net\/blogs\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=24"}],"version-history":[{"count":0,"href":"https:\/\/www.ragestorm.net\/blogs\/index.php?rest_route=\/wp\/v2\/posts\/24\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.ragestorm.net\/blogs\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=24"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ragestorm.net\/blogs\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=24"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ragestorm.net\/blogs\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=24"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}