Post Reply 
Remove Obfuscated Code [20081221b]
Dec. 17, 2008, 04:22 PM
Post: #2
RE: Remove Obfuscated Code [20081216]
Thanks, KyeU, for this filter. Looks like it replaces the PoC code with this:
Code:
var shellcode = unescape["%u0066%u006F%u006F%u0062%u0061%u0072
^ change [ to (
This seems cause Avira to quarantine the whole thing even with WebGuard disabled. Smile! Just thought I'd let you know.

Thanks again,
DarthTrader.

**Edited by Kye-U: the filter is matching the code in this post**
Add Thank You Quote this message in a reply
Post Reply 


Messages In This Thread
Remove Obfuscated Code [20081221b] - Kye-U - Dec. 17, 2008, 03:30 AM
RE: Remove Obfuscated Code [20081216] - DarthTrader - Dec. 17, 2008 04:22 PM
RE: Remove Obfuscated Code [20081216] - Kye-U - Dec. 17, 2008, 06:11 PM
RE: Remove Obfuscated Code [20081216] - z12 - Dec. 20, 2008, 12:53 PM
RE: Remove Obfuscated Code [20081216] - Kye-U - Dec. 20, 2008, 07:06 PM
RE: Remove Obfuscated Code [20081220a] - Kye-U - Dec. 20, 2008, 10:34 PM
RE: Remove Obfuscated Code [20081220a] - Kye-U - Dec. 20, 2008, 11:05 PM
RE: Remove Obfuscated Code [20081220b] - z12 - Dec. 21, 2008, 12:50 AM
RE: Remove Obfuscated Code [20081220b] - Kye-U - Dec. 21, 2008, 03:28 AM
RE: Remove Obfuscated Code [20081221b] - Kye-U - Dec. 21, 2008, 08:32 PM
RE: Remove Obfuscated Code [20081221b] - Kye-U - Dec. 22, 2008, 03:39 AM
RE: Remove Obfuscated Code [20081221b] - z12 - Dec. 22, 2008, 10:58 AM

Forum Jump: