skip to main | skip to sidebar

Neoava Guard

Neoava Guard is a Host-based Intrusion Prevention System (HIPS) software, which helps you protect your computer against malicious softwares. Neoava Guard allows you to completely control any suspicious action in your computer. By the way, Neoava has some innovative features to let you experience better protection and less wrong alerts.

Thursday, August 17, 2006

low-level disk access

thanks Krazaf,

after a new sample from Krazaf, I successfully found how this kind of attack can be detected.

it is not hard to implement and should take some hours/1 day.

I'll work on it, tomorrow.
Posted by Arman Nayyeri at 10:16:00 PM

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Blog Archive

  • ►  2015 (1)
    • ►  February (1)
  • ►  2007 (13)
    • ►  October (1)
    • ►  August (1)
    • ►  July (2)
    • ►  June (1)
    • ►  May (2)
    • ►  April (1)
    • ►  March (2)
    • ►  February (1)
    • ►  January (2)
  • ▼  2006 (23)
    • ►  November (1)
    • ►  October (2)
    • ►  September (4)
    • ▼  August (9)
      • learning-mode
      • driver file modification protection
      • Direct physical memory access & driver loading
      • Attacking Host-based Intrusion Prevention Systems
      • partition table protection done
      • low-level disk access
      • GeSwall incompatibility
      • everything is fine
      • debugging
    • ►  July (7)

About Me

My photo
Arman Nayyeri
I'm a security software developer who worked on Neoava Guard project.
View my complete profile

Links

  • Neoava Guard
  • Neoava Guard Support Forums
  • Arman Nayyeri

Hit Counter

 

Neoava Guard

Neoava Guard