~BD~, on Sep 20 2008, 11:51 AM, said:
Thanks for your comments, Dustin.
Is there any way that I - as a non-techie guy - can determine if a site
actually contains
malicious code, as you call it?
I'll be happy to explore on my own and send samples to you. Just tell me how to find/recognise it!
Dave
PS Shouldn't you be out and about enjoying yourself on a Saturday?!!
Their are several ways you can use to try and determine if a site has malicous code present. However, as Bruce has already mentioned, it only takes one screwup and you can be in serious trouble. If you do not have a test machine and/or reliable vm, this isn't something i'd recommend doing, unless you have really good reliable backups present.
Bruce has mentioned ProcessGuard, and if used properly it's a fine program. Very useful for obtaining malicious samples.
Depending on the malware in question, I'm known personally for Sandboxing it with Sandboxie, but again, if not used properly you can miss things (files the host is trying to remove for example) and/or still infect yourself.
For site code analysis, vurl is a nice app.
This is really a 7 days a week kind of thing Dave. Malware authors don't take days off. And for the time being atleast, neither can we.