Sponsored by..

Thursday 3 January 2008

JS/Exploit-BO false positive in McAfee

In what looks like a re-run of a recent false positive from eTrust, McAfee Anti-Virus is detecting JS/Exploit-BO in a number of innocent javascript applications, including Mootools. It's likely that McAfee is detecting the Dean Edwards Packer Tool as malware, although that's just an innocent application. Pattern 5197 has the problem, upgrading the signatures to pattern 5198 or later should fix it.

Unfortunately I guess this goes to show that packer tools can be a menace. There have been reports of this tool being used to obfuscate malware, so the smart advice to javascript developers is probably to not encode, compress or encrypt your code in any way if you want it to be trusted.

No comments: