Safely Testing Your Anti-Virus
Old September 15th, 2007, 02:17 PM   #1 (permalink)
Gorilla
Afro Resident
 
Gorilla's Avatar
 
Gorilla is offline
Join Date: Jan 2005
Posts: 996
Thanks: 53
Thanked 106 Times in 76 Posts
Gorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud of
Rep Power: 28
Credits: 7,877
Safely Testing Your Anti-Virus

The European Institute for Computer Anti-Virus Research (EICAR) provides a standardized method for testing Anti-Virus implementations safely and effectively.

To create a test file is quite simple and straight forward.

Open a text editor and input the following string:

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

save the file.

Next, simply run a virus scan on the file and watch the fun.

Alternatively, test files can be downloaded from here: eicar | THE ANTI-VIRUS OR ANTI-MALWARE TEST FILE

Some other ways to have fun:
  • Testing out your own email protection.
  • Renaming the file to alternative file extensions. A few of my favorites are
  • *.com, *.exe, *.bat
  • Sending it to friends who are technically inclined and can take a joke. (I am in no way responsible for what happens with this one )
  • Placing the string in a simple program and then scanning the executable.
  • Compressing it into various formats.
  • Distorting the string to see how an anti-virus responds

Important Notes

This file only tests some of the functionality of Anti-Virus implementations. It does not test the complete reliability or detection rates of Anti-Virus products.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old September 15th, 2007, 04:40 PM   #2 (permalink)
DBlack
Founder

 
DBlack's Avatar
 
DBlack is offline
Join Date: Sep 2004
Location: Atlanta, GA
Posts: 7,564
Thanks: 330
Thanked 1,330 Times in 718 Posts
DBlack has a reputation beyond reputeDBlack has a reputation beyond reputeDBlack has a reputation beyond reputeDBlack has a reputation beyond reputeDBlack has a reputation beyond reputeDBlack has a reputation beyond reputeDBlack has a reputation beyond reputeDBlack has a reputation beyond reputeDBlack has a reputation beyond reputeDBlack has a reputation beyond reputeDBlack has a reputation beyond repute
Rep Power: 192
Credits: 377,476
So what is the point or value of running this test?
__________________

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old September 15th, 2007, 04:56 PM   #3 (permalink)
Gorilla
Afro Resident
 
Gorilla's Avatar
 
Gorilla is offline
Join Date: Jan 2005
Posts: 996
Thanks: 53
Thanked 106 Times in 76 Posts
Gorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud ofGorilla has much to be proud of
Rep Power: 28
Credits: 7,877
Quote:
Originally Posted by DBlack View Post
So what is the point or value of running this test?
It tests if its functional on a basic level and presence at the points you expect it to be defending threats. It has lots of other applications as well in terms of evaluating security.

Last edited by Gorilla : September 15th, 2007 at 05:02 PM.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 01:59 AM.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.0.0



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46