Magic Byte Analysis .. Is it really a vulnerability?
The whole issue gives rise to an interesting discussion: is this actually a vulnerability?
As the (complete) file's hash has been changed, it's no longer exactly the same file. This means that the malicious file is technically a new variant or even a new malware(virus), not the same old malware. So in my opinion this is not a real vulnerability. The question is, does the so-called 'vulnerability' pose a real threat?
I don't think so. Of course, it remains to be seen exactly how this 'vulnerability' will be exploited. Anyway most AV vendors are adding a new feature... It's a little bit like detecting a new virus. It's not a vulnerability.
<< Home