<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Quickpost: &#8220;An Old IE Trick&#8221; Revisited</title>
	<atom:link href="http://blog.didierstevens.com/2008/11/01/quickpost-an-old-ie-trick-revisited/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2008/11/01/quickpost-an-old-ie-trick-revisited/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Sat, 11 Feb 2012 16:16:49 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2008/11/01/quickpost-an-old-ie-trick-revisited/#comment-33694</link>
		<dc:creator><![CDATA[Didier Stevens]]></dc:creator>
		<pubDate>Mon, 10 Nov 2008 18:18:44 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=848#comment-33694</guid>
		<description><![CDATA[What do you mean with &quot;signature based or pattern based&quot;? Are those 2 terms the same or different for you?

And I assume you&#039;re referring to the proposition that an algorithm that has to decide if a program is a virus or not, can be mathematically proved to be a special case to the Halting Problem, for which Turing proved it was undecidable?

I don&#039;t know the exact details of Fred Cohen&#039;s proof, but are you sure that this applies to signature based detection? Because signature based detection means that an algorithm has to decide if a file contains a given sequence or several sequences of bytes (i.e. the signature). I don&#039;t believe this particular algorithm is undecidable.

With signature based detection, it&#039;s the virus analyst defining the signature (I&#039;m excluding automatic signature generation here) that decides which samples are viruses.]]></description>
		<content:encoded><![CDATA[<p>What do you mean with &#8220;signature based or pattern based&#8221;? Are those 2 terms the same or different for you?</p>
<p>And I assume you&#8217;re referring to the proposition that an algorithm that has to decide if a program is a virus or not, can be mathematically proved to be a special case to the Halting Problem, for which Turing proved it was undecidable?</p>
<p>I don&#8217;t know the exact details of Fred Cohen&#8217;s proof, but are you sure that this applies to signature based detection? Because signature based detection means that an algorithm has to decide if a file contains a given sequence or several sequences of bytes (i.e. the signature). I don&#8217;t believe this particular algorithm is undecidable.</p>
<p>With signature based detection, it&#8217;s the virus analyst defining the signature (I&#8217;m excluding automatic signature generation here) that decides which samples are viruses.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous CS Guy</title>
		<link>http://blog.didierstevens.com/2008/11/01/quickpost-an-old-ie-trick-revisited/#comment-33683</link>
		<dc:creator><![CDATA[Anonymous CS Guy]]></dc:creator>
		<pubDate>Sat, 08 Nov 2008 00:50:28 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=848#comment-33683</guid>
		<description><![CDATA[There is this little thing called &quot;The Halting Problem&quot;. No algorithm will detect all possible variants regardless of the technique it uses - whether signature based or pattern based.]]></description>
		<content:encoded><![CDATA[<p>There is this little thing called &#8220;The Halting Problem&#8221;. No algorithm will detect all possible variants regardless of the technique it uses &#8211; whether signature based or pattern based.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sidephase</title>
		<link>http://blog.didierstevens.com/2008/11/01/quickpost-an-old-ie-trick-revisited/#comment-33678</link>
		<dc:creator><![CDATA[sidephase]]></dc:creator>
		<pubDate>Fri, 07 Nov 2008 17:31:42 +0000</pubDate>
		<guid isPermaLink="false">http://didierstevens.wordpress.com/?p=848#comment-33678</guid>
		<description><![CDATA[The one thing about BD from VirusTotal is that the engine it&#039;s using is the freebie one. Of course, that&#039;s an old engine...not exactly what I would call up to the task. I would love to test this out with the current version...]]></description>
		<content:encoded><![CDATA[<p>The one thing about BD from VirusTotal is that the engine it&#8217;s using is the freebie one. Of course, that&#8217;s an old engine&#8230;not exactly what I would call up to the task. I would love to test this out with the current version&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

