Re: [Full-Disclosure] Exploiting Multiple Flaws in Symantec Antivirus 2004 for Windows Mobile

From: 3APA3A (3APA3A_at_SECURITY.NNOV.RU)
Date: 09/17/03

  • Next message: Mandrake Linux Security Team: "[Full-Disclosure] MDKSA-2003:090-1 - Updated openssh packages fix buffer management error"
    To: auto9115@hushmail.com
    Date: Wed, 17 Sep 2003 19:39:57 +0400
    
    

    Dear auto9115@hushmail.com,

    --Tuesday, September 16, 2003, 11:59:22 PM, you wrote to full-disclosure@lists.netsys.com:

    ahc> Like any antivirus scanner, Symantec detects the Eicar test virus
    ahc> (eicar.exe or eicar.txt). At least, at first glance it appears to
    ahc> detect it. However, you can easily defeat this by adding a few
    ahc> bytes of random text before or after the Eicar string. For example,
    ahc> if you use a hex/text editor

    Probably you misunderstand what antiviral signature is. It's not some
    virus substring. Than researching virus, antiviral vendor makes an
    algorithm to catch virus behavior. If this virus is mutating, all
    _possible_ mutations must be catched by signature. The problem is, EICAR
    with 'few random bytes' is not possible mutation for EICAR, so catching
    it is not required for antiviral product :). And even more: catching
    changed EICAR string is invalid behaviour. In this case, you will not be
    able to read EICAR string on the web page or read it in e-mail message,
    as it was suggested by EICAR developers, because your antivirus will
    incorrectly think message or page is infected.

    -- 
    ~/ZARAZA
    Клянусь лысиной пророка Моисея - я тебя сейчас съем. (Твен)
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Mandrake Linux Security Team: "[Full-Disclosure] MDKSA-2003:090-1 - Updated openssh packages fix buffer management error"

    Relevant Pages

    • Re: eSafe: Could this be exploited?
      ... the eicar virus. ... Of course I have configure esafe to block virus infected emails ... > error to client and make him to delete partially downloaded data. ...
      (Bugtraq)
    • Re: [Full-Disclosure] [suse-security] Anti-Virus Problem
      ... EICAR is executable file and eicar string ... BS> Antivir seems to be an evaluation version. ... BS> an infected attachment or simply copy the virus string on the mail, ...
      (Full-Disclosure)
    • Re: Is Plain Text email 100% safe?
      ... If EICAR: Not really. ... It's not a virus - it just triggers the alarm. ... There used to be a time when plain text messages containing well crafted ...
      (microsoft.public.security.virus)
    • Re: eSafe: Could this be exploited?
      ... > the eicar virus. ... > Of course I have configure esafe to block virus infected emails ... The issue was seen with both v3.5 in CVP mode as well as v4 in bridging ... No further labtest were done to see if a full live EICAR version ...
      (Bugtraq)
    • Re: Testing e-mail antivirus protection
      ... I know there is a string by Eicar that will test the installed ... Avira AntiVir Personal - FREE Antivirus http://www.free-av.com/ ... scanning email is worthless. ...
      (alt.comp.anti-virus)

  • Quantcast