[Full-Disclosure] Re: Norton AntiVirus Scanner Remote DoS [temp. FIX!] [Part: !!!]

From: bipin gautam (visitbipin_at_yahoo.com)
Date: 07/09/04

  • Next message: Jelmer: "[Full-Disclosure] IE sucks : sun java virtual machine insecure tmp file creation"
    To: full-disclosure@lists.netsys.com
    Date: Fri, 9 Jul 2004 05:03:47 -0700 (PDT)
    
    

    --- Stuart Moore <smoore@securityglobal.net> wrote:
    > Bipin,
    >
    > Hi. When I download
    > http://www.geocities.com/visitbipin/EXTRACTit1st.zip
    > and then extract
    > it to REVANGE_tmm.tar.bz2 and then run NAV on the
    > bz2 file, Norton scans very quickly and
    > does not find any viruses.
    >
    > Am I doing something wrong? Is there really an
    > EICAR string in REVANGE_tmm.tar.bz2?
    >
    > Stuart
    >
    >

    EXTRACTit1st.zip wasn't ment for Notron
    antivirus........

    > There is an option to allow users to abort the scan.
    > Is it set ?

    (O;

    I don't think NAV engineers are still able to spot the
    problem;
    Lets HELP THEM OUT!

    The problem doesn't lie within the NAV virus scan
    engine; instead the

    problem lies within NAV file repair engine!

    Well, within few seconds... after the AV scan have
    started norton

    quickly scan's the infected file and smartly* skips
    the empty folder

    within the zip archive!

    But after norton detects virus in the archive it tries
    to delete the

    virus within the archive, and re-create the
    un-infected/fresh

    archive........ again!

    The problem triggers when NAV tries to re-create the
    50000 empty

    folders and construct the archive.

    *ANY* av scanners that autometically tries to delete
    the infected file

    and re-create the archive should be vulnerable to this
    exploit!!!

    Note: mark the fact... in the "AutoProtect Menu" of
    the option tab in

    Norton AV the option........

    *autometically repair the infected file <--- is set by
    default!

    you could temporarily be immune by this bug by setting
    the option,

    *deny access to the infected file.

    Did i just saved your MAIL SERVER??? (O;

    The compressed archive mustn't necessarily be a zip
    archive to trigger

    this attack. You could experiment this with other
    archive types......

    HAS ANYONE TRIED THE EXPLOIT ON SOME OTHER AV
    SCANNERS??????

    These are time's when you want to download some other
    AV scanners for a 30 days evaulation... There is a
    high chance you may never switch back again!

    bipin gautam
    http://www.geocities.com/visitbipin/

                    
    __________________________________
    Do you Yahoo!?
    Yahoo! Mail - 50x more storage than other providers!
    http://promotions.yahoo.com/new_mail

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Jelmer: "[Full-Disclosure] IE sucks : sun java virtual machine insecure tmp file creation"

    Relevant Pages

    • Re: SP2 and Norton Antivirus
      ... How do you download the WMI patch if you don't have NAV 2004? ... >Do you happen to have Norton 2003? ...
      (microsoft.public.windowsxp.general)
    • Re: SP2 and Norton Antivirus
      ... I received my WMI update for NAV 2003 through Autoupdate this morning. ... >>How do you download the WMI patch if you don't have NAV 2004? ... >>>I do have Norton 2003. ...
      (microsoft.public.windowsxp.general)
    • Re: Need advise about Anti-virus and firewalls.
      ... >>Yep, Norton is only for computers with large amounts of RAM, I suggest only ... the Symantec product stopped more threat vectors. ... improvements since I tested, however so has NAV. ... Performance hit on game play can be mitigated under NAV by tweaking ...
      (alt.computer.security)
    • Re: Norton Plug-in (+Norton)
      ... When I bother to look at what NAV and also ZoneAlarmPro have caught, ... Word MVP FAQ site: http://word.mvps.org ... Clear the check box for "Enable Office Plug-in." ... Do I activate the Norton software on my laptop when it ...
      (microsoft.public.word.newusers)
    • Various Vulnerabilities in Norton Anti-Virus 2002
      ... Various Vulnerabilities in Norton Anti-Virus 2002 ... We encountered 4 vulnerabilities in NAV 2002 email protection feature. ...
      (Bugtraq)