Re: Corsaire Security Advisory - Clearswift MAILsweeper MIME attachme nt evasion issue

From: http-equiv@excite.com
Date: 03/08/03

  • Next message: descript: "Win32hlp exploit for : ":LINK overflow""
    Date:         Sat, 8 Mar 2003 16:41:29 -0000
    From: "http-equiv@excite.com" <http-equiv@MALWARE.COM>
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    <!--

    Step 2: Now create a text file that will be used to hold the MIME
    encoded attachment. Start notepad (or another text editor), and paste
    in:

         MIME-Version: 1.0
         Content-Location:file:///executable.exe
         Content-Transfer-Encoding: base64

         TVp0AQIAAAAgAAgA//8YAIAAAAAQAAIAHgAAAAEAAAAAA
         AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
     -->

    That's a very interesting situation with content filters and anti-
    virus filters. How many others are affected one must wonder.

    Try the following as well, nothing more than pure binary:

    http://www.malware.com/bin.exe.zip

    MIME-Version: 1.0
    Content-Location:file://foo.exe
    Content-Transfer-Encoding: binary

    MZD ! ÿÿu ™ > û0jr y
    ž

    Lot more where that came from.

    End Call

    --
    http://www.malware.com
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Have you discovered a security vulnerability related to Windows or a
    commercial product which runs on Windows?
    Need assistance crafting the format or translating your advisory to English?
    Need to verify it, or having problems contacting the Vendor?
    Contact mailto:Advisories@NTBugtraq.com
    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    

  • Next message: descript: "Win32hlp exploit for : ":LINK overflow""

    Relevant Pages

    • Re: Text Editor
      ... My biggest gripes about it were: ... size of a file that can be opened (unless they changed it since Windows ME). ... program as simple as Notepad wouldn't have so many bugs. ... take me long to replace it with a halfway decent text editor. ...
      (alt.os.linux.suse)
    • Re: Zeichensatz Linux vs. Windows
      ... Ich meinte das kleine Notepad (Editor genannt). ... In Windows nutze ich TecniX-Center, ... Standard setzen, da man sonst schnell mal durcheinander kommt, was auf ...
      (de.comp.os.unix.linux.misc)
    • Re: Help! Lost the editor in UCB Logo
      ... could not launch the editor. ... I selected Notepad as my editor when I did ... Logo just tries to launch "notepad.exe" without specifying a directory, ... Logo's entries in the Windows registry got messed up. ...
      (comp.lang.logo)
    • Re: end of print = lower productivity ?
      ... In Vim, I'd do something ... It's my editor of choice when I'm stuck in ... Windows, and as a long-time member of the vim mailing list, ... comes from unix-like world that use vim instead of Notepad, Notepad2, ...
      (comp.lang.python)
    • Re: How to make the SWI-Prolog edit command invoke gvim instead of Notepad on Windows 2000
      ... Notepad on Windows 2000. ... % Waiting for editor ... ... Well, perhaps in your installation, because in my Windows XP, it works as directed in the FAQ. ... You showed above calling a unixy command 'pwd'. ...
      (comp.lang.prolog)