[NT] Multiple Vendor Antivirus Software Fails to Access Maliciously Named Files

From: SecuriTeam (support_at_securiteam.com)
Date: 11/21/05

  • Next message: SecuriTeam: "[NEWS] Belkin Wireless Devices Authentication Bypass Vulnerability"
    To: list@securiteam.com
    Date: 21 Nov 2005 17:13:06 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Multiple Vendor Antivirus Software Fails to Access Maliciously Named Files
    ------------------------------------------------------------------------

    SUMMARY

    Windows system may use different kinds of special characters inside
    filenames, several anti-virus engines are unable to analyze these
    specially named files, allowing to bypass infected files.

    DETAILS

    Vulnerable anti-virus Engines:
     * Kaspersky Antivirus
     * Symantec AntiVirus
     * F-Prot Antivirus
     * ClamWin Antivirus
     * Avast Antivirus
     * RAV AntiVirus
     * Microsoft AntiSpyware

    Software tested :
     * Symantec AntiVirus Corporate version 8.0
     * Kaspersky Antivirus Personal Pro version 4.5.0.104
     * Kaspersky Antivirus For MS NTServer version 4.5.0.104
     * F-Prot Antivirus version 3.16c
     * ClamWin Antivirus version 0.87
     * Avast.Professional.Edition version 4.6.603
     * RAV.AntiVirus.Desktop version 8.6
     * Microsoft AntiSpyware version beta1

    Choose a malicious file which would be detected, such as nc.exe, rename
    the file as nc??.exe (?? =Hex C0 D7 BA DC) Then these malicious files will
    be not detected by Antivirus scan.

    Because these special names are unable directly to input, so if you want
    to run these file, you should use the following way:

       [ROOT@D:\Vul\bugtrap]#dir /x
       1998-01-03 14:37 59,392 NC294E~1.EXE nc??.exe
       [ROOT@D:\Vul\bugtrap]#NC294E~1.EXE -help
       [v1.10 NT]
       connect to somewhere: nc [-options] hostname port[s] [ports] ...
       listen for inbound: nc -l -p port [options] [hostname] [port]
       options:
       ...

    Uses the MS-DOS name specification, we can operate file with Open Read
    Write and duplicate

    In fact the most vendor all have the problem in regarding this king of
    file parse: For instance use the right key clicks these kinds of file,
    will be no scan option menu to show by Kaspersky Antivirus, and Symantec
    AntiVirus Corporate V10.0.1.1000 will detected but can't remove it. AVG
    Anti-Virus will be passed by normally path scan method, but can't read the
    file if click the scan option menu.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:alert7@xfocus.org> alert7.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NEWS] Belkin Wireless Devices Authentication Bypass Vulnerability"

    Relevant Pages

    • [REVS] GDI+ JPEG Exploit Mutations Can Bypass Antivirus Tests
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... It seems that most Antivirus software is unable to detect variants of the ... JPEG exploit. ... The original public exploit code uses a buffer overflow string near the ...
      (Securiteam)
    • [NT] Computer Associates eTrust EZ Antivirus Insecure File Permission
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Computer Associates eTrust EZ Antivirus is "antivirus protection software ... Local exploitation of an insecure permission vulnerability in Computer ...
      (Securiteam)
    • [NT] AntiVirus Filename Bypassing
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Several AntiVirus programs do not scan filesnames that contain ... Several AntiVirus programs do not scan files that contain extended ASCII ... Alt + "some numbers" generate specials ASCII characters. ...
      (Securiteam)
    • Re: 80+Running processes and 50%+ physical memory
      ... Sorry, I have to add sth., I also installed Acronis True Image 2009 to have more "professional" image backups, and Acronis Disk Director Suite 10 to resize the partition ... You are running two of the most problematic and resource-hungry applications out there: Zone Alarm and Symantec Antivirus. ... ---I am sorry that I use Zone Alarm Pro since using XP, and Symantec Antivirus Corporate Edition 10 does not seem to be that "resource-hungry"> I am so used to both of them. ...
      (microsoft.public.windows.vista.general)
    • Re: Best Antivirus Suite for SBS2003 is ?????
      ... Norton antivirus does suck. ... Make sure and get Symantec Antivirus 9.0 with Groupware protection for your ... > Ijust removed all our symantec antivirus and installed Trend's protection. ...
      (microsoft.public.windows.server.sbs)