Re: Aladdin response regarding eSafe

From: 3APA3A (3APA3A_at_SECURITY.NNOV.RU)
Date: 07/28/04

  • Next message: Thierry Carrez: "[ GLSA 200407-22 ] phpMyAdmin: Multiple vulnerabilities"
    Date: Wed, 28 Jul 2004 21:45:03 +0400
    To: Ofer Elzam <ofere@hotmail.com>
    
    

    Dear Ofer Elzam,

    Of cause, this approach makes no problems in catching, for example,
    known ITW worms as executables or archives. Problems begin if you're
    trying to catch, lets say sites with Internet Explorer trojans. Remember
    Scob? Imagine what happens if Scob added to a page as a header instead
    of a footer. 80% and even 5% of the page have a good chance to contain
    fully working version of Scob before connection is terminated by filter.

    I know this problem it not eSafe specific. In fact, I don't know
    antiviral engine capable to catch signature in the stream of data
    immediately after signature is arrived in the stream. All antiviral
    engines I tested (KAV, ClamAV and others) are file-oriented. It makes it
    impossible to code good antiviral protection for proxy server with this
    engines.

    --Wednesday, July 28, 2004, 7:52:14 PM, you wrote to bugtraq@securityfocus.com:

    OE> In-Reply-To: <18610004519.20040724152743@SECURITY.NNOV.RU>

    OE> eSafe Gateway uses a default value of 80% file download before
    OE> first inspection of executable files from HTTP servers. This value
    OE> can be changed to as low as 5% if desired.
    OE> We feel that the 80% gives a good balance between user
    OE> experience and security needs. Customers would usually want to see a
    OE> fast moving download progress bar. If we set the value to 5% - the
    OE> progress bar will move just a little bit (5%) when downloading and
    OE> the remaining 95% very fast as eSafe finishes the inspection. This
    OE> annoys users.

    OE> If antiviral filter checks data _after_ all data received from client
    OE> with 20% buffering yes, it's possible to bypass this check for HTTP,
    OE> because there is no way (at least for HTTP/1.0 and FTP) to indicate
    OE> error to client and make him to delete partially downloaded data.

    -- 
    ~/ZARAZA
    Пока вы во власти провидения, вам не удастся умереть раньше срока. (Твен)
    

  • Next message: Thierry Carrez: "[ GLSA 200407-22 ] phpMyAdmin: Multiple vulnerabilities"

    Relevant Pages

    • bindingRedirect and COM-interop
      ... I think it's supposed to work with unmanged executables. ... LOG: Where-ref bind. ... LOG: Assembly download was successful. ... Host configuration file not found. ...
      (microsoft.public.dotnet.framework.interop)
    • Aladdin response regarding eSafe
      ... eSafe Gateway uses a default value of 80% file download before first inspection of executable files from HTTP servers. ... Testing this technique with EICAR is very specific as EICAR is not like typical real viruses; it is only a few bytes in length. ... In any case, if a future virus that can cause damage even when only a few bytes are downloaded is discovered, eSafe has the right technology to identify and block it. ... client will not be able to use "Range:" header to resume partially ...
      (Bugtraq)
    • Re: Need to restrict access to an EXE in IIS6
      ... Enable authentication protocol and disable anonymous access for support.exe ... Make sure "Scripts and Executables" is not enabled because you want ... Set NTFS permission on support.exe to only allow Read access to the ... > file to Deny for Everyone, it will still download ...
      (microsoft.public.inetserver.iis.security)
    • Forefront Scan Engines Not Downloading
      ... A few days ago I installed FF Security for Exchange SP1 on SBS 2008 Premium. ... All scan engines have auto downloaded and are kept updated apart from two ... An error occurred during the download procedure. ...
      (microsoft.public.windows.server.sbs)
    • Re: Fritz
      ... You can download a fritz version. ... For the record Fritz v5.32 I think it is was freely available on the ... as will various other free engines on their website. ... Martin Brown ...
      (rec.games.chess.computer)