what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

bitdefend161.txt

bitdefend161.txt
Posted Jul 15, 2005
Authored by x a i t a x - s e c u r i t y | Site xaitax.de

The BitDefender engine versions 1.6.1 and below only scan the first attachment in a message and ignore the rest.

tags | advisory
SHA-256 | 56c9ad446f0c70ecbe1e3e540b0c55c8ba89ae58e8e86485f96db6d6fbebaccc

bitdefend161.txt

Change Mirror Download
--/  INTRODUCTION  --

Advisory : 05_07_14-bitdefender_malicious_content_bypass
Release Date : 14. July 2005
Application : BitDefender Antivirus
Impact : Malicious content bypass
Author : Alexander 'xaitax' Hagenah [ah at primepage dot de]


--/ SYSTEMS AFFECTED --

BitDefender running on Linux/BSD
* Engine 1.6.1 and prior


--/ VENDOR --

Informed : 04. July 2005
Response : 05. July 2005
Patched : 13. July 2005


--/ ABOUT --

BitDefender Antivirus & Antispam for Linux and FreeBSD Mail Servers

The BitDefender solutions for Mail Servers running on Linux and FreeBSD
platforms provide content security at the gateway level, by scanning
all the inbound and outbound e-mail traffic for malware and spam.


--/ SUMMARY --

The BitDefender-Mail Server Scan-Engine is vulnerable against a simple
attachment `attack'.
A Scan-Engine normally splits a mail into header, body and attachments.
So the Scan-Engine is easily able to scan all the attachments in it's
origin format.
If there is more than one element, it simply jumps to the following and
does it's job again.
Not this one - in this engine only the first element is counted and
scanned. If there is more than one attachment, the following ones are
ignored. So you could simply add somewhere into the mail the following
lines:

.--
| begin
| end
`--

Now the engine expect this to be the first attachment and stops
scanning the mail. So there is no problem to add an attachment with
malicious content which will be ignored by the BitDefender scanner.

This only depends to UUencoded mails. For more information about
UUencode take a look at http://en.wikipedia.org/wiki/Uuencode.


--/ REPRODUCE --

If the engine is somewhere productive running, you can test it - maybe
with EICAR as attachment - and put into the body the begin/end content.
If not, there is a evaluation version to download on the
bitdefender-page.


--/ PATCH --

The patch is automatically downloaded by the bitdefender update engine.
It works with all versions, because all updates are transferred into
Plugins/ directory.


--/ CONTACT --

This advisory is provided by:

- ( x a i t a x - s e c u r i t y ) -
http://xaitax.de | ah at primepage dot de

top concepts Internetmarketing GmbH
http://topconcepts.de | hagenah at topconcepts dot de


Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    0 Files
  • 14
    Nov 14th
    0 Files
  • 15
    Nov 15th
    0 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close