[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20050311155528.91205.qmail@web31511.mail.mud.yahoo.com>
From: visitbipin at yahoo.com (bipin gautam)
Subject: Re: Multiple AV Vendor Incorrect CRC32 Bypass
Vulnerability.
In Local file header if you modify "general purpose
bit flag" 7th & 8'th byte of a zip archive with \x2f
ie: "\" F-port, Kaspersky, Mcafee, Norman, Sybari,
Symantec seem to skip the file marking it as clean!!!
This was discoverd during the analysis of "Multiple AV
Vendor Incorrect CRC32 Bypass Vulnerability."
Quick/rough conclusion were drawn using
www.virustotal.com
poc: http://www.geocities.com/visitbipin/gpbf.zip
regards,
bipin gautam
__________________________________
Do you Yahoo!?
Yahoo! Small Business - Try our new resources site!
http://smallbusiness.yahoo.com/resources/
Powered by blists - more mailing lists