[13446] in bugtraq
Worldsecure/Mail 4.3 vulnerability
daemon@ATHENA.MIT.EDU (Andreas =?iso-8859-1?Q?K=FCchler?=)
Thu Jan 20 15:33:09 2000
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="------------357942BA9FCB7340391D36AB"
Message-Id: <3886D4CF.6682E2E5@giepa.de>
Date: Thu, 20 Jan 2000 10:26:39 +0100
Reply-To: Andreas =?iso-8859-1?Q?K=FCchler?= <andreas.kuechler@GIEPA.DE>
From: Andreas =?iso-8859-1?Q?K=FCchler?= <andreas.kuechler@GIEPA.DE>
X-To: bugtraq@securityfocus.com
To: BUGTRAQ@SECURITYFOCUS.COM
This is a multi-part message in MIME format.
--------------357942BA9FCB7340391D36AB
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit
Worldsecure uses anonymous ftp to transfer their virus patterns
automatically from their site download.worldtalk.com to the Worldsecure
server. Obviously Worldtalk does __NOT__ check any signatures after the
file has been downloaded and integrates them into the antivirus engine
of the WorldSecure/Mail server. There are two scenarios:
1) if anyone gets access to the pattern files on download.worldtalk.com
and replaces them with a modified version :
a) he can transport any file named *.dat to the users worldsecure server
(the server transports everything called *.dat that is embeded inside
the dat-xxxx.zip residing on the ftp server to a directory under
Worldtalk called after the pattern revision. All you have to do is to
find the actual revision number of mcafees dat-files, add one and place
a new dat on the ftp server. By doing this you reach __ANY__
WS/Mail-server with enabled autoupdate feature!
b) by replacing scan.dat with any file which is not a virus pattern the
virus engine will be unable to scan for any viruses any more... By the
way wherent there some exploits against MS FTP Service 4.0 !?! :-(
2) if anyone gets access to the local registry of a worldsecure/Mail
server he can modify the download site from where worldtalk retrieves
its updates. He can then acomplish the same thing as before. (only on
the smaller scope of one server)
The big problem is that the Worldsecure/Mail server uses any file as
virus pattern and actually scans with this modified file (I tried
wincmd.exe !!! renamed as scan.dat) without producing any warnings or
log entries. The administrator has only a chance to smell the mess when
he restarts the server because then the virus engine will not
initialize.
Worldtalk has been informed about this scenarios and admits that there
is a problem which will be solved in a future release of
Worldsecure/Mail.
--
Andreas Kuechler
\|/
(@ @)
------------------------oOO--(_)--OOo-------------------------
``` 444
Leiter Netzwerke und Service Giegerich & Partner GmbH
Daimlerstrasse 1H
+49 6103 5881 71 Voice 63303 Dreieich
+49 6103 5881 79 Fax Germany
http://www.giepa.de andreas.kuechler@giepa.de
==============================================================
Fingerprint 7DCE 2A53 CB6E 6DF9 CA20 B65B 0FE1 915A 2069 15BD
--------------357942BA9FCB7340391D36AB
Content-Type: text/x-vcard; charset=us-ascii;
name="andreas.kuechler.vcf"
Content-Transfer-Encoding: 7bit
Content-Description: Card for Andreas K|chler
Content-Disposition: attachment;
filename="andreas.kuechler.vcf"
begin:vcard
n:K|chler;Andreas
tel;fax:+49 6103 5881 79
tel;work:+49 6103 5881 71
x-mozilla-html:FALSE
url:http://www.giepa.de
org:Giegerich & Partner GmbH
adr:;;Daimlerstrasse 1h;Dreieich;Hessen;63303;Germany
version:2.1
email;internet:Andreas.Kuechler@giepa.de
title:Leiter Netzwerke und Service
note:http://www.giepa.de
x-mozilla-cpt:;-5808
fn:Andreas K|chler
end:vcard
--------------357942BA9FCB7340391D36AB--