[35286] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Multiple Antivirus Scanners DoS attack.

daemon@ATHENA.MIT.EDU (Ethy H. Brito)
Mon Jun 14 17:18:08 2004

Date: Mon, 14 Jun 2004 14:48:09 -0300
From: "Ethy H. Brito" <ethy@inexo.com.br>
To: bugtraq@securityfocus.com
Message-Id: <20040614144809.3ed816e5.ethy@inexo.com.br>
In-Reply-To: <BAY17-F32jMdiiRq5jP00147ef0@hotmail.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit

On Mon, 14 Jun 2004 14:38:50 +0000
"bipin gautam" <visitbipin@hotmail.com> wrote:

> Multiple Antivirus Scanners DoS attack.
> 
> --- [Vulnerable Products] ---
>       Only tested on...
> 
> * Norton Antivirus 2002
> * Norton Antivirus 2003
> * Mcafee VirusScan 6
> * Network Associates (McAfee) VirusScan Enterprise 7.1
> * Windows Xp default ZIP manager [report's wrong size of compress ZIP 
> files.]

Linux uvscan scan engine 4.3.20 (MacAfee) is also vulnerable.
uvscan takes all CPU and lots of memory been only killed with signal 9 from another terminal.

from 'top':
 PID USER     PRI  NI  SIZE  RSS SHARE STAT %CPU %MEM   TIME CPU COMMAND
1306 nobody    15   0 22744  21M  1648 R    97.4 35.6   0:44   0 uvscan

nobody@babalu:/usr/local/uvscan# ./uvscan -v -r --analyze --unzip BlackHole.zip 
Scanning BlackHole.zip
Scanning file BlackHole.zip
Scanning file BlackHole.zip/~.BZ2
  ..... stalls here .....

-- 

Ethy H. Brito         /"\
InterNexo Ltda.       \ /  CAMPANHA DA FITA ASCII - CONTRA MAIL HTML
+55 (12) 3941-6860     X   ASCII RIBBON CAMPAIGN - AGAINST HTML MAIL
S.J.Campos - Brasil   / \ 

home help back first fref pref prev next nref lref last post