It appears that some antivirus vendors allow zip archives with invalid CRC checksums to pass as clean.
30230d15bf57169610a6c6eada332fd47468d80fe59fc45bb0c3406153eba193
Multiple AV Vendor Incorrect CRC32 Bypass
Vulnerability.
Affected Product:
AVG 718
Sybari (Antigen for M$ exchange) 7.5.1314
Symantec 8.0
McAfee 4442
BitDefender 7.0
Description:
if you create a zip archive with invalid CRC
checksum...... some AV skip scanning the archive
marking it as clean........ by this way, you can
bypass antivirus gateways and slip in any attachment
without scanning the archive. Moreover, these days....
software tools automatically repair a *broken*
archive.
Vendor notification: I've lost faith in responsible
disclosure... long ago! Moreover, vendors don't
respond in timely manner.
regards,
Bipin Gautam
http://www.geocities.com/visitbipin/
Disclaimer: The information in the advisory is
believed to be accurate at the time of printing based
on currently available information. Use of the
information constitutes acceptance for use in an AS IS
condition. There are no warranties with regard to this
information. Neither the author nor the publisher
accepts any liability for any direct, indirect or
consequential loss or damage arising from use of, or
reliance on this information.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com