what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

crc32AV.txt

crc32AV.txt
Posted Mar 15, 2005
Authored by Bipin Gautam | Site geocities.com

It appears that some antivirus vendors allow zip archives with invalid CRC checksums to pass as clean.

tags | advisory
SHA-256 | 30230d15bf57169610a6c6eada332fd47468d80fe59fc45bb0c3406153eba193

crc32AV.txt

Change Mirror Download

Multiple AV Vendor Incorrect CRC32 Bypass
Vulnerability.

Affected Product:
AVG 718
Sybari (Antigen for M$ exchange) 7.5.1314
Symantec 8.0
McAfee 4442
BitDefender 7.0


Description:
if you create a zip archive with invalid CRC
checksum...... some AV skip scanning the archive
marking it as clean........ by this way, you can
bypass antivirus gateways and slip in any attachment
without scanning the archive. Moreover, these days....
software tools automatically repair a *broken*
archive.

Vendor notification: I've lost faith in responsible
disclosure... long ago! Moreover, vendors don't
respond in timely manner.

regards,
Bipin Gautam
http://www.geocities.com/visitbipin/


Disclaimer: The information in the advisory is
believed to be accurate at the time of printing based
on currently available information. Use of the
information constitutes acceptance for use in an AS IS
condition. There are no warranties with regard to this
information. Neither the author nor the publisher
accepts any liability for any direct, indirect or
consequential loss or damage arising from use of, or
reliance on this information.


__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    0 Files
  • 9
    Aug 9th
    0 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close