what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

TZO-012005-Fprot.txt

TZO-012005-Fprot.txt
Posted Nov 3, 2005
Authored by Thierry Zoller | Site thierry.sniff-em.com

The F-Prot engine fails to decompress ZIP files that have a version header greater then 15. The consequence is that the F-prot Engine is unable to scan the virus/malware inside and consequently flags it as harmless. If used as an Email Gateway solution the offending Emails will slip through.

tags | advisory, virus
SHA-256 | 84a0def1156ec4829f01d470e51e93f26500ba11e4fc5b0989eaa0d50dedd25a

TZO-012005-Fprot.txt

Change Mirror Download
_______________________________________________________________________

F-Prot/Frisk Anti Virus bypass - ZIP Version Header
_______________________________________________________________________


Ref : TZO-012005-Fprot
Author : Thierry Zoller / Security Engineer
WWW : http://thierry.sniff-em.com
Article : http://thierry.sniff-em.com/research/fprot.html


I. Background
~~~~~~~~~~~~~

http://www.f-prot.com/products/corporate_users/

FRISK Software International has, since it was first established in 1993,
consistently maintained its position as one of the world's leading companies
in antivirus research and product development.

FRISK Software produces the hugely popular F-Prot Antivirus products range
offering unrivalled neural network and heuristic detection capabilities.
In addition to this, the F-Prot AVES managed online e-mail security service
filters away the nuisance of spam e-mail as well as viruses, worms and other
malware that increasingly clog up inboxes and threaten data security.

F-Prot Antivirus for Windows
F-Prot Antivirus for Microsoft Exchange
F-Prot Antivirus for Linux x86 / BSD x86
F-Prot Antivirus for AIX
F-Prot Antivirus for DOS
F-Prot Antivirus for Solaris SPARC / Solaris x86
F-Prot Antivirus for AIX

II. Description
~~~~~~~~~~~~~~~

The F-prot engines fails to decompress ZIP files that have a version
header greater then 15. The consequence is that the F-prot Engine
is unable to scan the virus/malware inside and consequently flags
it as harmless. If used as an Email Gateway solution the offending
Emails will slip through.

Local ZIP file header:
local file header signature 4 bytes (0x04034b50)
version needed to extract 2 bytes

Winzip, Winrar, MS Zip engine decompress fine.

Tested offset :
Offset 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
00000000 50 4B 03 04 15 00 00 00 00 00 88 80 38 33 3C CF
00000016 51 68 44 00 00 00 44 00 00 00 09 00 00 00 65 69

In this example byte 4 has the version header value 15. F-prot fails to
decompress the ZIP files with a version header greater then 15.

Solution:
The ZIP decompression engine should ignore the Version header of the
ZIP file and nonetheless decompress the file whatever the version
field indicates.


III. Summary
~~~~~~~~~~~~~~~
Vendor contact : 30/10/2005
Vendor Response : 01/11/2005

Thank you very much for notifying us of this bug in the current version of
F-Prot Antivirus. A fix for this bug will be included in future versions
of F-Prot Antivirus.

IV. Thanks
~~~~~~~~~~~~~~~
http://virusscan.jotti.org/
http://www.virustotal.com



_______________________________________________________________________

Reference : TZO-012005-Fprot
Author : Thierry Zoller / Security Engineer
WWW : http://thierry.sniff-em.com

Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    34 Files
  • 18
    Jul 18th
    6 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close