exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Avira Antivir Generic Evasion

Avira Antivir Generic Evasion
Posted May 30, 2009
Authored by Thierry Zoller

The Avira Antivir Anti-Virus engine can by bypassed by specially crafted RAR, CAB, ZIP, and LH files.

tags | advisory, virus
SHA-256 | b507728df20115d41c0d77dcddee65a95d9169e3affd2bae91bb1bf6aaa9fc62

Avira Antivir Generic Evasion

Change Mirror Download
________________________________________________________________________

From the low-hanging-fruit-department
Avira Antivir generic RAR,CAB,ZIP,LH evasion
________________________________________________________________________

CHEAP Plug :
************
You are invited to participate in HACK.LU 2009, a small but concentrated
luxemburgish security conference. More information : http://www.hack.lu
CFP is open, sponsorship is still possible and warmly welcomed!
************

Release mode: Coordinated but limited disclosure.
Ref : [TZO-28-2009] - Avira Antivir generic RAR,CAB,ZIP
WWW : t.b.a
Vendor : http://www.avira.com
Status : Patched (Engine-Version: AV7 7.9.0.180 / AV8/9 8.2.0.180)
(Re)Discovered : 2005 by froggz, 2007 by Thierry Zoller, 2009 by Roger Mickael
(please give appropriate credit - only when notified and pressured
under disclosure terms vendors fix these, even if they are known
since years. PS this is not exclusive to AVIRA)
CVE : none provided
Credit : t.b.a
OSVDB vendor entry: none [1]

Security notification reaction rating : good
Notification to patch window : 22 days

Disclosure Policy : http://blog.zoller.lu/2008/09/notification-and-disclosure-policy.html

Affected products :
- Avira AntiVir Free
- Avira AntiVir Premium
- Avira AntiVir Premium Security Suite
- Avira AntiVir Professional (Desktop)
- Avira AntiVir Server
- Avira AntiVir Exchange
- Avira AntiVir SharePoint
- Avira AntiVir ISA Server
- Avira AntiVir MIMEsweeper
- Avira AntiVir for KEN! 4
- Avira AntiVir Virus Scan Adapter for SAP NetWeaver®
- Avira AntiVir Professional (Unix)
- Avira AntiVir Server (Unix)
- Avira AntiVir MailGate
- Avira AntiVir WebGate

I. Background
~~~~~~~~~~~~~
Quote: "Avira AntiVir is a reliable free antivirus solution, that constantly
and rapidly scans your computer for malicious programs such as viruses,
Trojans, backdoor programs, hoaxes, worms, dialers etc. Monitors
every action executed by the user or the operating system and reacts
promptly when a malicious program is detected."


II. Description
~~~~~~~~~~~~~~~
The Anti-virus engine could by bypassed by special crafted files. The root
cause was the same for RAR,CAB,ZIP,LH.

III. Impact
~~~~~~~~~~~
The engine could be bypassed remotely, the malware was no longer detected.
An issue especially with Gateway solutions. To know more about the impact
and type of "evasion", I updated the description at
http://blog.zoller.lu/2009/04/case-for-av-bypassesevasions.html


IV. timeline
~~~~~~~~~~~~~~~~~~~~~~~~~
DD/MM/YYYY

07/05/2009 : Send proof of concept, description the terms under which
I cooperate and the planned disclosure date.

08/05/2009 : Avira replies that "Roger Mickael" reported a similar issues

08/05/2009 : Sent another POC in other formats then reported previously

11/05/2009 : Avira asks for a delay

27/05/2009 : Avira informs me that "please be informed that we've just
released the fixed engine files to the public (27th of May,
19:19 pm CET): Engine-Version: AV7 7.9.0.180 / AV8/9 8.2.0.180

29/05/2009 : Release of this advisory.


[1]
Avira is encouraged to leave their security contact details at
http://osvdb.org/vendor/1/AVIRA%20GmbH to facilate
communication and reduce lost reports.
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close