BugTraq
eSafe: Could this be exploited? Jul 23 2004 06:21PM
Hugo van der Kooij (hvdkooij vanderkooij org) (3 replies)
Re: eSafe: Could this be exploited? Jul 24 2004 11:27AM
3APA3A (3APA3A SECURITY NNOV RU) (2 replies)
Re: eSafe: Could this be exploited? Jul 26 2004 05:26AM
MegaHz (megahz gmail com) (1 replies)
Re: eSafe: Could this be exploited? Jul 26 2004 08:26PM
Hugo van der Kooij (hvdkooij vanderkooij org) (1 replies)
On Mon, 26 Jul 2004, MegaHz wrote:

> I have tested it out, and esafe blocked the hole email that contains
> the eicar virus.
> Of course I have configure esafe to block virus infected emails
> instead of modifying them and removing the virus.

SMTP (or SMTP via CVP) is handled as a store and forward mechanisme. Hence
the 80% rule does not apply.

The issue was seen with both v3.5 in CVP mode as well as v4 in bridging
mode. No further labtest were done to see if a full live EICAR version
could be passed along.

If someone is able to create a test executable based on the EICAR string
the point might be proven. Unfortunatly I am not a programmer and lack
window compiler tools all together. But if someone thinks (s)he can create
a sample binary that may run when the last bit is shot to pieces and still
contain a valid EICAR definition to show to the screen the issue might be
proven.

Putting it on a webserver and posting the URL would allow anyone who wants
to to verify the issue themselves.

Hugo.

--
All email sent to me is bound to the rules described on my homepage.
hvdkooij (at) vanderkooij (dot) org [email concealed] http://hvdkooij.xs4all.nl/
Don't meddle in the affairs of sysadmins,
for they are subtle and quick to anger.

[ reply ]
Re: eSafe: Could this be exploited? Jul 28 2004 09:30AM
Kev Ford (kev frod co uk) (1 replies)
Re: eSafe: Could this be exploited? Jul 30 2004 12:34AM
Nick FitzGerald (nick virus-l demon co uk)
Re: eSafe: Could this be exploited? Jul 25 2004 02:24PM
Andreas Constantinides (MegaHz) (megahz megahz org)
Re: eSafe: Could this be exploited? Jul 24 2004 01:22AM
Nick FitzGerald (nick virus-l demon co uk)
Re: eSafe: Could this be exploited? Jul 23 2004 07:49PM
Oliver (at) greyhat (dot) de [email concealed] (Oliver greyhat de)


 

Privacy Statement
Copyright 2010, SecurityFocus