多个供应商的病毒扫描回收站排除漏洞

多个供应商的病毒扫描回收站排除漏洞

漏洞ID 1105653 漏洞类型 其他
发布时间 1999-12-22 更新时间 2005-10-20
图片[1]-多个供应商的病毒扫描回收站排除漏洞-安全小百科CVE编号 CVE-2000-0119
图片[2]-多个供应商的病毒扫描回收站排除漏洞-安全小百科CNNVD-ID CNNVD-199912-076
漏洞平台 Windows CVSS评分 7.2
|漏洞来源
https://www.exploit-db.com/exploits/19733
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-199912-076
|漏洞详情
McAfee病毒扫描和Norton反病毒病毒检查程序中的默认配置存在漏洞,攻击者利用该漏洞存储未经检测的恶意代码,导致McAfee病毒扫描和Norton反病毒病毒检查程序不能检测回收站Recycled文件夹中的文件。
|漏洞EXP
McAfee VirusScan 4.0,Network Associates VirusScan for Windows NT 4.0.2/4.0.3 a,Symantec Norton AntiVirus 2000 Recycle Bin Exclusion Vulnerability

source: http://www.securityfocus.com/bid/956/info

Many commercial virus scanners for Windows platforms exclude the Recycled folder on the hard drive from their scans. The Recycled folder is where Win9x operating systems keep files that have been deleted via the GUI but not purged from the Recycle Bin. Files of any nature can be manually placed in the Recycled folder. Therefore, it is possible for any user or program to put code into that folder that will never be subject to virus scans.

Although WinNT makes use of a folder called 'Recycler' for similar purposes, many virus scanners for NT still have the 'Recycled' folder listed in the exclusions.

Note that other virus scanners than those listed under the 'info' tab may be vulnerable as well. 

This exploit will install a 'decoy' executable to the desktop, and install a file (winsetup.dll) containing an eicar.com virus signature into the Recycled folder. The hostile code is originally XORed with 25 to get it past active detection, but is then restored to its regular executable state after being placed into the recycled folder.

The zip file contains the executable exploit, and source for the installer and the decoy. 

https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/19733.zip
|参考资料

来源:BUGTRAQ
名称:20000130BypassVirusChecking
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=94936267131123&w;=2

相关推荐: HP Apollo Domain/OS /etc/suid_exec漏洞

HP Apollo Domain/OS /etc/suid_exec漏洞 漏洞ID 1207747 漏洞类型 未知 发布时间 1990-12-31 更新时间 2005-05-02 CVE编号 CVE-1999-1115 CNNVD-ID CNNVD-19901…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享