List Info

Thread: New: non-standard base64 encoding evades some scanners




New: non-standard base64 encoding evades some scanners
user name
2006-12-08 00:05:37
Kenneth Porter wrote:

> I just saw this on the SA-devel list. Note that ClamAV
0.88.6 is listed
> as vulnerable.

However, it is *not* vulnerable if you use the standard
MIMEDefang ClamAV
integration functions.

MIMEDefang passes virus scanners both the raw MIME message
and all the parts
as decoded by MIME::tools.  This design decision was made so
that MIME::tools
could work around any bugs in an AV tools' MIME decoder and
vice-versa.

The proof-of-concept test didn't make it past our test
MIMEDefang system.

Regards,

David.
_______________________________________________
NOTE: If there is a disclaimer or other legal boilerplate in
the above
message, it is NULL AND VOID.  You may ignore it.

Visit http://www.mimedefang.org and http://www.roaringpengu
in.com
MIMEDefang mailing list MIMEDefanglists.roaringpenguin.com
http://lists.roaringpenguin.com/mailman/listinfo/mime
defang
New: non-standard base64 encoding evadessome scanners
user name
2006-12-08 13:57:23
> -----Original Message-----
> 
> However, it is *not* vulnerable if you use the standard

> MIMEDefang ClamAV
> integration functions.
> 
> MIMEDefang passes virus scanners both the raw MIME
message 
> and all the parts
> as decoded by MIME::tools.  This design decision was
made so 
> that MIME::tools
> could work around any bugs in an AV tools' MIME decoder
and 
> vice-versa.
> 
> The proof-of-concept test didn't make it past our test 
> MIMEDefang system.
> 
> Regards,
> 
> David.


There goes my clam milter...

I was always a little curious why the standard filter
appeared to scan for
viruses twice.

Jason A. Bertoch
Network Administrator
jasonelectronet.net
ElectroNet Intermedia Consulting
3411 Capital Medical Blvd.
Tallahassee, FL 32308
(V) 850.222.0229 (F) 850.222.8771

_______________________________________________
NOTE: If there is a disclaimer or other legal boilerplate in
the above
message, it is NULL AND VOID.  You may ignore it.

Visit http://www.mimedefang.org and http://www.roaringpengu
in.com
MIMEDefang mailing list MIMEDefanglists.roaringpenguin.com
http://lists.roaringpenguin.com/mailman/listinfo/mime
defang
[1-2]

about | contact  Other archives ( Real Estate discussion Medical topics )