what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

noranvDoS.txt

noranvDoS.txt
Posted Jul 9, 2004
Authored by Bipin Gautam | Site geocities.com

Symantec Norton AntiVirus 2003 Professional Edition and Symantec Norton AntiVirus 2002 suffer from a denial of service condition when scanning files deeply embedded in directories.

tags | advisory, denial of service
SHA-256 | 98ca88296b853b3c220b0bb40bb8a43ab6781054eab9c20398d4b1984888d3d0

noranvDoS.txt

Change Mirror Download


Norton AntiVirus Denial Of Service Vulnerability [Part: !!!]

*vulnerable [...only tested on!]

Symantec Norton AntiVirus 2003 Professional Edition
Symantec Norton AntiVirus 2002

*not vulnerable
Mcafee 7*
Mcafee 8*

Risk Impact: Medium
Remote: yes

Description:
While having a virus scan [automatic/manual] of some specially crafted compressed files; NAV triggers a DoS using 100% CPU for a very long time. Morover, NAV is unable to stop the scan in middle, even if the user wishes to manually stop the virus scan. Then, in this situation the only alternate is to kill the process.
--- [Proof of Concept] ---
Please download this file.

https://www.geocities.com/visitbipin/av_bomb_3.zip <--- For symantec.

https://www.geocities.com/visitbipin/EXTRACTit1st.zip <--- A bzip2 file, test it on other AV products, too.

The file contains, 'EICAR Test String' burried in 49647 directories. This is just a RAW 'proof of concept'. A few 100kb's of compressed file could be crafted in a way... NAV will take hours or MIGHT even days to complete the scan causing 100% cup use in email gateways for hours. The compressed archive must not necessarily be a '.zip' to trigger this attack.

PLEASE: ...test this issue with other AV / trojan scanners as they might also be vulnerable.

-----------
Bipin Gautam
https://www.geocities.com/visitbipin/

Disclaimer: The information in the advisory is believed to be accurate at the time of printing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect or consequential loss or damage arising from use of, or reliance on this information.
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close