Bugtraq mailing list archives

Re: Multiple Vendor Unusual MIME Encoding Content Filter Bypass


From: Tomasz Kojm <tkojm () clamav net>
Date: Thu, 7 Dec 2006 15:15:50 +0100

On Wed, 06 Dec 2006 15:24:25 +0100
Hendrik Weimer <hendrik () enyo de> wrote:

Several e-mail virus scanners can be tricked into passing an EICAR
test file if the following conditions are met:

1. the EICAR file is encoded in Base64 including characters not in the
   standard alphabet (e.g. whitespaces) and
2. the part containing the EICAR file is nested within one or several
   levels of multipart/mixed content.

Details and PoC can be found at:
http://www.quantenblog.net/security/virus-scanner-bypass

That's _extremely_ irresponsible to disclose bugs without giving the vendors
any chance to fix them and prepare new software releases.

-- 
   oo    .....         Tomasz Kojm <tkojm () clamav net>
  (\/)\.........         http://www.ClamAV.net/gpg/tkojm.gpg
     \..........._         0DCA5A08407D5288279DB43454822DC8985A444B
       //\   /\              Thu Dec  7 15:13:35 CET 2006


Current thread: