Full Disclosure mailing list archives
Re: Backdoor not recognized by Kaspersky
From: KUIJPERS Jimmy <jimmy.kuijpers () swift com>
Date: Thu, 04 Mar 2004 14:29:46 +0100
Hehehe, encrypted is a big word. Especially for a zip file. The contents can most certainly be read. Also be email gateways and virusscanners. Passwords can be cracked. There are special tools that can extract the contact of a password protected zip file without knowning the password. To cut is short, the information is "reshufled" or rather compressed but NOT encrypted at all! I think eventrough e-mail is not intented as a file transfer utility. For the common people it is the only way they know how they can send some files to their friends and co-workers. So I do not think that we should block all executables and compressed files by default. Rather following the suggestion made to stop accepting mail from spoofed mail relays makes much more sense to me. If that solution is workable I think it could solve alot of problems related to spam. my 2cts Jimmy "Aditya, ALD [Aditya Lalit Deshmukh]" wrote:
The zip's contents can be seen without the password, just not unpacked...no cracking it required.now winrar has a option to encrypt file names with a password, me thinks pkzip with the 64 bit compression also has that feature... how are we going to deal with this ? by stopping all the compressed mail at the email gateway ? we do have one solutions: all the mail headers are spoofed so just stop accepting mail from spoofed host, this should solve your spam problem alsoYou should be blocking executables by policy anyway, yes?that is always being done by the all the people in this day and age, only now we seem to forget to add the compressed file format that are encrypted so that their file contects cannot be seen ? -aditya ________________________________________________________________________ Delivered using the Free Personal Edition of Mailtraq (www.mailtraq.com) _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
Current thread:
- RE: Backdoor not recognized by Kaspersky, (continued)
- RE: Backdoor not recognized by Kaspersky Oliver Schneider (Mar 03)
- RE: Backdoor not recognized by Kaspersky Paul Niranjan (Mar 03)
- Re: Backdoor not recognized by Kaspersky Mary Landesman (Mar 03)
- RE: Backdoor not recognized by Kaspersky Jyri.Tamminen (Mar 03)
- RE: Backdoor not recognized by Kaspersky David Kammering (Mar 03)
- Re: Backdoor not recognized by Kaspersky maarten (Mar 03)
- Re: Backdoor not recognized by Kaspersky Martin Mačok (Mar 03)
- Re: Backdoor not recognized by Kaspersky Nick FitzGerald (Mar 03)
- Re: Backdoor not recognized by Kaspersky Bart . Lansing (Mar 03)
- RE: Backdoor not recognized by Kaspersky Aditya, ALD [Aditya Lalit Deshmukh] (Mar 03)
- Re: Backdoor not recognized by Kaspersky KUIJPERS Jimmy (Mar 04)
- Re: Backdoor not recognized by Kaspersky maarten (Mar 03)
- Re: Backdoor not recognized by Kaspersky Gregor Lawatscheck (Mar 03)
- Re: Backdoor not recognized by Kaspersky Cael Abal (Mar 03)
- Re: Backdoor not recognized by Kaspersky Bart . Lansing (Mar 03)
- Re: Backdoor not recognized by Kaspersky Cael Abal (Mar 03)
- Re: Backdoor not recognized by Kaspersky Gregor Lawatscheck (Mar 03)
- Re: Backdoor not recognized by Kaspersky Valdis . Kletnieks (Mar 04)