Full Disclosure mailing list archives

Re: McAfee VirusScan Enterprise 8.0.0 Misidentifies EICAR Test File


From: TheGesus <thegesus () gmail com>
Date: Sat, 10 Jun 2006 23:40:53 -0400

On 6/10/06, Nick FitzGerald <nick () virus-l demon co uk> wrote:

> VENDOR NOTIFICATION
> ==================
> None.

Pity -- you might have saved yourself the embarrassment of this public
disclosure of your lameness.


OK, so I am pwned.  I am surprised you even bothered with me, Nickie.
You are such a bitch I know you can't help yourself.  But do you have
to be so WORDY?

Anyway, this is lots of fun.

So... cut & paste this new improved POC into a Windows CMD file and run...

FOR /L %%i in ( 1 1 100000 ) DO ECHO X5O!P@AP[4\ >virus%%i.exe
%0

And you have an instant Elspy.worm flood and your Enterprise AntiVirus
Administrator is shitting his pance.  Run in circles, scream and shout
and all THAT.

Be sure to do it before McAfee updates the DAT file on Monday!

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: