Security Basics mailing list archives
RE: NAV CE & Password Protected ZIP Files
From: "Glen L. Bowes" <bowes () cogeco ca>
Date: Thu, 4 Mar 2004 13:47:02 -0500
Fair enough but I'd much prefer users don't get the opportunity to open the attachment at all. Sophos has apparently found a way to check the archive and I got a reply off-list that suggests that the Symantec flavor of the Antivirus Corporate edition with the latest update can as well. Have you found that the file is immediately quarantined and user cannot access it any further?
-----Original Message----- From: Carlton Foster [mailto:c.a.foster () larc nasa gov] Sent: Thursday, March 04, 2004 1:17 PM To: Glen L. Bowes; security-basics () securityfocus com Subject: Re: NAV CE & Password Protected ZIP Files What we've seen in testing is if you try to open the zip using the password, NAV immediately flags the file inside as a virus. At 10:34 AM 3/4/2004, Glen L. Bowes wrote:Hi, Sorry for the off topic post but with the flurry of MyDoom variants appearing with the payload stored in password protected zip files, istherea way to get NAV CE to detect the virus? My understanding is that NAV cannot scan the file inside of the ziparchiveas it doesn't supply a password to extract it. My understanding at timescanbe mistaken though ;)
--------------------------------------------------------------------------- Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html ----------------------------------------------------------------------------
Current thread:
- NAV CE & Password Protected ZIP Files Glen L. Bowes (Mar 04)
- Re: NAV CE & Password Protected ZIP Files Carlton Foster (Mar 04)
- RE: NAV CE & Password Protected ZIP Files Glen L. Bowes (Mar 04)
- Re: NAV CE & Password Protected ZIP Files Carlton Foster (Mar 04)