Security Basics mailing list archives

Re: NAV CE & Password Protected ZIP Files


From: Carlton Foster <c.a.foster () larc nasa gov>
Date: Thu, 04 Mar 2004 13:17:28 -0500

What we've seen in testing is if you try to open the zip using the password, NAV immediately flags the file inside as a virus.

At 10:34 AM 3/4/2004, Glen L. Bowes wrote:
Hi,

Sorry for the off topic post but with the flurry of MyDoom variants
appearing with the payload stored in password protected zip files, is there
a way to get NAV CE to detect the virus?

My understanding is that NAV cannot scan the file inside of the zip archive
as it doesn't supply a password to extract it. My understanding at times can
be mistaken though ;)

TIA,


Glen L. Bowes


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
any course! All of our class sizes are guaranteed to be 10 students or less
to facilitate one-on-one interaction with one of our expert instructors.
Attend a course taught by an expert instructor with years of in-the-field
pen testing experience in our state of the art hacking lab. Master the skills
of an Ethical Hacker to better assess the security of your organization.
Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off any course! All of our class sizes are guaranteed to be 10 students or less to facilitate one-on-one interaction with one of our expert instructors. Attend a course taught by an expert instructor with years of in-the-field pen testing experience in our state of the art hacking lab. Master the skills of an Ethical Hacker to better assess the security of your organization. Visit us at: http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: