[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-Disclosure] Multiple Antivirus Scanners DoS attack. [summery]



> > * Windows Xp default ZIP manager [report's wrong
> size
> > of compress ZIP files.]
> 
> if you mess with headers any compression API tells
> you 
> the same wrong size. Check zlib, infoZip, rar, arj. 
> 
> 
> There is no way to get detect these changes.
> Checking each file integrity 
> against the header info will take significiant
> anount of time. Anyway like 
> WinZIP the extraction routine seek file content
> until the the next header 
> stats.  So that the altered file size will not able
> to fool the routine i.e 
> Design Error.  

do you have any idea how i created these compressed
archive??? i didn't modified the header info!!!
i created it using dd if=/dev/zero ..............

It has been few reports F-Prot 4.4.2 for Linux has a problem!!!


        
                
__________________________________
Do you Yahoo!?
Friends.  Fun.  Try the all-new Yahoo! Messenger.
http://messenger.yahoo.com/ 

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html