5 ms·
From SecurityWeek's writeup on the same topic [1]: No interaction is required to trigger the exploit. In fact, when Ormandy sent his PoC to Symantec, the secur
by DCoder 10y ago
From SecurityWeek's writeup on the same topic [1]:
No interaction is required to trigger the exploit. In fact, when Ormandy sent his PoC to Symantec, the security firm’s mail server crashed after its product unpacked the file.
[1]: http://www.securityweek.com/critical-vulnerability-symantec-av-engine-can-be-exploited-sending-email http://www.securityweek.com/critical-vulnerability-symantec-...
- ontoillogical 10y agoThe source for that detail is here: https://bugs.chromium.org/p/project-zero/issues/detail?id=820#c1 https://bugs.chromium.org/p/project-zero/issues/detail?id=82... > I think Symantec's mail server guessed the password "infected" and crashed (this password is commonly used among antivirus vendors to exchange samples), because they asked if they had missed a report I sent. > They had missed the report, so I sent it again with a randomly generated password. I'm not 100% sure I buy it. The follow up comment is about how he had mistakenly sent them a wrong testcase, and he had sent them similar exploits in a zip with the password infected before (see https://bugs.chromium.org/p/project-zero/issues/detail?id=810 https://bugs.chromium.org/p/project-zero/issues/detail?id=81... from April 28th). It would be incredible for Symantec to guess the password "infected" for ZIP files. It's possible though!
- jwcrux 10y ago"infected" is the industry standard. IIRC (could be making this up) gmail knows to try "infected" in password protected zips.
- graystevens 10y agoCorrect in regards to "infected" being used industry-wide for malware infected zips
- ontoillogical 10y agoYeah I'm just surprised it's going to be scanning zips with the industry standard malware password for ... malware.
- chipperyman573 10y agoIf it didn't, malware devs could just send malware zipped in a password protected folder with that password and tell users to enter that password to unzip.
- makomk 10y agoGMail does some really interesting analysis on e-mails. It even somehow managed to detect and block a file I wanted to send demonstrating a dcraw parser bug in a really obscure camera RAW image format.