Worldsecure/Mail 4.3 vulnerability

From: Andreas Küchler (andreas.kuechlerat_private)
Date: Thu Jan 20 2000 - 01:26:39 PST

  • Next message: Mike Frantzen: "Re: Trusted process on an untrusted machine?"

    This is a multi-part message in MIME format.
    --------------357942BA9FCB7340391D36AB
    Content-Type: text/plain; charset=iso-8859-1
    Content-Transfer-Encoding: 8bit
    
    Worldsecure uses anonymous ftp to transfer their virus patterns
    automatically from their site download.worldtalk.com to the Worldsecure
    server. Obviously Worldtalk does __NOT__ check any signatures after the
    file has been downloaded and integrates them into the antivirus engine
    of the WorldSecure/Mail server. There are two scenarios:
    
    1) if anyone gets access to the pattern files on download.worldtalk.com
    and replaces them with a modified version :
    
    a) he can transport any file named *.dat to the users worldsecure server
    (the server transports everything called *.dat that is embeded inside
    the dat-xxxx.zip residing on the ftp server to a directory under
    Worldtalk called after the pattern revision. All you have to do is to
    find the actual revision number of mcafees dat-files, add one and place
    a new dat on the ftp server. By doing this you reach __ANY__
    WS/Mail-server with enabled autoupdate feature!
    
    b) by replacing scan.dat with any file which is not a virus pattern the
    virus engine will be unable to scan for any viruses any more... By the
    way wherent there some exploits against MS FTP Service 4.0 !?! :-(
    
    2) if anyone gets access to the local registry of a worldsecure/Mail
    server he can modify the download site from where worldtalk retrieves
    its updates. He can then acomplish the same thing as before. (only on
    the smaller scope of one server)
    
    The big problem is that the Worldsecure/Mail server uses any file as
    virus pattern and actually scans with this modified file (I tried
    wincmd.exe !!! renamed as scan.dat) without producing any warnings or
    log entries. The administrator has only a chance to smell the mess when
    he restarts the server because then the virus engine will not
    initialize.
    
    Worldtalk has been informed about this scenarios and admits that there
    is a problem which will be solved in a future release of
    Worldsecure/Mail.
    --
    Andreas Kuechler
                                 \|/
                                (@ @)
    ------------------------oOO--(_)--OOo-------------------------
                            ```       ´´´
    Leiter Netzwerke und Service         Giegerich & Partner GmbH
                                         Daimlerstrasse 1H
    +49 6103 5881 71 Voice               63303 Dreieich
    +49 6103 5881 79 Fax                 Germany
    http://www.giepa.de                  andreas.kuechlerat_private
    ==============================================================
    Fingerprint 7DCE 2A53 CB6E 6DF9 CA20  B65B 0FE1 915A 2069 15BD
    --------------357942BA9FCB7340391D36AB
    Content-Type: text/x-vcard; charset=us-ascii;
     name="andreas.kuechler.vcf"
    Content-Transfer-Encoding: 7bit
    Content-Description: Card for Andreas Küchler
    Content-Disposition: attachment;
     filename="andreas.kuechler.vcf"
    
    begin:vcard
    n:Küchler;Andreas
    tel;fax:+49 6103 5881 79
    tel;work:+49 6103 5881 71
    x-mozilla-html:FALSE
    url:http://www.giepa.de
    org:Giegerich & Partner GmbH
    adr:;;Daimlerstrasse 1h;Dreieich;Hessen;63303;Germany
    version:2.1
    email;internet:Andreas.Kuechlerat_private
    title:Leiter Netzwerke und Service
    note:http://www.giepa.de
    x-mozilla-cpt:;-5808
    fn:Andreas Küchler
    end:vcard
    
    --------------357942BA9FCB7340391D36AB--
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:29:13 PDT