Re: Antivirus scanner DoS with zip archives

From: Michel Arboi (arboiat_private)
Date: Tue Jun 19 2001 - 11:53:54 PDT

  • Next message: Michel Arboi: "Bugs in Mac Afee AV? [Re: Antivirus scanner DoS with zip archives]"

    --- Markus 'FvD' Weber <fvdat_private> a écrit : 
    > There is 42.zip out there, 42K total size, which consists of
    > nested zip's and at the end a 4GB file (IIRC 6 levels deep,
    > each level 17 'wide') ... kills most email virus checker.
    
    I did not know it existed. Altavista found this on
    http://www.hanau.net/fgk/downloads/42.zip
    
    Why is this kind of attack not more common? I suspect that most filters
    are vulnerable and yet, they are not listed as such (e.g. on
    securityfocus). And companies continue to use them.
    
    > Under Unix ulimit/limit is your best friend ... 
    > (for process and file size). 
    
    *And* CPU time.
    What about Windows NT?
    
    
    
    ___________________________________________________________
    Do You Yahoo!? -- Pour faire vos courses sur le Net, 
    Yahoo! Shopping : http://fr.shopping.yahoo.com
    



    This archive was generated by hypermail 2b30 : Wed Jun 20 2001 - 06:40:55 PDT