mailing list archives
Re: new internet explorer exploit (was new worm)
From: Nick FitzGerald <nick () virus-l demon co uk>
Date: Tue, 30 Mar 2004 22:46:48 +1200
Void <void () sect net> wrote:
Just wanted to add that Norton Anti-Virus 2004 will detect this exploit and
Of course, what you mean is "this specific exploit".
You wouldn't -- unlike the snake-oilers at Symantec (and many other AV
companies) -- want to imply that its detection of the specific exploit
instance you tested (i.e. using Jelmer's example) is any kind of
indication of NAV's (etc...) detection of any and all possible exploits
of this vulnerability now, would you??
pop up a warning, but also fails to halt its execution or protect the user
in any way.
Here is what it thinks it is:
So there is some measure of warning, but no real protection.
You mean, of course, "there is some level of warning against sonme
unknown portion (perhaps as small a one over ininfity) of possible
exploits of this vulnerability".
I guess the handy thing, at least historically, is that the dweebs that
have used such things in their viruses and worms have tended to copy
the PoC examples as near as damnit to the letter, so have tended to be
Of course, _this_ exploit was discovered, analysed and somewhat fully
documented by the likes of "http-equiv" and Jelmer _AFTER_ it had been
discovered by someone else, not publicized and then used in a rather
"successful" worm. So maybe the writer of that worm is not one of your
typical skiddie types and the number of not publicly known functional
exploits of this vuln that are not detected by NAV, etc is worrying
higher than usual?
Computer Virus Consulting Ltd.
Ph/FAX: +64 3 3529854
Full-Disclosure - We believe in it.
Re: Addressing Cisco Security Issues Clayton Kossmeyer (Mar 29)
RE: Addressing Cisco Security Issues Lou Zirko (Mar 29)
Re: Addressing Cisco Security Issues neal rauhauser (Mar 30)
AW: new internet explorer exploit (was new worm) Ron Stiemer (Mar 29)
Message not available
- Re: Re: Addressing Cisco Security Issues, (continued)
RE: new internet explorer exploit (was new worm) Drew Copley (Mar 29)
RE: new internet explorer exploit (was new worm) Thor Larholm (Mar 29)
Re: new internet explorer exploit (was new worm) Jelmer (Mar 30)
Re: new internet explorer exploit (was new worm) - - (Mar 30)
RE: new internet explorer exploit (was new worm) Drew Copley (Mar 30)
- Re: new internet explorer exploit (was new worm) Nick FitzGerald (Mar 30)