Re: sophie not detecting some viruses
Vanja Hrustic <[email protected]>
| Newsgroups | gmane.comp.security.virus.vtools |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 19 Jan 2004 19:44:45 +0100 Markus Stumpf <[email protected]> wrote: > On Mon, Jan 19, 2004 at 01:05:11PM -0500, CertaintyTech wrote: > > Sophie does not pickup this virus on my system either when scanning > > the raw message. From my experience sophie can't be trusted to scan > > raw MIME messages. But that's why my virus scanner, qmail-scanner, > > always unpacks MIME attachments first then scans the attachment file > > using sophie. > > If you look at the file with e.g. "less" you will notice that it /is/ > already unpacked. It does not consist of MIME parts any more. > > \Maex The file which you've put online - how did it "get" into unpacked shape? Basically, what I'm wondering is if this arrived in an email (and had proper MIME headers, etc.), or it was a webpage downloaded from somewhere, or ... ? I've downloaded 3.77, and noticed that there are quite few new configuration options (which are not in latest SDK docs I have, argh), and even though I've enabled every single option, Sophie still can't detect this one. Either it is a combination of config options that simply don't match (maybe something has to be turned off in Sophie config in order to detect this one), or Sweep uses something I am not aware of. As usual, I have to remind that Sophie doesn't scan this by itself, it simply uses the same API Sweep is supposed to use. Seems that Sweep matches the virus (if this is, indeed a virus, although it certainly looks like one :) by some pattern in 'document.write' line, so if it's removed virus isn't detected. Seems like it doesn't check/unpack the Base64 encoded part at all. Btw, TrendMicro (Trophie, at least) doesn't detect this virus either. Vanja