Re: sophie not detecting some viruses

Markus Stumpf <[email protected]>
Newsgroups gmane.comp.security.virus.vtools
Organization SpaceNet AG, Muenchen, Germany
Message-ID <[email protected]>
On Mon, Jan 19, 2004 at 02:30:14PM -0500, CertaintyTech wrote:
> MIME-Version: 1.0^M
> Content-Location:file:///profile.exe^M
> Content-Transfer-Encoding: base64^M
> 
> That looks like MIME stuff to me...I haven't tried it but if you extract
> profile.exe from the file using ripmime I bet sophie would then detect
> the virus.

That's a leftover MIME Header. Probably need for the exploit to tell
Outlook that it is base64 encoded.
There are no MIME delimiters in the file. If you look at the end of the
file there are 3 empty lines and the HTML code directly attached.
I assume that the .html tells the mail reader to interprest it as HTML
code and the browser skips it (the base64 part) up to the real HTML
lines. The HTML lines tell the browser to open the file again
    <object style="cursor:cross-hair" alt="moo ha ha"
    classid="clsid:66666666-6666-6666-6666"  CODEBASE="
    mhtml:'+path+'\\Profile-720974.html!file:///profile.exe"></object>
and then the code is executed. Fault tolerance this time makes the
base64 decoder skip over the HTML code.

I have base64 decoded the "exe" file and put it in a separate file.
And I have also put the HTML portion in a separate file file. Funny
thing is that then neither sophie nor sweep detects a virus in any of
the files.

	\Maex

-- 
SpaceNet AG            | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0
Research & Development |       D-80807 Muenchen    | Fax: +49 (89) 32356-299
"The security, stability and reliability of a computer system is reciprocally
 proportional to the amount of vacuity between the ears of the admin"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.