dslreports logo
 
    All Forums Hot Topics Gallery
spc
uniqs
2
Mele20
Premium Member
join:2001-06-05
Hilo, HI

1 edit

Mele20 to ahulett

Premium Member

to ahulett

Re: Researchers warn of malware hidden in .zip files

said by ahulett:

However, if there's some vulns in the ZIP format (such as hiding malcode in weird places by mucking with the ZIP file and the end result being a non-standard ZIP, making AV scans miss because they potentially only follow preset scan paths or such, but yet the ZIP decompresses as intended despite being non-standard), then that's interesting.

The "Eight vulnerabilities were found in .zip" statement needs some expanding.
I'm glad I'm not the only one who got from that article that there are vulnerabilities in ZIP format and even MORE vulnerabilities in RAR, 7ZIP, etc formats that allow for hiding malware in places where AV cannot see it. I was eager to read further to find out details (especialy since I use WinRAR which has more vulnerabilities than does ZIP)...but there was nothing more to read!

Why do some here think an AV needs to be able to scan password protected ZIP, RAR, etc. files? On Demand scanner may be too weak to detect. You go to open that file and, if your AV is any good the Real Time scanner is the stronger one, then BAM! its got it! You don't get infected. If your AV scanner doesn't have a signature for the malware, or can't catch it via heuristics, or behavioral pattern, then you still won't get infected as long as you have a classic HIPS. Layered security everyone.

I don't think ISP's should delete or block the sending/receiving of password protected ZIP files attached to emails. I know I can send password protected RARed files that contain malware using my ISP's email because I have sent to all vendors via our Security forum's email submission process using OE and I have received replies from many of the vendors so I know the emails got through intact with a password protected RARed file containing new malware. I have not received any password protected RAR files in awhile but I don't think my ISP blocks them. I used to receive them with no problems and I don't think that policy has changed. But come to think of it, maybe I used my dslr account not my ISP's.

THZNDUP
Deorum Offensa Diis Curae
Premium Member
join:2003-09-18
Lard

THZNDUP

Premium Member

said by Mele20:

[I'm glad I'm not the only one who got from that article that there are vulnerabilities in ZIP format and even MORE vulnerabilities in RAR, 7ZIP, etc formats that allow for hiding malware in places where AV cannot see it. I was eager to read further to find out details (especialy since I use WinRAR which has more vulnerabilities than does ZIP)...but there was nothing more to read!
Per the people that found them(and the OPs article), RAR has LESS vulns than ZIP.

There are eight listed for 'ZIP', three listed for 'RARs', two for '7ZIP', and one each for 'CAB' and GZIP'.
Mele20
Premium Member
join:2001-06-05
Hilo, HI

Mele20

Premium Member

I just read the referenced Cnet article. It said: "Eight vulnerabilities were found in .zip, supported by Microsoft Office, along with seven others in the .7zip, .rar, .cab and .gzip file formats". That said to me that 7zip, rar, cab and gzip had seven additional vulnerabilities which I assumed were in all of the formats since the article did not say. Plus, I read it to mean those were in addition to the other 8. It wasn't very clear. It's good to know RAR has less than ZIP...I guess, but since I don't have any details...maybe the RAR are worse than the ZIP ones.