PDA

View Full Version : Is this something we should worry about?


Pieter_Arntz
November 10th, 2002, 08:13 AM
Application programmers have all made the same mistake of ignoring how the ZIP format works, using libraries and components that accommodate filenames only up to the OS maximum length (512 bytes for Windows, for example) instead of the 64K limit in the ZIP specification.

What's really alarming is the vulnerability to e-mail viruses. So far, every mail gateway virus scanner Rapid7 has tested lets a virus test file sneak right through if it's in a ZIP file with long filenames--the gateway scanners only catch the test files that are embedded in a "standard" ZIP file with short entry names.

Full article: http://techupdate.zdnet.com/techupdate/stories/main/0,14179,2894850,00.html

Apart from common sense stepping in, when you receive a zipped attachment with a name thatīs that long, I donīt think this will be a very frequently used way of sneaking viruses into your system.
Your views?

Regards,

Pieter

Paul Wilders
November 10th, 2002, 09:09 AM
Nice story. That said: any top notch antivirus will jump right at it when trying to execute such a file.

regards.

paul

Pieter_Arntz
November 10th, 2002, 09:30 AM
Thatīs right.
What Iīm worried about are the people that rely on their their ISPīs mail-scanner. Theyīre in for another disappointment.

Regards,

Pieter

Paul Wilders
November 10th, 2002, 09:47 AM
-{ Quote: "What Iīm worried about are the people that rely on their their ISPīs mail-scanner." }-

Personally, I do believe relying on such a service isn't the most reliable thing to do ;).

regards.

paul

Pieter_Arntz
November 10th, 2002, 10:20 AM
-{ Quote: " quoting: Forum Admin link=board=18;threadid=4782;start=0#31383 date=1036939631]

Personally, I do believe relying on such a service isn't the most reliable thing to do ;).

" }-

No argument here. Nevertheless, many people with limited system resources do. They pay good money to have their mail checked for viruses and perform an occasional on-line scan when their computer acts suspicious.
Unfortunate but true.

Regards,

Pieter

Paul Wilders
November 10th, 2002, 10:24 AM
-{ Quote: "Nevertheless, many people with limited system resources do." }-

Seems to me, buying a 128 MB SDRAM stick for say 25 US bucks is a far more cheaper solution.. ::)

regards.

paul