Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 7th, 2004, 08:12 PM
stormbyte stormbyte is offline
AV Expert
 
Join Date: Jul 2004
Posts: 97
Big Grin testers needed

Hey guys,
I think i found something that could be called a very tiny security issue in IE
I need people with AV software installed to test it for me
Go to: http://www.stormbyte.com/vtest/test.php
and report :
a. If your antivirus warned you about a new virus on your system
b. Your operating system, browser, and antivirus

Don't worry there will be no viruses or spyware installed. I just found a way to trick some antiviruses into thinking that computer is being infected by just visiting a web site.

Thanks!
Mariusz
  #2  
Old December 7th, 2004, 08:23 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,507
Default Re: testers needed

A - nope
B - Win2k, Firefox 0.9.1, NOD32

Just got a blank page there so if it's anything Proxo might have blocked - that might be the case as well.
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #3  
Old December 7th, 2004, 08:25 PM
stormbyte stormbyte is offline
AV Expert
 
Join Date: Jul 2004
Posts: 97
Default Re: testers needed

Quote:
Originally Posted by Detox
A - nope
B - Win2k, Firefox 0.9.1, NOD32

Just got a blank page there so if it's anything Proxo might have blocked - that might be the case as well.

Yeah. Firefox is safe. Try with IE
  #4  
Old December 7th, 2004, 08:27 PM
nadirah nadirah is offline
Massive Poster
 
Join Date: Oct 2003
Posts: 3,647
Default Re: testers needed

Quote:
Originally Posted by stormbyte
Yeah. Firefox is safe. Try with IE
I've got my own doubts about doing that. I used firefox, clicked on the link, and got a blank page with absolutely nothing happening at all.
I used IE, and also I get a blank page with nothing happening at all. I'm very secure here.
  #5  
Old December 7th, 2004, 08:28 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,507
Default Re: testers needed

Same result - IE 6.0 - also routing through Proxo. I'll try without.
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #6  
Old December 7th, 2004, 08:29 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,507
Default Re: testers needed

Same in IE without Proxo.
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #7  
Old December 7th, 2004, 08:31 PM
stormbyte stormbyte is offline
AV Expert
 
Join Date: Jul 2004
Posts: 97
Default Re: testers needed

Quote:
Originally Posted by Detox
Same result - IE 6.0 - also routing throw Proxo. I'll try without.

Then NOD32 is not looking at it as a virus.
But when you scan cookies folder you should find "Eicar" virus.
Unless Nod does not scan txt's or you have cookies disabled.
Oh well. Thanks anyway.
  #8  
Old December 7th, 2004, 08:33 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: testers needed

I get this in Proxo's (+ Opera) log window. Ran it with IE, no proxy, and F-Prot 3.16a and got just a blank window and no alert.

Nick
Attached Images
 
  #9  
Old December 7th, 2004, 08:33 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,507
Default Re: testers needed

I'll run a full scan now to see.
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #10  
Old December 7th, 2004, 08:41 PM
nadirah nadirah is offline
Massive Poster
 
Join Date: Oct 2003
Posts: 3,647
Default Re: testers needed

Just ran a full scan with all my security applications, nothing found at all. Clean.
  #11  
Old December 7th, 2004, 08:45 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: testers needed

Quote:
Originally Posted by stormbyte
Then NOD32 is not looking at it as a virus.
But when you scan cookies folder you should find "Eicar" virus.
Unless Nod does not scan txt's or you have cookies disabled.
Oh well. Thanks anyway.


Checked all of my cookies and found no eicar of any kind.
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #12  
Old December 7th, 2004, 08:49 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: testers needed

F-Prot found this using a manual scan:

Nick
Attached Images
 
  #13  
Old December 7th, 2004, 08:51 PM
stormbyte stormbyte is offline
AV Expert
 
Join Date: Jul 2004
Posts: 97
Default Re: testers needed

Quote:
Originally Posted by nadirah
Just ran a full scan with all my security applications, nothing found at all. Clean.

That is way I needed more people to test my idea
Basically, when you go to that page your browser will receive a cookie.
This cookies has eicar test virus string as a value. Some AVs when they see this file being written to the hard drive will inform you about that.
It will not work if you use Firefox, or have cookies disabled, or your AV is not scanning TCP packets, or txt/cookie files.
Like I said this is not a big issue, (or in your case it's not an issue) but I had to check it.
  #14  
Old December 7th, 2004, 08:54 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,507
Default Re: testers needed

Not sure exactly why but I got nothing in my scan either.
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #15  
Old December 7th, 2004, 08:54 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,190
Default Re: testers needed

Quote:
Originally Posted by nick s
F-Prot found this using a manual scan:

Nick

How did F-Prot do realtime? Or did you try that?
  #16  
Old December 7th, 2004, 08:55 PM
stormbyte stormbyte is offline
AV Expert
 
Join Date: Jul 2004
Posts: 97
Default Re: testers needed

Quote:
Originally Posted by nick s
F-Prot found this using a manual scan:

Nick

So it works
Now I have a question. Do you guys think that this could be called a "security hole" in IE? I know that it's only a cookie, can't be executed and so on, but still it could cause problems for some people. (OMG! My computer is infected - for example)
  #17  
Old December 7th, 2004, 08:59 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: testers needed

Interesting....what does all that mean ?

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*0
  #18  
Old December 7th, 2004, 09:00 PM
nick s nick s is offline
Very Frequent Poster
 
Join Date: Nov 2002
Posts: 1,427
Default Re: testers needed

Quote:
Originally Posted by ronjor
How did F-Prot do realtime? Or did you try that?
Hi Ron,

RealTime did not catch it.

Nick
  #19  
Old December 7th, 2004, 09:00 PM
solarpowered candle solarpowered candle is offline
Very Frequent Poster
 
Join Date: Jan 2003
Location: new zealand
Posts: 1,181
Default Re: testers needed

(A) Yes

(B) XP IE KAV extendia single engine

I got a blank page with Firefox as I did with IE But with IE Extendia alerted me instantly of access attempted with an infected file ( EICAR -test file )
  #20  
Old December 7th, 2004, 09:04 PM
Honyak's Avatar
Honyak Honyak is offline
Frequent Poster
 
Join Date: Jul 2004
Location: Deep South
Posts: 346
Default Re: testers needed

Mariusz
I closed firefox and opened the page with IE and ArcaVir 2005 immediatly reported a virus.
__________________
I think computer viruses should count as life. I think it says something about human nature that the only form of life we have created so far is purely destructive. We've created life in our own image.
- Stephen Hawking
  #21  
Old December 7th, 2004, 09:05 PM
stormbyte stormbyte is offline
AV Expert
 
Join Date: Jul 2004
Posts: 97
Default Re: testers needed

Quote:
Originally Posted by Bubba
Interesting....what does all that mean ?

X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*0

Virus test file. I did not wanted to use string from a real virus so I had to use Eicar. YOu can read more about it here:
http://www.eicar.org/anti_virus_test_file.htm
  #22  
Old December 7th, 2004, 09:06 PM
stormbyte stormbyte is offline
AV Expert
 
Join Date: Jul 2004
Posts: 97
Default Re: testers needed

Quote:
Originally Posted by Honyak
Mariusz
I closed firefox and opened the page with IE and ArcaVir 2005 immediatly reported a virus.

I know. I tested it first with mks_vir.
Question remains: should this be reported somewhere or not?
  #23  
Old December 7th, 2004, 09:12 PM
Honyak's Avatar
Honyak Honyak is offline
Frequent Poster
 
Join Date: Jul 2004
Location: Deep South
Posts: 346
Default Re: testers needed

Quote:
Originally Posted by stormbyte
I know. I tested it first with mks_vir.
Question remains: should this be reported somewhere or not?

It would seem to me that it warrants attention to try and prevent future exploitation.
__________________
I think computer viruses should count as life. I think it says something about human nature that the only form of life we have created so far is purely destructive. We've created life in our own image.
- Stephen Hawking
  #24  
Old December 7th, 2004, 10:28 PM
bigbuck's Avatar
bigbuck bigbuck is offline
Massive Poster
 
Join Date: Jul 2004
Location: Qld, Aus
Posts: 4,877
Default Re: testers needed

A. No virus reported.
B. opened in IE...XPSP2 Firewall.....Nav2003.....Cookies set to medium.....Nothing!....
  #25  
Old December 7th, 2004, 11:24 PM
nadirah nadirah is offline
Massive Poster
 
Join Date: Oct 2003
Posts: 3,647
Default Re: testers needed

You won't get any alert if you block stormbyte's cookies. The cookies will cause your antivirus to alert you if allow them in.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:24 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums