Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:STC:AV-MAGIC-EVADE

Severity

Minor

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Multiple Vendor Anti-Virus Magic Byte Detection Evasion

Release Date

2010/09/15

Update Number

1773

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Multiple Vendor Anti-Virus Magic Byte Detection Evasion


This signature detects attempts to exploit a known vulnerability against Multiple Anti-Virus products. Attackers can bypass the security restrictions of a system allowing the attacker to carry on future attacks on the victim's computer.

Extended Description

Multiple vendor anti-virus software is prone to a detection evasion vulnerability. The problem presents itself in the way various anti-virus software determines the type of file it is scanning. An attacker can exploit this vulnerability to pass malicious files passed the anti-virus software. This results in a false sense of security, and ultimately could lead to the execution of arbitrary code on the victim user's machine.

Affected Products

  • Arcabit arcavir 2005.0.0
  • Avg avg_anti-virus 7.0.323
  • Cat_computer_services quick_heal_antivirus 8.0.0
  • Dr.web dr.web 4.32.0 b
  • Etrust etrust_ca 7.0.14
  • Fortinet antivirus 2.48.0 .0.0
  • Frisk_software f-prot_antivirus 3.16.0 C
  • Ikarus ikarus 2.32.0
  • Kaspersky anti-virus 5.0.372
  • Mcafee internet_security_suite 7.1.5
  • Mcafee virusscan_enterprise 8.0.0
  • Norman virus_control 5.81.0
  • Panda titanium
  • Sophos anti-virus 3.91.0
  • Thehacker thehacker_antivirus 5.8.4 .128
  • Trend_micro officescan_corporate_edition 7.0.0
  • Trend_micro pc-cillin 2005
  • Ukrainian_antiviral_center una

References

  • BugTraq: 15189

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out