exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

iAntiVirus Fails In A Few Spots

iAntiVirus Fails In A Few Spots
Posted Mar 12, 2009
Authored by Carsten Eilers

iAntiVirus version 1.35 fails to fails to scan .sit and .dmg archives and can also be tricked to ignore archives if special characters are in the names.

tags | advisory
SHA-256 | 77d3cb6ec219d29ef53a708a22b43f77c3f33f9a4bd5d1ce112c51a9f7db7377

iAntiVirus Fails In A Few Spots

Change Mirror Download
Title
Multiple Vulnerabilities in iAntiVirus

Program
PC Tools iAntiVirus for Mac OS X
http://www.iantivirus.com/

Tested version
1.35, Engine Version 1.0.0.10

tested on german Mac OS X 10.5 with following preferences:
- Scan inside archives ON
- Scan mode NORMAL
- Heuristics NORMAL

Description
1. No scan in .sit- and .dmg-archives

The scan-function and the online-scanner OnGuard doesn't
scan .sit- and .dmg-archives.

Impact:
It's possible to download malware from the internet or
to copy it from an usb-stick without interruption from
iAntiVirus.
Malware in .sit-archives is recognized by OnGuard during
manuel decompression, but malware in .dmg-diskimages is
only recognized during a manual scan of the mounted image.
It's possible to run malware from the mounted diskimage
(tested with MacSmurf, which iAntiVirus recognizes as
'Hacktool.OSX.MacSmurf')

2. Problems with special chars in filenames

The scanner, OnGuard and the quarantine-management are
unable to work with files with several special chars in
it, for example ?, which is transformed to Æ.

Impact:
False-positives are lost, since it's impossible to restore
them. Perhaps it's possible to evade the virus-protection.

3. No user-restrictions in the quarantine-management

All quarantined files are managed in the same area. Every
user can restore the files of every other user, included
the admin

Impact:
A normal user can restore quarantined malware in other
accounts, tested with the iWorks-Trojan, which was
installed by the admin and restored by a normal user.
Additional, the history-function contains no information
about the user which performs an action and can erased by
every user.

4. OnGuard does only protect one user (or perhaps a few more)
If OnGuard is on and another user logs in, it seems as if
OnGuard is off. If he copies some malware on the system,
this disappears without any warning: OnGuard is active and
moves the files in the quarantine, but doesn't inform the
user about this. If the first user is an admin, this seems
to work for every normal user. If the first user is a normal
user, it sometimes works for the admin as second user, but
not every time.

5. Ignorance of file-permissions

Every normal user can start a "normal scan", which includes
the system-, library- an program-folders and the folders of
every user.

Solution
None

Credits
Carsten Eilers

Original advisory
http://www.ceilers-it.de/advisories/iantivirus.html
(also as german version)


Regards
Carsten Eilers


Login or Register to add favorites

File Archive:

May 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    44 Files
  • 2
    May 2nd
    5 Files
  • 3
    May 3rd
    11 Files
  • 4
    May 4th
    0 Files
  • 5
    May 5th
    0 Files
  • 6
    May 6th
    28 Files
  • 7
    May 7th
    3 Files
  • 8
    May 8th
    4 Files
  • 9
    May 9th
    54 Files
  • 10
    May 10th
    12 Files
  • 11
    May 11th
    0 Files
  • 12
    May 12th
    0 Files
  • 13
    May 13th
    17 Files
  • 14
    May 14th
    11 Files
  • 15
    May 15th
    17 Files
  • 16
    May 16th
    13 Files
  • 17
    May 17th
    22 Files
  • 18
    May 18th
    0 Files
  • 19
    May 19th
    0 Files
  • 20
    May 20th
    17 Files
  • 21
    May 21st
    18 Files
  • 22
    May 22nd
    7 Files
  • 23
    May 23rd
    0 Files
  • 24
    May 24th
    0 Files
  • 25
    May 25th
    0 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close