Re: [Full-disclosure] McAfee VirusScan Enterprise 8.0.0 Misidentifies EICAR Test File

2006-06-12 Thread Marcos Agüero
TheGesus escribió: And you have an instant Elspy.worm flood and your Enterprise AntiVirus Administrator is shitting his pance. Run in circles, scream and shout and all THAT. Oh! That's really stupid! The logs will show 1 infection on the same PC within a few seconds. Easy to spot as a

Re: [Full-disclosure] McAfee VirusScan Enterprise 8.0.0 Misidentifies EICAR Test File

2006-06-11 Thread TheGesus
It can be even more fun in an ePolicy Orchestrator (ePO) environment! Use it during the last week of the quarter and screw up the quarterly AV reports! Someone is guaranteed to shit their pance, although you may not be around to appreciate the ensuing hilarity. And the improved version (see my

[Full-disclosure] McAfee VirusScan Enterprise 8.0.0 Misidentifies EICAR Test File

2006-06-10 Thread TheGesus
REVISION 1.1 === Without offensive language. PROBLEM McAfee VirusScan Enterprise 8.0.0 (tested unpatched and with Patch 11) using the 4781 DAT file (dated 06/09/2006, perhaps also previous) and engine 4400 incorrectly identifies the industry standard EICAR test file as

Re: [Full-disclosure] McAfee VirusScan Enterprise 8.0.0 Misidentifies EICAR Test File

2006-06-10 Thread Nick FitzGerald
TheGesus wrote: REVISION 1.1 === Without offensive language. Where's the fun in that??8-) PROBLEM McAfee VirusScan Enterprise 8.0.0 (tested unpatched and with Patch 11) using the 4781 DAT file (dated 06/09/2006, perhaps also previous) and engine 4400 incorrectly

Re: [Full-disclosure] McAfee VirusScan Enterprise 8.0.0 Misidentifies EICAR Test File

2006-06-10 Thread TheGesus
On 6/10/06, Nick FitzGerald [EMAIL PROTECTED] wrote: VENDOR NOTIFICATION == None. Pity -- you might have saved yourself the embarrassment of this public disclosure of your lameness. OK, so I am pwned. I am surprised you even bothered with me, Nickie. You are such a bitch