On GameSpot: 54.2% of Xbox 360s fail - Report
BNET Business Network:
BNET
TechRepublic
ZDNet

July 7th, 2008

Approximately 800 vulnerabilities discovered in antivirus products

Posted by Dancho Danchev @ 1:44 pm

Categories: Anti Virus, Arbitrary Code Execution, Denial of Service (DoS), Malware, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: n.runs AG, Secunia, Dancho Danchev

UPDATE: McAfee debunks recent vulnerabilities in AV software research, n.runs restates its position. In what appears to be either a common scenario of “when the security solution ends up the security problem itself”, or aVulnerabilities Antivirus Software 2005/2007 product launch basing its strategy on outlining the increasing number of critical vulnerabilities found in competing antivirus products, the IT/Security consulting firm n.runs AG claims to have discovered approximately 800 vulnerabilities within antivirus products based on exploiting a standard malware scanning process known as “parsing” :

“During the past few months, specialists from the n.runs AG, along with other security experts, have discovered approximately 800 vulnerabilties in anti-virus products. The conclusion: contrary to their actual function, the products open the door to attackers, enable them to penetrate company networks and infect them with destructive code. The positioning of anti-virus software in central areas of the company now poses an accordingly high security risk. The tests performed by the consulting company and solutions developer n.runs have indicated that every virus scanner currently on the market immediately revealed up to several highly critical vulnerabilities. These then pave the way for Denial of Service (DoS) attacks and enable the infiltration of destructive code – past the security solution into the network. With that, anti-virus solutions actually allow the very thing they should instead prevent.”

In between the ongoing efforts put by malware authors to obfuscate their binaries, release as many as possible in the shortest time frame achievable, or ensure that they bypass the most popular personal firewalls before releasing them by applying quality assurance to their malware campaigns, can antivirus products be a security issue themselves? But of course, and the increasing number of vulnerabilities discovered is clearly indicating the increasing interest in proving the point in general.

How did n.runs manage to discover the vulnerabilities they claim they found? By following the very same logic on which a great deal of theVulnerabilities Antivirus Software Q1 2008 current vulnerabilities are based on, the way in which the scanner parses the file it’s supposed to scan :

“In this context, n.runs was able to make out so-called “parsing” as one of the main causes of this boomerang effect. The principle functions as follows: virus scanners must recognise as many “Malware” applications as possible – and thereby comprehend and process a large number of file formats. In order to be able to interpret the formats, an application must partition the corresponding file into blocks and structures. This separation of data into analysable individual parts is called “parsing”. Mistaken assumptions in the course of programming the parsing code create constellations which enable the infiltration and subsequent running of programme code. Moreover, the quick reactions time expected by developers (regarding threats) contributes to a decrease in the quality of the code. In short: the more parsing that takes place, the higher the recognition rate and the degree of protection from destructive software, but at the same time, the larger the attack surface – which makes the anti-virus solution itself a target.”

The research they cite is based on Secunia’s tracking of advisories affecting antivirus products, as well as research conducted by the University of Michigan emphasizing on the severity of the vulnerabilities on a per product basis. For instance, between 2002 and 2005 there were 50 advisories regarding vulnerabilities affecting antivirus products, but between 2005 and 2007, there’s been an increase of 240% with 170 advisories. Moreover, according to a research paper by Feng Xue, presented at this year’s Blackhat Europe, according to the U.S national vulnerability database, 165 vulnerabilities within antivirus products have been reported during the last 4 years. It’s even more ironic to point out that the now fixed remote code execution vulnerability in Panda Security’s online virus scanner, further proves that the security solution can indeed end up the security problem itself.

With the increasing interest and success into finding critical security vulnerabilities within antivirus products, are we going to see more abuse of these “windows of opportunity” by malware authors themselves? I don’t think so, at least not on a large scale. What they are going to continue researching are ways in which to shut down the antivirus solution silently, prevent it from reaching its hard coded update locations, and most importantly ensure the malware has been pre-tested against the most popular security solutions before it’s released in the wild - precisely what they’ve been doing for the last couple of years.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 173 Talkback(s)
Without having to use other programs?....
It is hard to guesstimate virus behaviour without other programs. You can't always count on eratic behaviour to tip you off; some really bad malware flat takes over your computer and gains administrat... (Read the rest)
Posted by: JCitizen Posted on: 08/12/08  (Edited: 08/12/08 @ 11:33) You are currently: a Guest | | Terms of Use
No matter what you do---  BALTHOR | 07/07/08
Re: No matter what you do---  ddanchevZDNet Moderator | 07/07/08
Oh the Humanity!  D-T-Schmitz | 07/07/08
What is "nt"?  MauiMike | 07/08/08
nt = no text  Happydawg | 07/08/08
Aha!  MauiMike | 07/08/08
Put nt in subject, not message  Embedded66 | 07/08/08
Which is damn near impossible...  Wolfie2K3 | 07/08/08
Hmm, didn't know that.  Embedded66 | 07/09/08
a single period is enough (nt)  rtk | 07/11/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  MrViklund | 07/07/08
You know it's pretty bad when AV vulnerabilities are found...  toadlife | 07/07/08
That's how computer viruses work  chaz15 | 07/07/08
So what about AV vendors that claim not...  JCitizen | 07/08/08
It would be FAR more responsible...  vulpine@... | 07/08/08
The danger of running under the System account  PB_z | 07/07/08
RE:The danger of running under the System account  JT82 | 07/08/08
A better approach ...  mwagner@... | 07/08/08
So which AV products are any good?  kraterz | 07/08/08
The free ones are best  Mike Hunt | 07/08/08
Rare-Sense  jbones39 | 07/08/08
To not use any AV protection is wreckless!  mwagner@... | 07/08/08
Linux has protection built in. (8.04)  joe.smetona@... | 07/08/08
Not just Linux  CreepinJesus | 07/09/08
I hope it's better...  Mike Hunt | 07/09/08
Instead of AV software,  arminw | 07/08/08
Complete Bunk  notsofast | 07/08/08
Factually incorrect  bmerc | 07/08/08
Viruses for the commodore Amiga  alaniane@... | 07/08/08
Only partially incorrect  Kiltedbear | 07/08/08
You're all WRONG....  Wolfie2K3 | 07/08/08
Factually Incorrect  notsofast | 07/09/08
get a life  cyberbull | 07/08/08
I cannot believe the narrow minded focus  Cayble | 07/08/08
RE: I cannot believe the narrow minded focus  richdave | 07/08/08
Re: New software  Mike Hunt | 07/09/08
Macs are mor secure because no one targets them nt  tech_walker | 07/08/08
Are Mac's Protected?  MAC HUNK | 08/05/08
It is the applications that make Mac's ...  JCitizen | 08/05/08
I stopped using AV on my XP machine  tech_walker | 07/08/08
Bot or not?  jayinoz@... | 07/09/08
stop use microsoft  jderash | 07/10/08
Re: To not use any AV protection is wreckless!  Demzon | 07/08/08
Gmail Anti-Spam system is virtually Perfect (nt)  joe.smetona@... | 07/10/08
Mostly depends on the user.  xrxca | 07/09/08
I have to agree - freeware AV is best  jlafitte | 07/08/08
I have seen many discussions about best anti-virus product  batia | 07/08/08
What about eset.com products? Anyone?  sailnott@... | 07/08/08
Eset products (NOD av)  martian@... | 07/08/08
I use MS LiveOneCare...  jerry@... | 07/09/08
RE: I use MS LiveOneCare ....  GreyGeek | 07/13/08
Last time I tried LOC it nearly blew up my...  JCitizen | 07/13/08
NOD 32  bigleagues | 08/04/08
Best AV Software  rooste14@... | 08/12/08
Without having to use other programs?....  JCitizen | 08/12/08
ESET  finewine80@... | 07/08/08
I am very impressed with ESET NOD32...  JCitizen | 07/11/08
Maybe...  joe.smetona@... | 07/12/08
Yes I do...  JCitizen | 07/13/08
Converting users takes time.  joe.smetona@... | 07/14/08
Thanks Joe...  JCitizen | 07/14/08
My Professional Opinion . . .  bigleagues | 08/04/08
Thank you, and I agree, buy the way...  JCitizen | 08/05/08
Yes and No  jhimes | 07/14/08
Free ANtiVirus?  MAC HUNK | 08/05/08
Free ANtiVirus?  MAC HUNK | 08/05/08
I'd try avast! Mac edition...  JCitizen | 08/05/08
And they dared to lower the Windows 64 bits security  timiteh | 07/08/08
antivirus programs cause more damages and problems than viruses  qmlscycrajg | 07/08/08
Based on what data?  DevGuy_z | 07/08/08
Real life  Mike Hunt | 07/08/08
Most ISPs now provide their customers ...  mwagner@... | 07/08/08
ISP provided AV  martian@... | 07/08/08
delivery of definition updates  Keywalker4God | 07/08/08
RE: Most ISPs now provide their customers ...  richdave | 07/08/08
Sad, but true.  notsofast | 07/09/08
Thats not always true...Sometimes comercial AV sucks too.  bernalillo | 07/08/08
Trend Micro advantages  w_c_mead | 07/08/08
No Scanner is perfect but it's better than nothing  dunn@... | 07/08/08
BTW: Good article and good references. (nt)  dunn@... | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  slatz@... | 07/08/08
I find it interesting that ...  mwagner@... | 07/08/08
Is the kernel open already, or did Symantec..  JCitizen | 07/08/08
The backdoor is open ...  mwagner@... | 07/08/08
Thanks mwagner and again for ...  JCitizen | 07/13/08
Can't always blame MS, huh?  RDrr | 07/08/08
AVG was great...  wmlundine | 07/08/08
AVG was always a resource hog.  Know1 | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  bobsjeep@... | 07/08/08
I just enter the AV product in the search window..  JCitizen | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  chris.green@... | 07/08/08
I like ESET as well; no scanning necessary...  JCitizen | 07/08/08
thinking outside of software  gdstark13 | 07/08/08
er, hardware runs on.... software  jlafitte | 07/08/08
I think he is talking gateway solutions...  JCitizen | 07/08/08
RE: I think he is talking gateway solutions...  gdstark13 | 07/08/08
Like Intel Core 2 vPro?  JCitizen | 07/08/08
RE: Like Intel Core 2 vPro?  gdstark13 | 07/08/08
I'm talking about the vPro...  JCitizen | 07/11/08
er, hardware runs on.... software  gdstark13 | 07/08/08
er, hardware can run without software  olaney@... | 07/08/08
I'm not sure how successfull hardware solutions...  JCitizen | 07/08/08
er, hardware can run without software  gdstark13 | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  sluger1138 | 07/08/08
One of the main reasons...  joe.smetona@... | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  sluger1138 | 07/08/08
As usual COMODO wins!  kokuryu | 07/08/08
I don't see that  jwelshjr | 07/08/08
Or use a firmware gateway scanner...  JCitizen | 07/08/08
The writer should take a math-refresher course.  GrizzledGeezer | 07/08/08
... and you will take a civility course?  mike.blyth@... | 07/09/08
Antivirus doesn't work!!  lordshipmayhem | 07/08/08
RE: Antivirus doesn't work!!  gdstark13 | 07/08/08
If you go to Secunia.com...  joe.smetona@... | 07/08/08
RE: If you go to Secunia.com...  gdstark13 | 07/08/08
How about this?  joe.smetona@... | 07/08/08
RE: How about this?  gdstark13 | 07/08/08
Yes, right on track!  joe.smetona@... | 07/08/08
Correction.  joe.smetona@... | 07/08/08
You have a point but.....  i8thecat | 07/08/08
RE: You have a point but.....  gdstark13 | 07/08/08
There aren't virus in linux...  magallanes | 07/08/08
Good example...  JCitizen | 07/08/08
However...  JCitizen | 07/08/08
RE:Antiviruses don't work  GreyGeek | 07/13/08
Sounds like the age old problem ...  softwareFlunky | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  NetworkMeUp | 07/08/08
Not everone can afford the supercomputer...  JCitizen | 07/08/08
Replying to JCitizen...  NetworkMeUp | 07/08/08
I agree with you...  JCitizen | 07/11/08
AVG is one of the most secure!!!!  Pyrotech_z | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  Ross Snowden | 07/08/08
IF MY HERRO LOVEROCK WAS HERE  bill_haaak | 07/08/08
BALTHOR  martian@... | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  gdstark13 | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  NotRichandFamous | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  NotRichandFamous | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  kano51 | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  NetworkMeUp | 07/08/08
China and the antivirus product vulnerabilities  Recce1 | 07/08/08
China  largemac1955 | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  Orchid de Noir | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  morph000 | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  sirteddy | 07/08/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  sirteddy | 07/08/08
What's worse, the virus or the anti-virus.....  Narg | 07/08/08
What's worse, the virus or the anti-virus.....  FairlySharp | 07/08/08
Disable AVG new features  jonxdoe@... | 07/08/08
Totally agree  morrigen | 07/09/08
Linkscanner is due for some changes...  JCitizen | 07/13/08
Better with than without  w_c_mead | 07/08/08
I've seen a dozen or so that have been infected...  tracy anne | 07/09/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  fourijm@... | 07/09/08
The reason Anti Virus software is a broken fix  tracy anne | 07/09/08
(moved to reply to "The writer should take a math-refresher course."  mike.blyth@... | 07/09/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  morrigen | 07/09/08
How does this affect Mac users? Lack of Viruses/Lack of Anti-Virus = ???  jjarman | 07/09/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  mike1mb | 07/09/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  jayinoz@... | 07/09/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  jayinoz@... | 07/09/08
scanning is not the right approach to prevention  mike acker | 07/10/08
You are talking about Linux.  joe.smetona@... | 07/10/08
Several versions of Mandrake seem..  JCitizen | 07/13/08
I'd suggest Linux Mint or Ubuntu 8.04  joe.smetona@... | 07/15/08
A suggestion about media.  joe.smetona@... | 07/15/08
Sorry for not responding sooner!  JCitizen | 07/20/08
But its the only effective approach  jayinoz@... | 07/11/08
Blended approach work best for me now...  JCitizen | 07/13/08
The line has been crossed.  joe.smetona@... | 07/14/08
I've never checked to see if Wine comes with...  JCitizen | 07/14/08
scissors method is the only approach  that random guy | 08/01/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  EmperorDarius | 07/12/08
RE: Approximately 800 vulnerabilities discovered in antivirus products  grampa1631@... | 07/17/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here