OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Mcafee Alerting DOS vulnerability
From: Harry Schmilllson (schmilllsonHOTMAIL.COM)
Date: Wed Jun 07 2000 - 17:28:07 CDT


This is my first post to the list. Hope it's on traq!

I have found that the alerting mechanism in Mcafee's VirusScan 4.03 could
allow any network user to create unlimited "alerts" and send them to the
Central Alert server(s). The alerts from Win9X clients are in the form of a
formatted text file. This file includes info such as user name, computer
name, virus name, etc... A malicious user could format this text file and
insert any info desired including existing or non-existent usernames,
computer names, virus names etc.... The alert server receives these
messages in a share with everyone create, write and delete access. This
could be used in some very interesting ways!
________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com