Astaro Beta Report
--------------------------------
Version: 7.470
Type: BUG
State: FIXED
Reporter: BrucekConvergent
Contributor:
MantisID: 10992
--------------------------------
2009:07:19-07:28:03 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/modules/exploits/windows/browser/realplayer_console.rb, category 1, level 2, code 32
2009:07:19-07:28:03 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/modules/exploits/windows/browser/.svn/text-base/ms06_013_createtextrange.rb.svn-base, category 1, level 2, code 32
2009:07:19-07:28:03 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/modules/exploits/windows/browser/.svn/text-base/ibmlotusdomino_dwa_uploadmodule.rb.svn, category 1, level 2, code 32
2009:07:19-07:28:03 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/modules/exploits/windows/browser/.svn/text-base/symantec_backupexec_pvcalendar.rb.svn-, category 1, level 2, code 32
2009:07:19-07:28:03 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/modules/exploits/windows/browser/.svn/text-base/creative_software_cachefolder.rb.svn-b, category 1, level 2, code 32
2009:07:19-07:28:03 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/modules/exploits/windows/browser/.svn/text-base/ms06_057_webview_setslice.rb.svn-base, category 1, level 2, code 32
2009:07:19-07:28:03 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/modules/exploits/windows/browser/.svn/text-base/realplayer_console.rb.svn-base, category 1, level 2, code 32
2009:07:19-07:28:03 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/modules/exploits/windows/browser/.svn/text-base/ie_createobject.rb.svn-base, category 1, level 2, code 32
2009:07:19-07:28:03 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/modules/exploits/windows/browser/.svn/text-base/hpmqc_progcolor.rb.svn-base, category 1, level 2, code 32
2009:07:19-07:28:19 asg httpproxy[31089]: [0xab82b5d0] avira_error_cb (avirascanner.c:80) name framework-3.2.tar --> framework-3.2/external/source/ReflectiveVNCDll.zip --> ReflectiveVNCDll/winvnc/winvnc/res/vncviewer.jar, category 2, level 0, code 29
2009:07:19-07:29:55 asg httpproxy[31089]: id="0056" severity="info" sys="SecureWeb" sub="http" name="web request blocked, error while scanning" action="pass" method="GET" srcip="192.168.9.2" user="" statuscode="200" cached="4" profile="REF_DefaultHTTPProfile (Default Proxy)" filteraction="REF_DefaultHTTPCFFAction (Default content filter action)" size="13099756" time="190273 ms" request="0xab82b5d0" url="spool.metasploit.com/.../x-gzip" engine="Astaro-AV"
[07:39:12] root@beyond - ~/tmp/framework-3.2> clamscan --infected -r
LibClamAV Warning: ***********************************************************
LibClamAV Warning: *** This version of the ClamAV engine is outdated. ***
LibClamAV Warning: *** DON'T PANIC! Read www.clamav.net/.../faq ***
LibClamAV Warning: ***********************************************************
/root/tmp/framework-3.2/modules/exploits/windows/browser/ms06_057_webview_setslice.rb: Exploit.CVE-2006-3730 FOUND
/root/tmp/framework-3.2/modules/exploits/windows/browser/.svn/text-base/ms06_057_webview_setslice.rb.svn-base: Exploit.CVE-2006-3730 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 596476
Engine version: 0.95.1
Scanned directories: 5839
Scanned files: 10424
Infected files: 2
Data scanned: 59.41 MB
Data read: 28.86 MB (ratio 2.06:1)
Time: 10.129 sec (0 m 10 s)
I understand that some AV scanners see the exploits in the tarball and will say that the archive contains a virus; but the issue here is the Avira scanner doesn't even get that far, it looks like it can't even scan inside the file, whereas other scanners I've tried can. I know Avira supports archives like this (I've seen it scan others before), but I think there's something going on here when it can't scan this one.
This piece of software, if you're not familiar with it, is used to do penetration testing, etc. so I know it includes these exploits.