LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-30-2004, 12:52 PM   #1
conner_f
LQ Newbie
 
Registered: May 2004
Posts: 4

Rep: Reputation: 0
Question wget succeeds in retrieving a virus ftp through a firewall !


I found command wget kept trying retrieve a virus file after failure because of the quarantine by firewall . And after some tries, the virus file was completely retrieved finally !!

I want to know this feature of the firewall is normal or not ? Macfee virus engine was used in the firewall.

Thanks heeps
CF
 
Old 05-30-2004, 01:32 PM   #2
Hko
Senior Member
 
Registered: Aug 2002
Location: Groningen, The Netherlands
Distribution: Debian
Posts: 2,536

Rep: Reputation: 111Reputation: 111
Quote:
Macfee virus engine was used in the firewall.
The thing may be buggy then, I suppose...
 
Old 05-30-2004, 03:46 PM   #3
Systematic
Member
 
Registered: May 2004
Location: Mechanicsburg, PA
Distribution: Mainly Slackware, but test run various different distros.
Posts: 77

Rep: Reputation: 15
was the macafee updated.. does it have the latest .dat file... also what virus was it? would be interesting to know.
 
Old 05-31-2004, 02:26 AM   #4
zmedico
Member
 
Registered: Feb 2002
Location: Mission Viejo, California, USA
Distribution: Gentoo
Posts: 707

Rep: Reputation: 30
Break the virus into small enough pieces and it's patterns aren't recognizable anymore. Encryption would be another way to sneak it through a firewall.
 
Old 05-31-2004, 10:06 PM   #5
crabboy
Senior Member
 
Registered: Feb 2001
Location: Atlanta, GA
Distribution: Slackware
Posts: 1,821

Rep: Reputation: 121Reputation: 121
Moving to Security.
 
Old 05-31-2004, 10:41 PM   #6
witeshark
Member
 
Registered: Jan 2004
Location: Miami FL
Distribution: Mac OS X 10.4.11 Ubuntu 12.04 LTS
Posts: 429

Rep: Reputation: 30
Also if they are compressed the scanner can miss it
 
Old 06-04-2004, 05:46 PM   #7
db391
Member
 
Registered: Jun 2004
Location: Britain
Distribution: Slackware
Posts: 186

Rep: Reputation: 31
Quote:
Originally posted by Systematic
The label said Windows 95 or better, so i installed Slackware!
The label said Window$ 95 or better, so i installed Linux!
 
Old 07-05-2004, 03:32 PM   #8
conner_f
LQ Newbie
 
Registered: May 2004
Posts: 4

Original Poster
Rep: Reputation: 0
They are not compressed and they are scanned by our ftp av deamon. But wget can break it pieces and it's patterns aren't recognizable anymore. That's exactly what zmedico saied.
 
Old 07-05-2004, 06:58 PM   #9
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Actually that's not the reason. The reason is that most gateway AV scanners will "trickle" the file to the client while they buffer it on the firewall to see if there's a virus. This means that before the file is fully downloaded into the firewall's buffer, a little bit of it is downloaded by wget (this is to prevent time-outs while the firewall is buffering). Once the AV scanner on the firewall can scan the full file, it realizes there's a virus and terminates the connection. If you have wget set to resume downloads, it will start over from where it left off. This time it will get a little more of the file before the AV scanner can buffer it and scan it again. Keep repeating this many times and you'll eventually succeed in constructing the entire virus with wget.

The only way to stop this is to turn off the "trickle" option on the AV firewall. Of course, that could cause downloads to time-out on large files because your client would give up before the firewall has finished buffering the file to scan it.
 
Old 07-06-2004, 01:28 AM   #10
MS3FGX
LQ Guru
 
Registered: Jan 2004
Location: NJ, USA
Distribution: Slackware, Debian
Posts: 5,852

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
Er, wouldn't the more pressing question be: why was wget trying to download a virus?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
retrieving wiki pages with wget pete-theobald Programming 4 07-20-2005 09:28 AM
Using wget to copy entire ftp directory stuartmunro Linux - Newbie 7 06-17-2005 07:06 PM
wget and FTP mikz Linux - Newbie 1 05-07-2005 03:10 PM
wget - retrieving one folder of website davidhayter Linux - Software 4 03-07-2005 08:20 PM
wget from a ftp thesnaggle Linux - Networking 1 11-06-2003 12:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:17 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration