[comp.virus] SAM Loophole

KMREANE@ERENJ.BITNET (08/03/90)

  Another Loophole in SAM Intercept

  Folks:

We have discovered another loophole that can allow a person to bypass the
floppy scan in SAM intercept.

If you are in an application and want to open a file on a floppy, SAM
will scan the floppy you insert. If, however, while in the File Open
dialog box, you click on EJECT and insert another floppy, this floppy
(and any other subsequent floppies you insert) are not scanned by SAM.

This "loophole" in SAM would allow you to infect your unit if there is
a virus on the second or later floppies. Since most viruses go on to
infect the system files, SAM would pick up the infection the next time
you reboot your machine (provided you have configured your copy to
scan the system folder at startup)

We have notified Symantec of this loophole and would appreciate further
confirmation.