Go Back   Trackpads Community > General Discussions > Chit-Chat

Chit-Chat Non-debate discussions - uncontroversial topics not covered in other forums , light-hearted, heartwarming, risque, weird news, fun things etc.

Reply
 
LinkBack Thread Tools
Old 05-27-2006, 01:21   #1 (permalink)
Monkey Mouse
 
Woodmonkey's Avatar
My Awards Rack
Gold Staff Service Medal Gold Reputation Medal Bronze Referrals Medal Bronze Magazine Medal Silver Gallery Medal Gold Donations Award Silver Donations Award 2 Blue Star 
Total Awards: 12
My Mood
My Mood:
Status
Woodmonkey is online now
Post Count
58,261
My Photos
My Photos: 108
Staff Title
Trackpads XO
Member Flags
United States us connecticut
My Referrals
My Referrals: 15
Personal Guestbook
Reputation +/-
Woodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond reputeWoodmonkey has a reputation beyond repute
Petz
Other Swag
T-Bucks: 90,775.56
Bank: 1,341,109.03
Total T-Bucks: 1,431,884.59
     
     
     

 
Default Symantec AntiVirus Worm Hole Puts Millions at Risk

Symantec AntiVirus Worm Hole Puts Millions at Risk

A gaping security flaw in the latest versions of Symantec's anti-virus software suite could put millions of users at risk of a debilitating worm attack, Internet security experts warned May 25.

Researchers at eEye Digital Security, the company that discovered the flaw, said it could be exploited by remote hackers to take complete control of the target machine "without any user action."

"This is definitely wormable. Once exploited, you get a command shell that gives you complete access to the machine. You can remove, edit or destroy files at will," said eEye Digital Security spokesperson Mike Puterbaugh.

Click here to read about Symantec's use of a rootkit-type feature in its Norton SystemWorks.

"We have confirmed that an attacker can execute code without the user clicking or opening anything," Puterbaugh said.

eEye, based in Aliso Viejo, Calif., posted a brief advisory to raise the alarm about the bug, which can allow the execution of malicious code with system-level access. The flaw carries a "high risk" rating because of the potential for serious damage, Puterbaugh said.

Symantec, of Cupertino, Calif., confirmed receipt of eEye's warning and said an investigation was underway.

"[Our] product security team has been notified of a suspected issue in Symantec AntiVirus 10.x. [We] are evaluating the issue now and, if necessary, will provide a prompt response and solution," a Symantec spokesperson said in a statement sent to eWEEK.

Symantec's anti-virus software is deployed on more than 200 million systems in both the enterprise and consumer markets, and the threat of a network worm attack is very real. However, eEye's Puterbaugh said there are no publicly shared proof-of-concept exploits or other information to suggest an attack is imminent.

But, he said, "there's nothing to say that someone hasn't found this and is already using it for nefarious activities. … It's quite possible that we weren't the only ones to find this. Who knows if it's already being used in targeted attacks that we'll never hear about."

To read about Symantec patches for a DNS cache-poisoning and redirection vulnerability in several of its products, [u]click here.[/url]

Internet security experts have long warned that flaws in anti-virus products will become a big target for malicious hackers. During the last 18 months, some of the biggest names in the anti-virus business have shipped critical software updates to cover code execution holes, prompting speculation among industry watchers that it's only a matter of time before a malicious hacker is motivated to create a devastating network worm using security software flaws as the attack vector.

"The big surprise is we haven't seen one yet," said Johannes Ullrich, chief technology officer at the SANS ISC (Internet Storm Center), of Bethesda, Md., in a recent eWEEK interview.

In March 2004, the fast-moving Witty worm exploited a zero-day buffer overflow in security products sold by Internet Security Systems. Unlike most self-propagating worms, Witty was capable of corrupting the hard drives of infected machines, preventing normal operation of the PC and eventually causing it to crash.

"This could be Symantec's Witty," Puterbaugh warned.

The vulnerable Symantec 10.x application promises real-time detection and repairs for spyware, adware, viruses and other malicious intrusions. It is used by many of the world's largest corporate customers and U.S. government agencies.

The Source
__________________
~~~~~~~~~~~~~~~~~
How May I Help You?





PM me through this link if clicking on those banners doesn't help with your questions

~~~~~~~~~~~~~~~~~
Woodmonkey is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Trackpads Information
Click to Visit
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Symantec AntiVirus Worm Hole Puts Millions at Risk Woodmonkey Computer and Technology 0 05-27-2006 01:21
[News Feed] Symantec Reports Critical Security Flaw in AntiVirus Scan Engine Forum Mouse News Articles 0 10-07-2005 02:00
[News Feed] Symantec Patches Antivirus App Forum Mouse News Articles 0 09-06-2005 22:00
[News Feed] Symantec Acknowledges Two Holes in Antivirus Products Forum Mouse News Articles 0 03-30-2005 22:00
[News Feed] Symantec Awarded Antivirus Patent Forum Mouse News Articles 0 03-03-2005 16:00


Community Information
Options
Quick Options
Trackpads Non-Commercial Ad
Copyright Information Click to Visit
Time
Server Time
All times are GMT -4. The time now is 01:52.
Copyright
Copyright Information
The header is based off of work by Vipixel.com and modified by this site. Trackpads and the Trackpads Logo are both Registered Trademarks of Jason Edwards and cannot be used without prior written permission.  The only exception is as a link back to this site. Trackpads is a private website run by a small legion of volunteers, 3 dogs, 12.5 cats and an army of small, super smart, bio-engineered mice with pointy hats and tutu's. Search Engine Friendly URLs by vBSEO 3.2.0 RC7
Archive Links
Archive Links
Page generated in 0.63254 seconds with 21 queries