Symantec (Norton) AV Corporate Edition vulnerable to hacks

Real Life Events.

Go off topic and I will break you!

Moderator: Dictators in Training

Symantec (Norton) AV Corporate Edition vulnerable to hacks

Postby Arlos » Thu May 25, 2006 4:25 pm

Talk about irony...

All you IT people here on NT should be aware of this, and get ready to patch all your user's machines if you're running corporate version of Symantic AV

WASHINGTON (AP) -- Symantec Corp.'s leading antivirus software, which protects some of the world's largest corporations and U.S. government agencies, suffers from a flaw that lets hackers seize control of computers to steal sensitive data, delete files or implant malicious programs, researchers said Thursday.

Symantec said it was investigating the issue but could not immediately corroborate the vulnerability. If confirmed, the threat to computer users would be severe because the security software is so widely used and because no action is required by victims using the latest versions of Symantec Antivirus to suffer a crippling attack over the Internet.

Symantec has boasted that its antivirus products are installed on more than 200 million computers. A spokesman, Mike Bradshaw, said the company was examining the reported flaw but described it as "so new that we don't have any details."

Researchers from eEye Digital Security Inc. of Aliso Viejo, California, discovered the vulnerability and provided evidence to Symantec engineers this week, said eEye's chief hacking officer, Marc Maiffret. He demonstrated the attack for The Associated Press.

eEye said it appeared consumer versions of Symantec's Norton Antivirus software -- sold at retail outlets around the country -- were not vulnerable to the flaw, though consumers who are provided Symantec's corporate edition antivirus software by their employers for use at home may be affected.

Maiffret's company -- which has discovered hundreds of similar flaws in other software products -- also produces intrusion-protection software, called "Blink," that he said already blocks such attacks and can operate alongside Symantec's antivirus products.

Maiffret published a note about the company's discovery on its Web site but pledged not to reveal details publicly that would help hackers attack Internet users until after Symantec repairs its antivirus software. eEye said it intends to describe the problem in detail privately for some of its largest customers.

"People shouldn't panic," Maiffret said. "There shouldn't be any exploits until a patch is produced."

The reported flaw comes at an awkward time for Symantec. Its chief executive, John Thompson, has campaigned in recent months to convince consumers they should trust Symantec -- not Microsoft Corp. -- to protect their personal information.

Maiffret said eEye's testing showed the problem affects Symantec Antivirus Version 10, including its corporate editions. He said Symantec's consumer antivirus product, known as Norton Antivirus 2006, and its current security suite -- which includes both antivirus and firewall features -- did not appear to be vulnerable.


-Arlos
User avatar
Arlos
Admin Abuse Squad
Admin Abuse Squad
 
Posts: 9021
Joined: Thu Mar 11, 2004 12:39 pm

Postby Martrae » Thu May 25, 2006 6:54 pm

IMO anyone using anything other than AVG is asking for trouble.
Inside each person lives two wolves. One is loyal, kind, respectful, humble and open to the mystery of life. The other is greedy, jealous, hateful, afraid and blind to the wonders of life. They are in battle for your spirit. The one who wins is the one you feed.
User avatar
Martrae
Admin Abuse Squad
Admin Abuse Squad
 
Posts: 11962
Joined: Mon Mar 15, 2004 9:46 am
Location: Georgia

Postby Gidan » Thu May 25, 2006 7:19 pm

If my box at work had anything norton on it, I would immediatly uninstall it. With the exception of Norton Ghost, now that I like.
For to win one hundred victories in one hundred battles is not the acme of skill. To subdue the enemy without fighting is the acme of skill.
User avatar
Gidan
Admin Abuse Squad
Admin Abuse Squad
 
Posts: 2892
Joined: Tue Jan 04, 2005 11:01 am


Return to Current Affairs

Who is online

Users browsing this forum: No registered users and 41 guests