Symantec AntiVirus Hole Found 241
Posted
by
CowboyNeal
from the safer-than-sorry dept.
from the safer-than-sorry dept.
Hotwater Mountain writes "eWeek has a story about a gaping security flaw in the latest versions of Symantec's anti-virus software suite that could put millions of users at risk of a debilitating worm attack. According to eEye Digital Security, the company that discovered the flaw, the vulnerability could be exploited by remote hackers to take complete control of the target machine 'without any user action.'"
Re:Older Versions? (Score:3, Interesting)
jsut because they release updates on wensdays and i don't thing they will have a cert'ed patch ready by wensday as this is a holiday weekend and their customers don't matter to them (at least the ones that could be infected)
AntiVirus is for Newbs (Score:2, Interesting)
I had a bit of a problem a few years ago with SpyWare, first I Installed a IE plugin and then moved to FireFox.
These 'Security' behemoths are insane. They hog 20%+ of computer resources with their 'real time scanning'. The only time anything needs to be scanned is when it's first comming to your computer. Downloads need to be scanned, that's it! If I download something questionable, I'll run it through Trend Micro online scan before running.
Daily backups are the key. And not Whole Fucking Hard Drive Backups like most insane backup programs want to do. Backup your damn documents and data.
Firefox and a little common sense and this whole virus/spyware thing is just not an issue for me. I haven't run SpyBot/AdAware since last year. I occasionally scan my download folder with TM Online.
tit for tat? (Score:3, Interesting)
Recent history:
Does anyone else feel that this time line suggests that the last item or two might be part of a hidden agenda? Are we witnessing the start of a FUD throwing contest between two of the industry's major players?
I am so confused. What web news publishers should I now put my faith in?
Alternatives to Symantec Antivirus? (Score:5, Interesting)
Has anyone deployed something other than Symantec Antivirus in a 250 PC company? If so, I'd like to hear your experiences.
Re:It depends (Score:5, Interesting)
So now we don't have to worry about this security hole, which means we can finally say that something good came out of using Rational Clearcase.
I'm getting tired trying to keep up. (Score:2, Interesting)
We need to fix root cause of the problem. Not restore service, but fix it.
It's time to tackle this problem at the compiler level. Get rid of the various IDE wizards, where the latest summer student can spend 5 minutes building a so called enterprise class application.
Instead of the next dual core processor, maybe the industry could spend some time on software and get it right.
Re:Alternatives to Symantec Antivirus? (Score:3, Interesting)
Fairly happy with it.
smash.
oh piffle (Score:2, Interesting)
Re:Alternatives to Symantec Antivirus? (Score:2, Interesting)
The downside is that it's not as user friendly as the others. Sophos only sell to business customers and hence expect it to be installed by a competant sysadmin. Once you've learnt how to manage it though it's beautiful. One of the products I can install on a network and then ignore for the next 18 months with 100% confidence that it'll sit there and do its job, and will warn me if it can't.
In 4 years I can remember only one bad update, they had a workaround within hours and a fix within a day or two.
Sophos technical support is another good reason for dealing with them. You get straight through to a native english speaking team and even their first line staff have a depth of experience with the product that makes a welcome change from the usual idiots.
Re:Throw me a friggin bone! (Score:3, Interesting)
Past exploits in software firewalls where issues in the packet inspection engine. The engine packs itself infront of the tcpip stack of windows and inspects _every_ packet that goes in or out, regardless of wheter it connects to some port or not. This is done in order to log the packet and to reassure the user with annoying popups that his investment was worth his money.
Back to antivirus: This thing also scans email. It does this by scanning the traffic on pop3 and imap ports. My suspicion is that it does this regardless of the connection state. E.g. if you send packets from port 110 to the target machine it probably inspects them, even if the target machine isn't currently downloading any email. Again: this is speculation on my part.
To answer the parent's questions:
If the above is the case:
- Do I have to browse to a malicious website?
Probably not.
- Do I have to download an infected file for it to scan?
It's possible that the worm also works when an email is scanned. So if you recieve an email that has such a virus attached your machine would be also infected even if you'd use a hardware firewall.
- Does it somehow come in on Live Update?
Unlikley. You'd have to do a man in the middle attack for that. E.g. capture the users dns traffic or route his traffic through the mitm. Both rather unlikley in an Internet scenario unless you have a _really_ lousy provider.
- What if I have a firewall?
In a connection-state tracking software firewall it would matter in what comes first: the antivirus or the firewall. A hardware firewall would protect you better as it comes first in any case, but it wouldn't protect you from an exploit that travels from your e-mail account to your machine.
IMO symantec products all suffer from bloat:
- Way too many features, no average user can comprehend. (and i have a suspicion that the devlopers don't either.)
- The install base from the complete package is probably above 100MB. I think a firewall and
antivirus should be doable in a fraction of that. (excluding signature files)
- They slow the systems they are installed to to a crawl.
- I get 5+ support calls a day that deal with broken symantec products. (e-mail and internet related.)
Please use FreeAVG, AntiVir or learn how to use ClamAV!
Better yet: install FOSS software like i have done years ago, and get rid of _all_ these problems in an instant.
Free alternatives to Symantec Antivirus (Score:3, Interesting)
AVG Anti-Virus [wikipedia.org]
Re:Details? (Score:3, Interesting)
Just wait until some PHB or road warior brings thier laptop in and it is infected. Or my favorite, Someone (law clerk) was bringing in Files that her computer at home wouldn't open corectly to see if the work computers could open them because they seem to do more. I guess the idea was to make sure they weren't needed before they got deleted.
And what of the firewall is a nortan product? or spread VIA email too. Ohh well
The Hows: A well reasoned theory and some impacts (Score:4, Interesting)
AS A SYMANTEC EMPLOYEE, I AGREE (Score:2, Interesting)
Nothing suprising about this "development" (Score:4, Interesting)
I normally recommend something along the lines of AVG or Avast! to customers after that little experience. People normally learn after their wallet gets hit a few good times for computer repair.
Re:Details? (Score:2, Interesting)