With all of the talk about source-code theft, extortion attempts by a shadowy probably-Anonymous-affiliated group, and most importantly the Giants winning the Super Bowl, I thought I’d spend a moment to reflect on what the release of source code for PCAnywhere and, in all likelihood, a depreciated version of Norton Antivirus could mean for the average persistent threat.
Much of the commentary on the topic, specifically that relating to PCAnywhere, has downplayed the release, owing to the age of the stolen code and number of active users. While it is true that installations of PCAnywhere certainly do not seem to be as widespread as they once were, it is certainly still out there and remains utilized by large private and government organizations. Although I don’t consider the release of PCAnywhere source to be particularly severe, I do question why Symantec chose to advise users to cease use of the product after the release and not before. And what makes it so sure that the product is now safe? In any case, the question of Norton Antivirus may be a little complex.
Targeting security products (whether that be an IDS, firewall, or AV product) is hot business these days, and vulnerabilities in antivirus engines can be extremely valuable to attackers if it means they are now able to slip an email attachment or drive-by download that would have otherwise been caught onto the target's system.
Anyone that has ever worked with, or had anything to do with, any kind of software product company will know that while names, logos, and even the interface for a product may change over time, the code behind it all will not necessarily follow suit. Even in circumstances where a “complete rewrite” has been done, they seldom ever are, and even in extreme cases we all know that a certain amount of CTRL-C/V action is going to go down somewhere along the way.
Note that although at the time that this was written the source code for Norton Antivirus does not appear to have been made public, we can safely assume that the stolen code has been shared privately, amongst a closed community associated with the individual responsible for the original heist.
So what does this all mean? Well, for the high-end adversary, probably not a whole lot as you’re likely to already have a copy of the source code. And it’s likely to be a much more recent version. On the other hand, folks who do not have a few hundred Gs laying around for bribing the employee of a software vendor so he’ll cut you a DVD full of source code are likely to see this as something of an opportunity. Through the use of not-uncommon analysis tools, figuring out which code segments are shared between the compromised source and possible modern derivatives thereof is a relatively trivial and inexpensive task.
While many groups who may do such a thing have probably put Symantec products under the microscope before, source-code analysis often opens up a whole, new world of subtle bugs in hard-to-reach regions of code that may have previously gone unnoticed. While the world's most well-funded and sophisticated actors are unlikely to find the release of source code particularly exciting, this may provide an excellent opportunity for less well-resourced groups involved in organized crime (such as botnet herders) and acts of industrial espionage to get one up on a product that has in the past spoiled the fun.
Tom Parker is Chief Technology Officer at FusionX.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
How Did They Get In? A Guide to Tracking Down The Source of an APT
If you think that your organization hasn't been affected by an advanced persistent threat, you probably haven't looked hard enough. Identifying that your organization is under attack is difficult enough; determining the scope of infiltration and damage presents a whole new level of challenge. To effectively protect against APTs, security pros will need to employ an arsenal of tools in a coordinated fashion, as well as develop new understandings of and approaches to system and data exploits. Here's a short and simple guide to this challenge.
Detecting and Defending Against Advanced Persistent Threats
APTs are a growing problem for enterprises big and small. Protecting your organization from these targeted threats
requires constant vigilance, ongoing employee training and a concerted effort to align security systems to address
every phase of an APT. Companies also need to develop a remediation and response plan if, despite best efforts, defenses are breached.
Smarter, Stealthier, Sneakier Malware
Increasingly sophisticated and targeted attacks are making it more difficult for organizations to detect
and defend against the latest malware. In this compendium of recent coverage from Dark Reading, you?ll get a look at some of the newest -- and most dangerous -- malware on the Web, and what you can do to stop it.
Other reports from the Advanced Threats Tech Center:
| Sponsored by: |
MOBILE SECURITY - Mapping an Ecosystem of Risk
This white paper highlights the various considerations for defending mobile applications-from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.
Software Security Delivered in the Cloud
This Solution Guide details the automated, turnkey service that requires no special security assessment expertise. It details HP's market-leading static and dynamic analysis technologies that help organizations worldwide gain insight into the security state of their essential business applications.
SANS Mobility/BYOD Security Survey
This survey, which includes input from more than 500 IT professionals, explores how organizations are managing risk around their end user mobile devices as well as what level of policies and controls enterprises have around mobile usage.
Expert Guide to Application Security - Real-time Hybrid Analysis
Explore the next generation of hybrid security analysis - what it is, how it works, and its benefits. This white paper details how hybrid application security enables organizations to resolve critical software security issues faster and at a lower cost than any other available technology.
A Mainstay Partners Study: Does Application Security Pay?
Measuring the Business Impact of Software Security Assurance Solutions: a study of 17 organizations that implemented solutions from Fortify Software, combining industry research and benchmark analysis to identify, qualify, and quantify the full range of benefits seen from their SSA investments.
MORE NEWSFEED >>>