Vulnerabilities / Threats
1/26/2012
09:45 AM
50%
50%

Symantec: Users Should Disable PCAnywhere Now

Symantec moves into damage-control mode after LulzSec leader tweets the remote-access software may be used to launch exploits.

The source code theft involves more than just the pcAnywhere application, and Symantec Tuesday detailed all products involved. "Our investigation continues to indicate that the theft is limited to only the code for the 2006 versions of Norton Antivirus Corporate Edition; Norton Internet Security; Norton SystemWorks (Norton Utilities and Norton GoBack); and pcAnywhere," according to Symantec.

What exactly could malicious actors do with the source code to pcAnywhere? In a white paper released Tuesday, Symantec detailed the potential risks, which include breaking the encryption or encoding used by the product, which would allow attackers to launch successful man-in-the-middle attacks, through which they could steal a PC user's credentials or session information. In particular, this could allow them to steal the cryptographic key required to remotely connect to the computer. "If the cryptographic key itself is using Active Directory credentials, it is also possible for them to perpetrate other malicious activities on the network," said Symantec.

Similar types of attacks could be launched by insiders or botnets, according to the white paper. In either case, provided that attackers had broken the pcAnywhere encryption, they'd be able to intercept session details or credentials by planting a sniffer in the internal network.

Symantec said the source code stolen in 2006 accounted for approximately 5% of the code found in its Symantec AntiVirus 10.2 product. But it said that users of its 10.x and newer products--aside from pcAnywhere--"should not be in any increased danger of cyber attacks" resulting from the source code theft.

Also on the good-news front, the company said that it now thinks that the source code for Symantec Endpoint Protection 11, released in late 2007, wasn't stolen, as it first suspected. That finding will be a relief for current version 11 users, as well as for Symantec, since the product was the first to contain multiple new types of security technology--also present in its current 12.x product versions--including "heuristic protection, intrusion prevention security, firewall, application control, device control, tamper protection, redesigned core engines, as well as our Symantec Endpoint Protection Manager (SEPM)," according to Symantec.

It's no longer a matter of if you get hacked, but when. In this special retrospective of news coverage, Monitoring Tools And Logs Make All The Difference, Dark Reading takes a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape. (Free registration required.)

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7444
Published: 2015-09-01
The Special:Contributions page in MediaWiki before 1.22.0 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.

CVE-2015-2807
Published: 2015-09-01
Cross-site scripting (XSS) vulnerability in js/window.php in the Navis DocumentCloud plugin before 0.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the wpbase parameter.

CVE-2015-6520
Published: 2015-09-01
IPPUSBXD before 1.22 listens on all interfaces, which allows remote attackers to obtain access to USB connected printers via a direct request.

CVE-2015-6727
Published: 2015-09-01
The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.

CVE-2015-6728
Published: 2015-09-01
The ApiBase::getWatchlistUser function in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 does not perform token comparison in constant time, which allows remote attackers to guess the watchlist token and bypass CSRF protection via a timing attack.

Dark Reading Radio
Archived Dark Reading Radio
Another Black Hat is in the books and Dark Reading was there. Join the editors as they share their top stories, biggest lessons, and best conversations from the premier security conference.