Vulnerabilities / Threats
1/26/2012
09:45 AM
50%
50%

Symantec: Users Should Disable PCAnywhere Now

Symantec moves into damage-control mode after LulzSec leader tweets the remote-access software may be used to launch exploits.

The source code theft involves more than just the pcAnywhere application, and Symantec Tuesday detailed all products involved. "Our investigation continues to indicate that the theft is limited to only the code for the 2006 versions of Norton Antivirus Corporate Edition; Norton Internet Security; Norton SystemWorks (Norton Utilities and Norton GoBack); and pcAnywhere," according to Symantec.

What exactly could malicious actors do with the source code to pcAnywhere? In a white paper released Tuesday, Symantec detailed the potential risks, which include breaking the encryption or encoding used by the product, which would allow attackers to launch successful man-in-the-middle attacks, through which they could steal a PC user's credentials or session information. In particular, this could allow them to steal the cryptographic key required to remotely connect to the computer. "If the cryptographic key itself is using Active Directory credentials, it is also possible for them to perpetrate other malicious activities on the network," said Symantec.

Similar types of attacks could be launched by insiders or botnets, according to the white paper. In either case, provided that attackers had broken the pcAnywhere encryption, they'd be able to intercept session details or credentials by planting a sniffer in the internal network.

Symantec said the source code stolen in 2006 accounted for approximately 5% of the code found in its Symantec AntiVirus 10.2 product. But it said that users of its 10.x and newer products--aside from pcAnywhere--"should not be in any increased danger of cyber attacks" resulting from the source code theft.

Also on the good-news front, the company said that it now thinks that the source code for Symantec Endpoint Protection 11, released in late 2007, wasn't stolen, as it first suspected. That finding will be a relief for current version 11 users, as well as for Symantec, since the product was the first to contain multiple new types of security technology--also present in its current 12.x product versions--including "heuristic protection, intrusion prevention security, firewall, application control, device control, tamper protection, redesigned core engines, as well as our Symantec Endpoint Protection Manager (SEPM)," according to Symantec.

It's no longer a matter of if you get hacked, but when. In this special retrospective of news coverage, Monitoring Tools And Logs Make All The Difference, Dark Reading takes a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape. (Free registration required.)

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-2086
Published: 2015-02-26
Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title.

CVE-2015-2087
Published: 2015-02-26
Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.

CVE-2015-2088
Published: 2015-02-26
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Term Queue module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2015-2089
Published: 2015-02-26
Multiple cross-site request forgery (CSRF) vulnerabilities in the CrossSlide jQuery (crossslide-jquery-plugin-for-wordpress) plugin 2.0.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting (...

CVE-2015-2090
Published: 2015-02-26
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.