On TV.com: ANGELINA JOLIE looks stunning as usual
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: Jan 16, 2007 9:17:00 PM

Symantec first dismissed the threat, but worm attacks that exploit a known security hole in the company's corporate antivirus tool are proving to be persistent.

The attacks target computers running older versions of Symantec Client Security and Symantec AntiVirus Corporate Edition. Compromised systems are turned into remotely controlled zombies by the attacker and used to relay spam and other nefarious activities. Symantec's Norton consumer software is not affected.

"What we have been seeing in December and in the last week and a half is related to new variants of Spybot," Vincent Weafer, senior director of Symantec Security Response, said Tuesday. "We had a couple of versions of Spybot that went nowhere, but these ones found a way to propagate more effectively."

The Spybot variants break into computers through a known security hole in the widely used Symantec antivirus tools. When installed on a PC, Spybot opens a back door in the system and connects to an Internet Relay Chat server to let the remote attacker control the compromised computer. Spybot first surfaced in 2003 and has spawned many offshoots.

The first version of Spybot to exploit the Symantec security hole surfaced in November. This was followed in December by another pest dubbed Sagevo, or Big Yellow. Symantec initially dismissed both threats, stating that their impact was minimal. While Sagevo fizzled, Spybot is causing harm, Weafer said.

"We're definitely seeing Spybot out there and seeing that it is being trapped in customer environments," he said. The attacks have been escalating since December 20, when Symantec and its customers first saw increased activity on TCP port 2967, the network port used by the vulnerable software.

A fix for the flaw has been available since May 25, but it appears not all users have applied the fix. Unlike Symantec's consumer products, the corporate antivirus software doesn't include automatic product updates.

"Customers have to go to the support site and download the update," Weafer said. The security fix is different from the regular definition updates, which are automatically delivered to both consumer and corporate virus shields, he said.

Symantec is re-evaluating the update mechanism for its corporate tools, Weafer said. Additionally, the company on Wednesday plans to push out an update to its antivirus scanning engine that is designed to better detect Spybot, he said. The engine update will go out automatically to all users, he added.

  • Talkback
  • Most Recent of 54 Talkback(s)
slim competition
"works" is Norton System Works. As for competition you may get lots of links when you Google but the majority of what comes up is not really competition for Symantec. Unless I've read great reviews &#... (Read the rest)
Posted by: nikitac Posted on: 03/08/07 You are currently: Logged In | Log out
Gee...this 'article' is a REAL surprise considering the volumn .. nomorems   | 01/16/07
so wait... you're saying that this very real issue... JoeMama_z   | 01/16/07
agreed.. mdsmedia   | 01/16/07
LOOK EVERYONE!!!@ I'M LOVED!!! Loverock Davidson   | 01/16/07
Dude Shelendrea   | 01/16/07
Talk about trolling off the deep end... lenohere   | 01/17/07
the 'article' is a REAL surprise? nds0601   | 01/17/07
Huh? notsofast   | 01/17/07
Minimal Effect... projectnetsafe   | 01/16/07
Patch Management projectnetsafe   | 01/16/07
Indeed.... Wolfie2K3   | 01/16/07
lawsuit? bobzoom   | 01/17/07
The Upgrade Process...... NatiGator   | 01/16/07
sad admin go home Been_Done_Before   | 01/16/07
I feel your pain... BitTwiddler   | 01/23/07
What's the alternative? upuaut   | 01/16/07
my thoughts..... JoeMama_z   | 01/16/07
alts akira_kazooie@...   | 01/16/07
My Security system... voyager529@...   | 01/16/07
First off bumberfsck   | 01/16/07
slim competition nikitac   | 03/08/07
The Alternatives Lynne's Honey   | 01/17/07
Trend is much better georgeou   | 01/17/07
Kaspersky is also very good lenohere   | 01/17/07
That's been my experience too andy88488   | 01/17/07
Message has been deleted. bumberfsck   | 01/16/07
It's Norton... rbert16000   | 01/16/07
McAfee or CA rbert16000   | 01/16/07
No CA for me, ever ken@...   | 01/16/07
McAfee - Never Again JustMichael   | 01/17/07
You should look at Symantec's manual uninstall procedure... BitTwiddler   | 01/23/07
Say What? HeadlessHorseman   | 02/08/07
Trend Micro has worked well andy88488   | 01/17/07
Free Tech Support andy88488   | 01/17/07
AntiVirus=Performance Penalty HeadlessHorseman   | 02/08/07
SAV is a pig stevej@...   | 01/16/07
Clarification Needed please monkey_poop   | 01/17/07
Sophos Anti-Virus SJ2006Tech   | 01/17/07
Norton has always sucked philgoetz   | 01/17/07
Norton is in the business of staying in business Boot_Agnostic   | 01/17/07
Norton's in Business "to stay in Business" SJ2006Tech   | 01/17/07
Norton's in Business "to stay in Business" -- NOT! kenneth.grush@...   | 01/17/07
Norton's in Business "to stay in Business" -- NOT! kenneth.grush@...   | 01/17/07
Symantec BIG prob affects ALL, not just Corp users Questor1   | 01/17/07
Cleaning up Since Monday (15) flourry1@...   | 01/17/07
Spybot..I'm confused kemble88@...   | 01/17/07
SpyBot, AdAware, Symantec d_peters314@...   | 01/18/07
Spybot is also a class of Virus. Has been around for years... BitTwiddler   | 01/19/07
Add Insult to Injury zephyrwind69@...   | 01/18/07
AV nickyburnell@...   | 01/19/07
"Spybot" confusion CWG-Jr   | 01/19/07
Acutally this is "Spybot S&D" PhilippeV   | 01/20/07
Norton is dead. harrycki   | 01/21/07
Symantec only had rootkits before, now its also vulnerable http://www.data-recovery-reviews.com   | 01/28/07

What do you think?

advertisement
advertisement