Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Critical bug found in anti-virus software
New Scientist news service ^ | 22 December 2005 | Will Knight

Posted on 12/23/2005 9:05:03 AM PST by george76

A critical software bug has been discovered in several of the most widely used anti-virus programs. It could be exploited to take control of a computer or to steal information, according to an analysis produced by the independent security analyst who made the discovery.

The glitch affects 39 different Symantec products - including both home and enterprise versions of its anti-virus software. It resides within the Symantec anti-virus library, which is used by all of the packages.

The analyst, Alex Wheeler, discovered that a critical error occurs when the Symantec anti-virus library decompresses files from "RAR" format for analysis

Symantec has confirmed the problem and produced an advisory of its own. It is currently working on a permanent fix but has released an update so that computers running its anti-virus software should automatically detect and block attempts to exploit the bug.

(Excerpt) Read more at newscientist.com ...


TOPICS: Business/Economy; Crime/Corruption; Extended News; Government; News/Current Events; War on Terror
KEYWORDS: antivirus; avast; avg; bitdefender; computer; mcafee; n00bs; nod32; norton; panda; rar; rarformat; software; sophos; spying; symantec; trendmicro; zonealarm
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-76 next last
To: MplsSteve

AVG has missed two invasions of my system over the last two months. I found them in standard scans. I use AVG, AdAware SE and Spybot Search and Destroy in combination.


21 posted on 12/23/2005 9:18:12 AM PST by Colonel_Flagg ("Defeatism may have its partisan uses but it is not justified by the facts.")
[ Post Reply | Private Reply | To 6 | View Replies]

To: xrp

I too quite all anti-virus swft. Too much of a resourse hog, and slows things down. I NEVER email in html, txt only, delete cookies daily, and dump cache several times daily.


22 posted on 12/23/2005 9:18:36 AM PST by devane617 (An Alley-Cat mind is a terrible thing to waste)
[ Post Reply | Private Reply | To 3 | View Replies]

To: LostInBayport; All

I am going to ditch Norton when my subscription runs out next month.

Thanks to all for the suggestions on this thread about Trend Micro and some of the other good ones.

I couldn't figure out why my 'puter slowed down more and more after each Symantec update. I'm a little behind the curve, not being a computer professional--just an ordinary user.

I finally figured out that if I deleted the calendar in Microsoft Works, it would solve a Norton glitch. Just look for wks.cal.exe on your hard drive and get rid of it.

Better yet, get rid of Norton altogether.


23 posted on 12/23/2005 9:19:41 AM PST by Palladin (Merry Christmas! God bless us, every one!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Spktyr
AVG is a good system.

The best prevention of infection is the person sitting at the keyboard.

I generally do not have antivirus software installed on my computer (Windows Server 2003 / Ubuntu) while my wifes (XP Pro) does have AVG installed along with antisypware software. I will periodically and temporarily install AVG and AdAware on my system just to check and have never found anything (apart from the standard cookies and java.byte.verify) while my wife's computer I have to clean every month.
24 posted on 12/23/2005 9:19:55 AM PST by ndt
[ Post Reply | Private Reply | To 11 | View Replies]

To: NoCmpromiz

ping


25 posted on 12/23/2005 9:24:54 AM PST by DJ MacWoW (If you think you know what's coming next....You don't know Jack.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All
Help for viruses and malware:
 
 Ad-Aware ... Spybot ... Peper Uninstaller ... HijackThis... CWShredder ... Spyware Blaster ... IE Spyad ... BitDefender Free online Virus scan ... Trend Micro Free online Virus scan ... Kaspersky Free online Virus scan ... Ewido Anti-Malware ... LSPfix ... How to Show Hidden Files ... How to boot into Safe Mode ... How did I get infected in the first place?


Things you need--(all FREE)

Anti-Virus
AVG

 Avast
Firewall
Kerio(Direct Download) Zone Alarm
 If are using zone alarm it may slow your PC. Try Outpost Firewall http://www.agnitum.com/products/outpost or Sygate Firewall http://www.sygate.com/, both have FREE and Pro versions and are heads above ZA.
Misc.
IE Spyads SpywareBlaster Spyware Guard
Windows Update- you must keep updated, it is the start of a secure system-
get all CRITICAL Updates

26 posted on 12/23/2005 9:25:19 AM PST by jdm (I'm not blunting.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: xrp

I don't even use a computer. Just pen and paper for me.


27 posted on 12/23/2005 9:26:49 AM PST by Maceman (Fake but accurate -- and now double-sourced)
[ Post Reply | Private Reply | To 3 | View Replies]

To: iPod Shuffle; LostInBayport; NoClones
I dropped Symantec too. I read a review that said that Symantec hadn't updated the engine in eons, therefore,
it was slow, and a resource hog.

That, and I remember it having install problems, granted, the site had the workaround info, but still a pain, and a few
other annoying problems. I guess they considered them FAD or "features" that couldn't be disabled, either permanently, or
temporarily.

28 posted on 12/23/2005 9:26:49 AM PST by Calvin Locke
[ Post Reply | Private Reply | To 2 | View Replies]

To: jdm

Sorry about the errors. I just realized a few links are dead.


29 posted on 12/23/2005 9:27:40 AM PST by jdm (I'm not blunting.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: jdm

Thank you for that.

Now will you come to my house and fix everything for me?


30 posted on 12/23/2005 9:28:19 AM PST by Palladin (Merry Christmas! God bless us, every one!)
[ Post Reply | Private Reply | To 26 | View Replies]

To: george76

bump


31 posted on 12/23/2005 9:29:17 AM PST by Maceman (Fake but accurate -- and now double-sourced)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Maceman

"I don't even use a computer. Just pen and paper for me."

LOL. Me, I prefer Lotus Notes.


32 posted on 12/23/2005 9:29:28 AM PST by jdm (I'm not blunting.)
[ Post Reply | Private Reply | To 27 | View Replies]

To: 1FASTGLOCK45

One of my old machines that still runs on w98 crashed badly during the latest ZoneAlarm update. Took me about six hours over a month to debug it and now I don't think I will reload their Shareware firewall on it again.


33 posted on 12/23/2005 9:30:10 AM PST by KC Burke (Men of intemperate minds can never be free....)
[ Post Reply | Private Reply | To 14 | View Replies]

To: george76
Critical software bug or FBI back-door?

You decide:


AV vendors split over FBI Trojan snoops:

Keystroke loggerheads

By John Leyden
Published Tuesday 27th November 2001 18:44 GMT

Antivirus vendors are at loggerheads over whether they should include in their software packages detection for a Trojan horse program reportedly under development by the FBI.

A keystroke logging Trojan, called Magic Lantern, will enable investigators to discover break PGP encoded messages sent by suspects under investigation, MSNBC reports. By logging what a suspect types, and transmitting this back to investigators, the FBI could use Magic Lantern to work out a suspect's passphrase. Getting a target's private PGP keyring is easy in comparison, and with the two any message can be broken.

MSNBC quotes unnamed sources who says that Magic Lantern could be sent to a target by email or planted on a suspect's PC by exploiting common operating system vulnerabilities.

Although unconfirmed, the reports are been taken seriously in the security community, and are consistent with the admitted use of key-logging software in the investigation of suspected mobster Nicodemo Scarfo. In that case, FBI agents obtained a warrant to enter Scarfo's office and install keystroke logging software on his machine.

Magic Lantern, which would be an extension of the Carnivore Internet surveillance program, takes the idea one step further by enabling agents to place a Trojan on a target's computer without having to gain physical access.

The suggested technique creates a clutch of legal, ethical and technical issues. Greater powers in the Patriot Act, which Congress is considering, may allow the tool to be used. But what if it was modified for use by hackers?

And antivirus vendors are mulling over the rights and wrongs of putting Magic Lantern on their virus definition list.

Eric Chien, chief researcher at Symantec's antivirus research lab, said that provided a hypothetical keystroke logging tool was used only by the FBI, then Symantec would avoid updating its antivirus tools to detect such a Trojan.

Symantec is yet to hear back from the FBI on its enquiries about Magic Lantern.

"If it was under the control of the FBI, with appropriate technical safeguards in place to prevent possible misuse, and nobody else used it - we wouldn't detect it," said Chien. "However we would detect modified versions that might be used by hackers."

Graham Cluley, senior technology consultant at Sophos, disagrees. He says it it wrong to deliberately refrain from detecting the virus, because its customers outside the US would expect protection against the Trojan. Such a move also creates an awkward precedent.

Cluley adds: "What if the French intelligence service, or even the Greeks, created a Trojan horse program for this purpose? Should we ignore those too?"

34 posted on 12/23/2005 9:30:15 AM PST by Ol' Dan Tucker (Karen Ryan reporting...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 1FASTGLOCK45
Best protection. Two computers. Only one that does not contain my valuable files is connected to the Internet.
35 posted on 12/23/2005 9:31:48 AM PST by Logical me (Oh, well!!!)
[ Post Reply | Private Reply | To 14 | View Replies]

To: george76

AVG is the best I've found so far. Much easier on system resources too. Norton is garbage.


36 posted on 12/23/2005 9:32:16 AM PST by reagan_fanatic (Darwinism is a belief in the meaninglessness of existence - R. Kirk)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Same here - great program


37 posted on 12/23/2005 9:33:27 AM PST by ItsOurTimeNow ("Hail Him who saved you by His grace, and crown Him Lord of All")
[ Post Reply | Private Reply | To 8 | View Replies]

To: george76

Cisco Security Agent is better.


38 posted on 12/23/2005 9:34:22 AM PST by Centurion2000 ((Aubrey, Tx) --- America, we get the best government corporations can buy.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Maceman
I don't even use a computer. Just pen and paper for me.

I still use my computers. But I discovered that if I write on the front surface of the screen with a grease pencil, rather than on the back side with the keyboard, I can avoid viruses altogether and save $30/year.

Take that, Norton!

39 posted on 12/23/2005 9:39:03 AM PST by Hank Rearden (Never allow anyone who could only get a government job attempt to tell you how to run your life.)
[ Post Reply | Private Reply | To 27 | View Replies]

To: george76

This is ridiculous "the sky is falling" journalism at its worst; don't get caught up in it Freepers. It's a nice "bash-a-successful-company" tone that belongs on socialist/commie Slashdot but not here.

(1) There is no known public exploit of this vulnerability. And Symantec has released a heuristic (signature) that detects it, so if you are using Symantec software in the first place, you are probably getting the most up-to-date update so now you are OK.

(2) if you are a consumer, you would get infected only if you interact and download a malicous RAR file, which is a not-very-popular file compression algorithm. And for it to "take over your computer", the malicious file would have to be written to successfully execute code on you PC/laptop, which is no easy feat.

(3) if your company's or ISP's Gateways are using Symantec's email security products, the admins could/would have put a block on RAR files until Symantec came out with the heuristic, which was a span of less than 36 hours.

(4) Symantec Antivirus Corporate Editions 8 & 9 are not affected; that makes up about 90% of the corporate pie.

Move along folks; nothing to see here.

And shame on you Freepers who got duped :-)

Any other questions, please email me at iggy_e@yahoo.com. As you can guess, I know something about this.


40 posted on 12/23/2005 9:40:03 AM PST by American in Singapore (Liberals: They even lie in their diaries)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-76 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson