ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Symantec admits to LiveUpdate security hole

Wendy McAuliffe ZDNet.co.uk

Published: 11 Oct 2001 12:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A group of German hackers have exposed a new vulnerability in Symantec's LiveUpdate 1.4, which could be used to download and run hostile code from an unauthorised server.

Symantec, which makes antivirus and security software, has confirmed that older versions of its virus definition software will allow the deployment of malware such as trojan application viruses, and the remote penetration of systems running LiveUpdate. The risk of unauthorised intrusion is lessened on systems running the latest version 1.6, but network degradation and outages could still be possible.

The German hacking group Phenoelit who spotted the security hole is adamant that LiveUpdate could be forced to download illicit programmes onto the querying host. "When LiveUpdate 1.4 is started (either by hand or by a scheduled task), it looks for the server 'update.symantec.com'," states the Phenoelit bulletin. "An attacker can use one of several attacks to return false information to the querying host."

According to the Phenoelit alert, when the host running LiveUpdate tries to connect to update.symantec.com via FTP, it is possible for an attacker to redirect the request to a server of their choice. LiveUpdate will then try to download the necessary files, which will be compared with existing versions of Symantec software installed on the host to see if an upgrade is needed. LiveUpdate will then uncompress the files and perform the actions described in their coding, which includes the execution of downloadable attachments.

LiveUpdate 1.6 follows the same update procedure, but includes the safeguard of "cryptographic signatures" of all update files. According to Symantec, this makes it virtually impossible to use the latest version as a penetration tool. Mis-direction attacks can also be controlled by Norton AntiVirus products, which are designed to detect and block malware.

Despite admitting to the vulnerability of its product, Symantec is refusing to accept all of the responsibility. "The DNS attacks... have been widely known to be an Internet infrastructure problem, not a Symantec product problem, for some time and have been utilised in many well-publicised DNS spoofing, redirection, cache poisoning attacks," reads the Symantec response.

The company is also insisting that although LiveUpdate 1.6 could be hit by a denial of service attack, "only a small percentage of a very large user base could potentially be impacted to any degree as the spoofing or redirection would, by its very nature, be limited to a local Internet area/region".

Symantec is encouraging users to upgrade to LiveUpdate 1.6 if they are still relying on the four-year-old 1.4 version.

See the Viruses and Hacking News Section for the latest headlines.

See the Net Crime News Section for the latest on hacking, fraud, viruses and related issues.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read other letters.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
58 out of 110 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Upgrade from VB to C# - By the coast in Devon

VB6/VB.NET developers - upgrade to the latest C#! Windows and Web Joining an expanding development team, with a multitude of projects, you will be ...

Internet Team Leader

Responsibility for maintaining the integrity of the networks (i.e.providing adequate protection from viruses, spam, hacking, compliance with the Data ...

SAP BASIS CONSULTANT - Support/Upgrade - NorthWest

The role being offered will involve delivery of support to upgrade projects of systems from R/3 4.5b to ECC 6.0 including building test systems and ...

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains