Advertisement
Promo

Security threats Toolkit

Web attacks: Cure worse than disease?

Steven J. Vaughan-Nichols ZDNet.co.uk

Published: 09 Mar 2000 10:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Trend Micro's enterprise anti-viral program OfficeScan -- which also scans for denial-of-service (DoS) vulnerabilities -- also is a prime vehicle for foul play. According to Bugtraq reports and Trend Micro itself, OfficeScan also opens the door for internal attacks.

OfficeScan, it turns out, suffers from several problems. If the product is set to be administered from a server, as commonly done, an attacker can impersonate the server and crash clients. Indeed, all it takes to lock up a client system is opening up more than five simultaneous connections and then flooding them with random data.

Sysadmins can seal this hole by upgrading to version 3.5 of OfficeScan, which allows users to set the update features to other ports, and installing the updated dynamic link library, 3508tmsock.dll. For registered OfficeScan 3.1x's users, that is a free upgrade.

There's more trouble lurking in OfficeScan. Unlike all other Trend Micro products, OfficeScan doesn't have an authentication/crypto-protected protocol between clients and the program manager. That means within a network on the same subnet, there are numerous ways to use OfficeScan to do everything from cause a LAN-wide DoS attack, to rewrite entire hard drives, to subtlety place invisible Trojan programs on computers.

For the short-term, the only solution is to disable the NTlisten.exe service on systems. By the end of the week, Trend Micro claims it will have a better answer. Dan Schrader, VP of new technology at Trend Micro, acknowledges these problems are "very significant and we're taking it seriously."

Specifically, by this weekend, Trend Micro will be releasing a patch that will automatically update OfficeScan programs to include authentication and encryption of commands and data flying between server and clients. Those, and other improvements, should seal this hole, he says.

Why are the fixes taking a week? According to Schrader, because OfficeScan works on heterogeneous networks, Trend Micro is "making sure it's bulletproof before we release it." Ironically, the news of the OfficeScan vulnerability follows on the heels of Microsoft's offer of a free copy of OfficeScan for Microsoft Small Business Server 4.5 with every copy of SBS 4.5 purchased between March 1 and June 30.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
66 out of 104 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Video icon

Video

Sentry Posts Blog

homer

lets show everyone that labour has compasion[whilst there counting the votes] running upto march/april 2010...http://tinyurl.co...nus very good nb gordon brown said today on our... More

Post a comment

This Crap Site

How utterly stupid - I am ranked #40 in the top 100 - as a member of this site..... I mean HOW utterly stupid.... I have done sweet FA, I have only rejoined this site after a 3 or... More

Post a comment

Microsoft Security Update: November Pa...

Apologies for this late update to our core Patch Tuesday update. Here is a summary of the update .... The November Patch Tuesday update from Microsoft follows the largest patch and... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters