ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Veritas systems in the firing line

Joris Evers CNET News.com

Published: 01 Jul 2005 09:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security flaw in a Veritas backup tool is being exploited to attack corporate systems, the US watchdog for Internet threats has warned.

Malicious code to exploit a vulnerability in Veritas' Backup Exec Remote Agent for Windows is publicly available, the US Computer Emergency Readiness Team said in an alert on Thursday. The organisation has received reports of attacks and has seen an increase in scanning activity on TCP Port 10000, an indication that hackers are looking for vulnerable systems.

The buffer overflow flaw in the Veritas software could allow an intruder to gain control of a vulnerable system. The tool is used to trigger backup of data on Microsoft Windows servers, to protect the data from computer crashes, storage system catastrophes and other risks. It listens for commands addressed to TCP Port 10000 and accepts links to the backup server before the backup. However, it fails to properly validate incoming packets, Veritas said in an advisory last week.

The Backup Exec Remote Agent bug is one of several flaws in Backup Exec products that Veritas provided fixes for last week. The problem was discovered by security company iDefense, the storage company said.

The company and US-CERT are urging companies to apply the patches. For protection, they could also use a firewall to filter traffic on Port 10000 to accept only commands from backup servers, US-CERT said.

A Veritas representative said the company is not aware of any attacks on customer systems.

Veritas is in the process of merging with security specialist Symantec.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
78 out of 152 people found this useful


Full Talkback thread

0 comments

Related Jobs

Asset Management company London seeks Desktop support analyst

Expertise required Three years experience of user support and system administration in a Microsoft Windows environment Windows XP & Vista, Microsoft ...

3rd Line support Engineer- Exchange 07 & Active Directory- Immediate

Backups / Restores - Backup Exec System Recovery Server Edition / Backup Exec for Windows Servers. I am currently looking for a 3rd Line Engineer who ...

Operations Support Analyst

As an Operations Support Analyst your main responsibilities will involve: - Providing technical support in relation to the IT Infrastructure and ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment