ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Veritas patches backup flaw

Dawn Kawamoto CNET News.com

Published: 14 Oct 2005 10:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Veritas on Wednesday issued a patch for a security flaw in its Java authentication service running on NetBackup servers and clients.

The vulnerability in question could let attackers gain remote access to information stored on backup servers.

For Veritas, owned by security-software giant Symantec, this latest flaw in its backup software is the third security glitch in less than four months. In this case, however, the vulnerability not only affects the server but also client systems, said Johannes Ullrich, chief research officer for the SANS Institute.

NetBackup 4.5, 5.0, 5.1 and 6.0, running on all platforms and all versions, are affected by the vulnerability, according to a posting on Veritas' support site.

An attacker could remotely exploit a flaw in the Java authentication service, bpjava-msvc, running on NetBackup servers and clients. The attacker potentially could then execute code.

"The problem with this vulnerability is it's not only running on all the desktops, but, even worse, if a malicious hacker gets into the backup server, they have access to all your backup information," Ullrich said.

Though no exploit code has been found, hackers are laying the groundwork needed to take advantage of the flaw once exploit code is available, Ullrich noted. Hackers are scanning far more computer systems to ascertain if the systems are vulnerable.

He added that users, especially those who experienced a fallout several months ago from an earlier Veritas vulnerability, are likely to patch the most recent flaw quickly.

"A few months ago, there was a similar (Veritas) backup problem that was widespread and caused a lot of headaches," Ullrich said. "People who didn't patch quickly last time will do it much faster this time."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
82 out of 160 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Windows Engineer

Team player MCSE (or ability to demonstrate knowledge to that level or higher) DESIRABLE SKILLS/QUALIFICATIONS: Exchange 2003 Veritas netbackup CA ...

Pre-sales Consultant-NAS Storage, De-duplication,VTLs, NFS, CiFS iSCSI

Pre-sales Consultant-NAS Storage, De-duplication,VTLs, NFS, CiFS FCP iSCSI, HBA Server Conneectivity, Veritas Netbackup, Disaster Recovery, Windows, ...

Systems Engineer

NT netbackup administration Maintain an up-to-date knowledge of evolving MS and other relevant technologies, for example: Server/Desktop OS; Active ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment