ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Symantec flaw found by TippingPoint bounty hunters

Tom Espiner ZDNet.co.uk

Published: 14 Oct 2005 18:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security flaw in Veritas's NetBackup application has been found and patched through an initiative run by TippingPoint that pays security researchers who find and report bugs.

TippingPoint, a subsidiary of 3Com, announced the first fruits of its Zero Day Initiative (ZDI) on Thursday. Through ZDI, TippingPoint rewards security researchers who inform 3Com of vulnerabilities and do not publicly disclose them before the vendor has issued a patch.

3Com reported the potential threat to Veritas parent company Symantec on 12 September. Symantec went public with the flaw and issued a patch a month later, on 12 October.

But according to TippingPoint, 3Com customers using its intrusion prevention systems were issued protection against the Symantec vulnerability almost immediately, and -- unlike other Symantec customers -- have been protected against the flaw for the past month.

TippingPoint says it was was tipped off about the vulnerability by an independent researcher. It affects NetBackup 4.5, 5.0, 5.1 and 6.0, running on all platforms and all versions.

An attacker could potentially remotely exploit a format string overflow vulnerability in the Java authentication service, bpjava-msvc, running on NetBackup servers and clients. The attacker could then execute arbitrary code.

"The problem with this vulnerability is it's not only running on all the desktops, but, even worse, if a malicious hacker gets into the backup server, they have access to all your backup information," said Johannes Ullrich, chief research officer for the SANS Institute.

Under ZDI, 3Com will reward security researchers who inform them about "zero day vulnerabilities". These are vulnerabilities "that are unknown and for which there is no patch," 3Com said.

CNET News.com's Dawn Kawamoto contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
65 out of 120 people found this useful


Full Talkback thread

1 comment

  1. ARE THERE ANY SUCH THIING AS AbOUNTY hUNTER IN THE... DEON MCKENZIE

Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Asset Management company London seeks Desktop support analyst

Expertise required Three years experience of user support and system administration in a Microsoft Windows environment Windows XP & Vista, Microsoft ...

Pre-sales Consultant-NAS Storage, De-duplication,VTLs, NFS, CiFS iSCSI

Pre-sales Consultant-NAS Storage, De-duplication,VTLs, NFS, CiFS FCP iSCSI, HBA Server Conneectivity, Veritas Netbackup, Disaster Recovery, Windows, ...

Presales Systems Engineer, SE, Consultant - Storage NAS SAN - Vendor

You should have core skills across NAS and iscsi as well as Software Data Protection such as Veritas Netbackup, Legato Networker, Tivoli Storage ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment