ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Botnet worm exploits Symantec flaw

Joris Evers CNET News.com

Published: 18 Dec 2006 10:02 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new worm that uses a known security hole in Symantec's corporate antivirus tools to spread has hit the Net, experts warned on Friday.

The worm, dubbed "Big Yellow" by eEye Digital Security, turns vulnerable computers into remote-controlled zombies. It is the second such malicious code in as many months that exploits a 6-month-old security flaw in Symantec Client Security and Symantec AntiVirus Corporate Edition. A fix for the flaw has been available since May.

The new "botworm" scans for computers running the vulnerable Symantec software and then attempts to break in, said Marc Maiffret, chief technology officer at eEye, a security software maker. The threat appears to be widespread, Maiffret said. eEye is tracking a server used by the worm to download part of its malicious payload; that server has pushed data out to more than 60,000 systems, he said.

Symantec is aware of the new worm, which it calls "Sagevo", said Vincent Weafer, a senior director at Symantec Security Response. However, the company doesn't see it as a big threat. Only three customers have seen it and there isn't anything more than "background noise" on Symantec's network of security sensors, he said.

"Technically eEye is correct, there is a new botworm out there," Weafer said. "But the impression and the worm alert is misleading because we are not seeing any activity."

A similar worm, a variant of Spybot, spread last month. When installed on a PC, both Spybot and Big Yellow open a back door in the system and connect to an Internet Relay Chat server to let the remote attacker control the compromised computer. Such remote control software is the most prevalent threat to Windows PCs, according to Microsoft.

The fact that a bug in Symantec's widely used security software is being exploited by worms underscores a security trend that experts have pointed out before: attackers are increasingly looking beyond the operating system for flaws.

"Any time you have vulnerability in a major application, the likelihood of having it used in a botworm is much higher," Weafer said. "Vulnerability research and exploits are going from operating system level into the application level. It is something we're going to continue to see."

And while patching Microsoft applications has become second nature for many IT departments, the same does not hold true for other software programs, Maiffret said. "People should be thinking about non-Microsoft software when it comes to patching," he said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
269 out of 299 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Network Engineer up to 35k pa + bens

An exciting opportunity has arisen to work for a leading IT Consultancy. A talented Network Engineer is urgently required to maintain the companys ...

Systems Administrator / 2nd Line Support, Deeside, 20,000

Technical Requirements: - Exchange support & maintenance - Windows Server 2003 support & maintenance - Backup Exec - Proxy/Firewall/VPN - Antivirus & ...

Windows IT Technician/ 2nd Line Support, Swindon

Backups Veritas Antivirus This is a second line/third line, hands on position so you must have worked in a similar type of role before. I have an ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Biometric devices. Do you need one?

When saying “biometrics” I am not thinking about law enforcement, AFIS systems, national ID and visa projects. I first think about personal solutions that will make my life easier.... More

1 comment

Barracuda launches counter-suit agains...

Court cases are never pleasant or simple. The ongoing battle between security companies Trend Micro and Barracuda Networks took a new twist on Wednesday, when Barracuda launched a counter-suit... More

Post a comment

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment