Security flaw in Symantec's antivirus updater
The tool used to update the virus definitions in Symantec Corp.'s antivirus products has a security hole that can allow hostile code to be downloaded to PCs, according to the German hacking group Phenoelit.
LiveUpdate, the software used by Symantec's antivirus software to automatically update virus protections when updates become available, has flaws in both the 1.4 and 1.6 versions that allow for the attacks, Phenoelit said. When LiveUpdate 1.4 looks for updates, it attempts to connect to a specific server at Symantec, the group said. That connection, however, can be hijacked using a number of DNS (domain name server) attacks and rerouted to the server of the attacker's choice, Phenoelit said. If an attacker recreates the proper directory structure on the server the connection is sent to, any code can be downloaded to the user's machine and executed, the group said.
Version 1.6 doesn't have as extensive a vulnerability, but can fall victim to a network performance degradation attack, the group said. The use of a special Symantec data format for the updates and cryptographically signed update files prevents the same kind of attacks that LiveUpdate 1.4 can be hit with, Phenoelit said. Version 1.6 can also be prevented from receiving any updates, even if they are available, by using the connection hijacking attack and manipulating some files on the destination server, the group said.
Phenoelit notified Symantec of the flaw on Sept. 22, according to documents on the group's Web site. Symantec did not immediately return calls seeking comment.
The group advised users to upgrade to LiveUpdate 1.6, though it noted that LiveUpdate 1.6 is still vulnerable to the network degradation attack. It also urged Symantec to use new cryptographic signing methods and to tell its customer about the security flaws in LiveUpdate 1.4.
Symantec, in Cupertino, California, can be reached at +1-408-253-9600 or via the Web at http://www.symantec.com. Phenoelit's full advisory can be found on the group's Web site at http://www.phenoelit.de/stuff/LiveUpdate.txt.
ITworld.com
Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world
jfruh
Apple syncing patent can't come soon enough
pasmith
New Twitter features borrow from 3rd party clients
Esther Schindler
Open Source Changes the Software Acquisition Process
mikelgan
How to set up continuous podcast play on the new iTunes
David Strom
Five important Windows 7 mobility features
sjvn
Guard your Wi-Fi for your own sake
Sandra Henry-Stocker
Grepping on Whole Words
Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325
Join the conversation here
Quick, practical advice for IT pros. Made fresh daily.
Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.












