Showing posts with label Symantec. Show all posts
Showing posts with label Symantec. Show all posts

Wednesday, February 1, 2012

pcAnywhere is Safe Again

Symantec issued a statement updating their pcAnywhere customers with the news that they were able to patch all breach-exposed vulnerabilities that had previously caused the company to advise users to disable the product.
"On Friday, January 27, 2012, Symantec released a patch that eliminates known
vulnerabilities affecting customers using pcAnywhere 12.0 and pcAnywhere 12.1."
Symantec is also offering a free-upon-request upgrade to the latest version of pcAnywhere, version 12.5. Users should send the company an email to their pcanywhere@symantec.com address.

Thursday, January 26, 2012

Symantec Urges Customers to Disable pcAnywhere

The breach of Symantec source code by an Indian hacking group a few weeks ago was all but brushed off by the security giant. Symantec went on the record saying that the leaked code is, "so old that current out-of-the-box security settings will suffice against any possible threats that might materialise as a result of this incident." 

However, in a posting on their website yesterday and an accompanying technical white paper, Symantec suggests that pcAnywhere customers are at a heightened risk and advises users to "disable the product until Symantec releases a final set of software updates that resolve currently known vulnerability risks." Customers could be at risk for "man in the middle" attacks where an unauthorized person accesses pcAnywhere transactions and intercepts data as it travels from its source to its destination. These attacks are more likely because the blueprints for Norton Antivirus Corporate Edition, Norton Internet Security, Norton SystemWorks (Norton Utilities and Norton GoBack) and pcAnywhere were accessed in the breach. The information contained in these blueprints makes it easier to identify and exploit software vulnerabilities. 

Symantec reps say that there are 50,000 people using the standalone version of pcAnywhere along with an unknown number of users who received the product bundled within other security packages.

Friday, January 6, 2012

Symantec confirms source code leak in two enterprise security products


Computer world has a great article on Symantec's recent source code leak in India. It was supposedly taken from a government database in India where it is not uncommon for tech companies to have to submit their source code to prove they are not using their software to spy on the government. I think many organizations will take notice of this breach and begin to push back more on the requirements to submit source code.
Computerworld - Symantec late Thursday confirmed that source code used in two of its older enterprise security products was publicly exposed by hackers this week.In a statement, the company said that the compromised code is between four and five years old and does not affect Symantec's consumer-oriented Norton products as had been previously speculated."Our own network was not breached, but rather that of a third party entity," the company said in the statement. "We are still gathering information on the details and are not in a position to provide specifics on the third party involved. Presently, we have no indication that the code disclosure impacts the functionality or security of Symantec's solutions," the statement said.Symantec spokesman Cris Paden identified the two affected products as Symantec Endpoint Protection 11.0 and Symantec Antivirus 10.2. Both products are targeted at enterprise customers and are more than five years old, Paden said."We're taking this extremely seriously, but in terms of a threat, a lot has changed since these codes were developed," Paden said. "We distributed 10 million new signatures in 2010 alone. That gives you an idea of how much these products have morphed since then, when you're talking four and five years."Symantec is developing a remediation process for enterprise customers who are still using the affected products, Paden noted. Details of the remediation process will be made available in due course, he added.