Top Tech News

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Tech Leaders
Friday, November 20th 
Home
Network Security
Microsoft/Windows
Linux/Open Source
Apple/Macintosh
Wireless Tech
World Wide Web
Tech Trends
Data Storage
Software
Hardware
Communications
Spam & Hackers
Chips & Processors
E-Business
Personal Tech
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement
Network Security

New Worm Attacks Through Symantec Antivirus App

New Worm Attacks Through Symantec Antivirus App
December 18, 2006 12:45PM

Bookmark and Share
The software vulnerability through which the Big Yellow worm is able to penetrate Windows PCs was patched by Symantec in May 2006. But according to eEye Digital Security, many I.T. departments have not yet rolled out the fix, leaving these computers vulnerable to attack.


A new worm is making the rounds, attacking some business computers through a known -- and already patched -- flaw in a popular antivirus software suite from security Relevant Products/Services firm Symantec.

The worm, called "Big Yellow" and discovered initially by eEye Digital Security, zaps vulnerable computers with malicious code and turns them into remote-controlled zombie machines capable of wreaking all sorts of havoc at the behest of the hackers responsible for creating the worm.

Big Yellow exploits a vulnerability in the remote-management interface for Symantec AntiVirus and Symantec Client Security software packages.

Marc Maiffret, eEye's founder and CTO, said that the threat appears to be widespread and that eEye is tracking a server Relevant Products/Services used by the worm to download part of its malicious payload. That server has pushed data Relevant Products/Services out to more than 60,000 PCs already, according to eEye's data.

Old Vulnerability

Although eEye discovered and reported this vulnerability in May 2006 and worked with Symantec to create a patch at that time, many I.T. departments have not yet deployed the fix, Maiffret said. "Given the rapid discovery of critical security vulnerabilities within desktop Relevant Products/Services applications other than Microsoft Relevant Products/Services, the release of malware of this magnitude targeting non-Microsoft software was only a matter of time," noted Maiffret.

Maiffret also said users need to realize that attacks not only target Microsoft software but also the myriad applications that are scattered throughout a corporate network Relevant Products/Services, from antivirus software to media applications. These non-Microsoft desktop applications, many of which are not even approved by I.T. departments, will become the enterprise Relevant Products/Services's biggest point of vulnerability, according to Maiffret.

However, Natalie Lambert, an analyst with Forrester Research, said that while the flaw is potentially fatal to some systems, the fact that a fix for the hole was first pushed out by Symantec last May means diligent users can stop the worm in its tracks. Lambert said it is the casual user, not the enterprise, that is most likely to be affected by this outbreak.

"Consumers are the weak link here," said Lambert, who noted that it's the job of I.T. administrators to constantly update and protect their company's network. "And they are generally very good at it," she said.

No Zero-Day Attack (continued...)

1  |  2  |  Next Page >

Advertisement


 Network Security
1. Peer-to-Peer Software Ban Sought
2. Los Alamos Computer Security Weak
3. Security Firm Fortinet Plans IPO
4. Heartland Restraining Order Denied
5. Social-Networking Security a Concern


advertisement


 Most Popular Articles
1. Verizon's Buzz for Motorola's Droid Fizzles at Day's End
2. Facebook Hijacking Points To Social-Networking Holes
3. Motorola's Droid 'Doing Fine' with About 100,000 Sold
4. Dell Will Debut Mini 3 Smartphone in China and Brazil
5. Sophos, Microsoft Disagree on Windows 7 Security

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Barnes & Noble Nook Is Delayed
  Ballmer Says Windows 7 Sales Good
  New Pogoplug 'Cloud' Gets Social
  Chrome OS Team Aims for Speed
  FAA Glitch Causes Air Travel Delays

 Technology Marketplace
Business Intelligence
IBM - Smarter business for a Smarter Planet.
 
Compliance
Webcast: SOX, GLBA, HIPAA Compliance and IT security controls.
 
Customer Service
Rackspace Hosting: 24x7x365 Support, Windows and Linux Certified
 
Data Security
Secure your data center today with the TippingPoint N-Platform
 
Enterprise Hardware
IT Costs out of Control? Download APC's FREE Cooling Efficiency kit.
 
Enterprise I.T.
Learn how Microsoft server upgrades can create efficiencies
Rackspace: It makes a difference when you focus on support
IBM - Smarter technology for a Smarter Planet.
Simplify. Automate. Innovate. The new network is here.
IT Costs out of Control? Download our FREE Cooling Efficiency kit.
Windows 7 Enterprise designed specifically for IT Professionals
 
Enterprise Software
Open cross-network software provides rich user experiences and fast time to market.
 
Innovation
3-D scaling lets networks support more subscribers, services & bandwidth -- at the same time.
 
Microsoft/Windows
Read about how to add efficiencies with Microsoft Virtualization.
Check out the new Windows 7 features. Download the FREE trial.
 
Network Security
Junos software platform and Juniper systems provide new cloud-networking & security solutions.
 
Security Products
Secure your data center today with TippingPoint's N-Platform
 
Navigation
Top Tech News
Home/Top News | Network Security | Microsoft/Windows | Linux/Open Source | Apple/Macintosh | Wireless Tech | World Wide Web
Tech Trends | Data Storage | Software | Hardware | Communications | Spam & Hackers | Chips & Processors
E-Business | Personal Tech
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2009 Top Tech News. All rights reserved. Article rating technology by Blogowogo.