Symantec corporate software under attack

Symantec first dismissed the threat, but worm attacks that exploit a known security hole in the company's corporate antivirus tool are proving to be persistent.

The attacks target computers running older versions of Symantec Client Security and Symantec AntiVirus Corporate Edition. Compromised systems are turned into remotely controlled zombies by the attacker and used to relay spam and other nefarious activities. Symantec's Norton consumer software is not affected.

"What we have been seeing in December and in the last week and a half is related to new variants of Spybot," Vincent Weafer, senior director of Symantec Security Response, said Tuesday. "We had a couple of versions of Spybot that went nowhere, but these ones found a way to propagate more effectively."

The Spybot variants break into computers through a known security hole in the widely used Symantec antivirus tools. When installed on a PC, Spybot opens a back door in the system and connects to an Internet Relay Chat server to let the remote attacker control the compromised computer. Spybot first surfaced in 2003 and has spawned many offshoots.

The first version of Spybot to exploit the Symantec security hole surfaced in November. This was followed in December by another pest dubbed Sagevo, or Big Yellow. Symantec initially dismissed both threats, stating that their impact was minimal. While Sagevo fizzled, Spybot is causing harm, Weafer said.

"We're definitely seeing Spybot out there and seeing that it is being trapped in customer environments," he said. The attacks have been escalating since December 20, when Symantec and its customers first saw increased activity on TCP port 2967, the network port used by the vulnerable software.

A fix for the flaw has been available since May 25, but it appears not all users have applied the fix. Unlike Symantec's consumer products, the corporate antivirus software doesn't include automatic product updates.

"Customers have to go to the support site and download the update," Weafer said. The security fix is different from the regular definition updates, which are automatically delivered to both consumer and corporate virus shields, he said.

Symantec is re-evaluating the update mechanism for its corporate tools, Weafer said. Additionally, the company on Wednesday plans to push out an update to its antivirus scanning engine that is designed to better detect Spybot, he said. The engine update will go out automatically to all users, he added.

Like this article? Click below to send it to your mobile for free!

Talkback 2 comments

  1. Norton 360 Revis Martin -- 29/08/07

    The first problem I had was that Norton 360 vanished from my system. I had to reinstall it. The next problem was that automatic update would not complete. That also had to be reinstalled. I don't trust the software for a minute. Furthermore I will not renew it.

    1. My Live Update will not run! Mark Thomas -- 09/11/07

      Have any of you had this problem. you start a system Scan or just do a Live Update, and it Failes to run. It tell you it can't connect to the server. I have been on the phone with Norton Teck Support for about a week now, off and on, with the same Priority ID# and they still can't fix my problem.

Add your opinion


Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay Australian Govt funds IT start-ups
    This week Australia's Federal Government announced it had allocated $3.6 million in funding to 57 local research projects so that they could be commercialised, with many of them being web or IT-related start-ups.
  • Array Google should come clean on datacentres
    It's nice that Google says it has put an effort into making its datacentres more energy efficient, but the search giant's pledges won't mean much until it discloses just how many of the beasties it's actually running.
  • Array US shows what OPEL could have been
    Sprint's WiMAX roll-out in Baltimore will prove the Australian government's decision to worm its way out of the Opel WiMAX contract was a short-sighted, and ultimately damaging, political stunt that has benefited nobody.
  • More blogs »

Tags

Back to top

Featured