techPowerUp! Forums

Go Back   techPowerUp! Forums > www.techpowerup.com > News

Reply
 
Thread Tools
Old Jan 17, 2007, 12:38 AM   #1
zekrahminator
McLovin
 
zekrahminator's Avatar
 
Join Date: Jan 2006
Location: My house.
Posts: 6,280 (2.35/day)
Thanks: 105
Thanked 340 Times in 246 Posts
Send a message via ICQ to zekrahminator Send a message via AIM to zekrahminator Send a message via MSN to zekrahminator

System Specs

Persistant 'zombie' attacks target systems protected by corporate editions of Symantec antivirus

Once again, it really pays to keep your virus protection updated. A new worm, which seems to be a spybot variant, works on a flaw found in older versions of Symantec antivirus for corporations. While personal editions of the software are not affected, any corporation running an older version of Symantec Norton will be vulnerable to the worm. The worm turns whatever it infects into a "zombie" PC, which only serves to copy and send the virus. Symantec had a fix for the problem on May 25th, but not all users downloaded it. Symantec is re-evaluating it's patch/virus definition distribution method.

Source: CNET
zekrahminator is offline  
Reply With Quote
Old Jan 17, 2007, 01:23 AM   #2
PVTCaboose1337
Graphical Hacker
 
PVTCaboose1337's Avatar
 
Join Date: Feb 2006
Location: San Antonio, Texas
Posts: 7,478 (2.81/day)
Thanks: 798
Thanked 1,174 Times in 834 Posts

System Specs

Noobs got pwnt.
__________________
CPU-Z validation sig pics temporarily blocked
PVTCaboose1337 is offline  
Reply With Quote
Old Jan 17, 2007, 04:14 AM   #3
Steevo
Eligible for custom title
 
Steevo's Avatar
 
Join Date: Nov 2005
Posts: 5,567 (2.02/day)
Thanks: 238
Thanked 979 Times in 729 Posts

System Specs

Trying to see if you haxored your stuff and are running a webserver, or FTP.



It happens.
__________________

“it would have been perfect....its got trains and the line"tech your kids not to do what iv done"(or similar) because i had obviously done something to warrent 2 e-thugs to come 4000miles out of their way and kill me.” -Solaris17
“yeah i failed. i noticed the "coming soon" part after i posted.” -Mussels
“people are just stupid.” -W1zzard
Yes I am evil, yes you can have some.
Steevo is offline  
Reply With Quote
Old Jan 17, 2007, 12:33 PM   #4
WarEagleAU
Bird of Prey
 
WarEagleAU's Avatar
 
Join Date: Jul 2006
Location: Gurley, AL
Posts: 9,994 (3.99/day)
Thanks: 3,810
Thanked 557 Times in 521 Posts
Send a message via AIM to WarEagleAU Send a message via Yahoo to WarEagleAU

System Specs

Symantec is a great product, but they cant force everyone to update and download new patches (though, I think all Antivirus companies should automatically force a download of a patch, just to make sure folks are protected).
__________________
=-TheEagle-=



http://www.heatware.com/eval.php?id=62454
“You crazy? Surfing any website without an antivirus is like freaking with a dirty woman without protection” -OzzmanFloyd120
- Edited for content and clarity
WarEagleAU is offline  
Reply With Quote
Old Jan 17, 2007, 12:47 PM   #5
DanTheBanjoman
Señor Moderator
 
DanTheBanjoman's Avatar
 
Join Date: May 2004
Location: Utrecht, Utrecht, The kingdom of the Netherlands
Posts: 8,498 (2.59/day)
Thanks: 41
Thanked 1,453 Times in 1,077 Posts
Send a message via ICQ to DanTheBanjoman Send a message via MSN to DanTheBanjoman

System Specs

Quote:
Originally Posted by WarEagleAU View Post
Symantec is a great product, but they cant force everyone to update and download new patches (though, I think all Antivirus companies should automatically force a download of a patch, just to make sure folks are protected).
Symantec is the company. As for their products, they're mostly bloated memory hogs.
DanTheBanjoman is offline  
Reply With Quote
Old Jan 17, 2007, 02:13 PM   #6
overcast
500 Posts
 
Join Date: Jan 2006
Posts: 707 (0.26/day)
Thanks: 0
Thanked 2 Times in 2 Posts

System Specs

Quote:
Originally Posted by russianboy View Post
my good System Suite 7 protects me excellently


(SS7 told me that my ISP was doing portscans wtf? )
Those software "firewall" , "security" suite whatever things, constantly show false positives about everything. However, it's not out of the question that an ISP would do portscans to check for users hosting services such as www and ftp.
overcast is offline  
Reply With Quote
Old Jan 17, 2007, 02:40 PM   #7
Alec§taar
Banned
 
Alec§taar's Avatar
 
Join Date: May 2006
Location: Someone who's going to find NewTekie1 and teach him a lesson
Posts: 3,380 (1.32/day)
Thanks: 0
Thanked 102 Times in 101 Posts

System Specs

HOW TO SECURE VULNERABLE SERVICES vs. BUFFEROVERFLOW ESCALATION OF PRIVELEGE ATTACKS

HOW TO SECURE VULNERABLE SERVICES vs. BUFFEROVERFLOW ESCALATION OF PRIVELEGE ATTACKS

Per a discussion I had w/ Russ Cooper from NtBugTraq here on our forums in this NEWS section:

A "working-work around" I discovered earlier in 2005-2006 & posted here on these forums (now a STICKY thread in the GENERAL SOFTWARE SECTION of the forums) & prior to that on SETI@Home & Folding@Home forums, that should help in the meantime, is listed below...

http://forums.techpowerup.com/showth...495#post232495

=============================================
PERTINENT MATERIAL EXCERPT:
=============================================

Quote:
Originally Posted by NTBugtraq View Post
2. "Shatter" attacks. Shatter attacks are where a process is launched which, as you've been referring to regarding messages between processes, feeds events/messages to other processes that have higher privilege. For example, in the past many AV programs had a core that ran as SYSTEM, and then UI processes that ran in the context of the running user. These components had methods to talk to each other. If I could gain control of the user component, I might be able to exploit the SYSTEM component...thereby gaining elevated privilege.
A safe & easy to implement technique vs. THIS VERY THING you note in exploitable services running as SYSTEM when they don't HAVE TO BE as their logon entity.

SECURING VULNERABLE SERVICES AGAINST ATTACK FORUM POST:

http://forums.techpowerup.com/showthread.php?t=16097

& later here, when the folks here "wikipediafied it":

SECURING VULNERABLE SERVICES AGAINST ATTACK TPU WIKI:

http://reference.techpowerup.com/Sec...ndows_Services

The technique noted by myself counters for services buffer overflow escalation of privelege attacks (the very thing you noted as an example, & it works against it, by lowering services logon privelege entities - very safe & simple) IF the service in question is securable thus (not ALL are unfortunately due to WHAT they may have to be able to do, priveleges wise).

Many antivirus makers' ware can have their services/daemons can be limited to NETWORK PROCESS entity levels, & lower, like LOCAL PROCESS levels.

Also, NORTON ANTIVIRUS (corporate edition @ least, post v.10.1 iirc) has "ANTITAMPER PROTECTION" as well, keeping its services list running no matter what - works well, I can't even MANUALLY SHUTDOWN 10.2 IF I TRY AS ADMIN!)...

----------------------------------------------------------

SYMANTEC CORP. EDITION CLIENT SERVICES TO SET AS LOCAL SERVICE (& they will still work fully & fine):

Symantec AntiVirus
Symantec AntiVirus Definitions Watcher Service

SYMANTEC CORP. EDITION CLIENT SERVICES TO SET AS NETWORK SERVICE (& they will still work fully & fine):

SAV Roam
Symantec LiveUpdate

=============================================



* Microsoft now also has a subset of this material (covering only their default OS services though, ONLY (my list has FAR MORE that apply & can do this) on their technet/knowledgebase websites, which appeared 6 months or more after I wrote mine up!

(So, that said? Well, you KNOW this works well enough, as a substantiation of it, because MS has it also, albeit far after the article I authored here & elsewhere on it, & far less services this security technique applies to!)

APK

P.S.=> This technique also works in the patched model, 10.2 (& above), of the Norton/Symantec Corporate Edition AntiVirus client program, some "FYI" & a good general measure of protection against exploitable services (not just NORTON/SYMANTEC ONES, mind you)!

The URL above detailing HOW this defense mechanism is done (easy, via services.msc) also notes many other services this can apply to, to protect you vs. this type of attack... apk
Alec§taar is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT. The time now is 09:13 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts