Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

January 26th, 2012, 09:09 GMT · By Eduard Kovacs

Symantec: Users Should Disable pcAnywhere to Prevent Attacks

SHARE:

Adjust text size:


Symantec pcAnywhere users may be exposed
Enlarge picture
There have been many rumors around the hacking operation that affected Symantec back in 2006, resulting in the theft of source code for some of their products. Now the company came forward with official “security recommendations,” advising customers to disable their pcAnywhere products until they release a patch.

Symantec confirms that products from the 2006-era are affected by the data breach that took place at the time, including Norton Antivirus Corporate Edition, Norton Internet Security, Norton SystemWorks, which includes Norton Utilities and Norton GoBack, and pcAnywhere, a software that allows direct PC-to-PC communications.

A detailed analysis of the situation reveals that most customers aren’t exposed due to the age of the products.

“There is nothing additional that customers of these products need to do beyond adhering to best practices. The code that has been exposed is so old that current out-of-the-box security settings will suffice against any possible threats that might materialize as a result of this incident,” reads the advisory.

On the other hand, pcAnywhere customers should be somewhat concerned, especially those who use the 12.0, 12.1, 12.5 and prior versions of the product. pcAnywhere is also bundled with numerous other products such as Altiris based solutions and backup and security products.

Users who rely on these applications are exposed because the encoding and encryption elements within pcAnywhere are vulnerable, allowing a cybercriminal to launch a successful man-in-the-middle attack, depending on the configuration and the way it’s used.

Basically, traffic could be intercepted and encoded if a network sniffer is placed in the customer’s internal network, but this implies that the attacker either has a malicious insider or has a botnet operating in the environment.

“At this time, Symantec recommends disabling the product until Symantec releases a final set of software updates that resolve currently known vulnerability risks,” the security solutions provider advises customers.

Also, they recommend that consumers follow some general security best practices to mitigate the issue.
FILED UNDER:
Symantec
advisory
hacked

TELL US WHAT YOU THINK:

1,202 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hackers Obtain Norton Antivirus Source Code, Symantec Investigates

Symantec: Hackers Obtained Enterprise Product Source Code, Not Norton

Hacker Reveals Norton Utilities Code to Aid Scareware Lawsuit Plaintiff

Symantec Sued for Scaring Customers into Buying Their Products

Symantec: Norton Code Stolen in 2006 Hacking

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM