Feeds

Flaw means virus could disable Norton Anti-Virus

Symantec is the string vest of Internet security

  • alert
  • submit to reddit

Intelligent flash storage arrays

A security loophole has been discovered in Norton Anti-Virus (NAV) which could allow the creation of a virus able to shut down the software on a user's machine.

In an advisory available here, Peter Kruse of Scandinavian telco Telia argues that a "very obvious and unsafe registry entry that makes it quite simple to disable NAV 2001".

According to Kruse, if the registry key NAV 2001 is changed in value Norton Anti-Virus startup is disabled, leaving users without any protection against viruses when they restart their machine.

The upshot of this, said Kruse, is that using either a virus or a remote administrator tool, a cracker could take out a Symantec user's antivirus protection, which could be restored only by reinstalling the software or editing the registry entry.

Symantec said the issue was been handled out of its US office and we weren't able to speak to anyone before press (pub) time. According to American reports, however, Symantec has played down the significance of the potential vulnerability by saying it only affects the product's on-demand scanner and not its core real-time scanner, which is called AutoProtect.

Despite this Symantec is taking the issue seriously enough to announce plans that it will change the way Norton AntiVirus uses a PC system's registry starting with NAV 2002.

Previous versions of NAV, Symantec's flagship antivirus product (prior to NAV 2001), were not tested for the vulnerability so it's not known if users of older products are affected by the alleged bug. ®

Related Links

Newsbytes: Symantec Downplays Disabling Attack On Norton AntiVirus
Access to registry entry could allow malicious code to shutdown N AV2001

Beginner's guide to SSL certificates

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
USB coding anarchy: Consider all sticks licked
Thumb drive design ruled by almighty buck
Attack reveals 81 percent of Tor users but admins call for calm
Cisco Netflow a handy tool for cheapskate attackers
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Reducing the cost and complexity of web vulnerability management
How using vulnerability assessments to identify exploitable weaknesses and take corrective action can reduce the risk of hackers finding your site and attacking it.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.