Original URL: http://www.theregister.co.uk/2006/01/12/symantec_fixes_rootkit_bug/
Symantec has updated its popular Norton SystemWorks security suite this week following the discovery of a security bug (http://secunia.com/advisories/18402/) that creates a possible means for hackers to hide computer viruses on infected systems. A design error in SystemWorks means files within the NProtect directory of the Norton Protected Recycle Bin are hidden from Windows APIs.
Because of this client-based virus scanning software might be unable to spot malicious or virus-infected files placed in the directory. This rootkit-style vulnerability is only exploitable locally and has not been actively exploited, according to Symantec. Nonetheless the security vendor has rushed out an update which corrects the flaw by ensuring the previously hidden NProtect directory is displayed in the Windows interface.
Users of Norton SystemWorks 2005/2006 and Norton SystemWorks Premier 2005/2006 are urged to apply the patch by running LiveUpdate. Symantec credits Mark Russinovich of Sysinternals and the F-Secure Blacklight team for discovering the vulnerability, explained in greater depth here (http://securityresponse.symantec.com/avcenter/security/Content/2006.01.10.html). ®
Symantec security products less than secure (9 August 2007)
http://www.theregister.co.uk/2007/08/09/norton_security_bugs/
Symantec subscription glitch derails users (22 February 2007)
http://www.theregister.co.uk/2007/02/22/symantec_subscription_glitch/
Symantec coughs to security hole in its AV software (26 May 2006)
http://www.theregister.co.uk/2006/05/26/symantec_av_flaw/
Virtual rootkits create stealth risk (13 March 2006)
http://www.theregister.co.uk/2006/03/13/virtual_rootkit/
'Keylogger text' spooks Symantec (3 March 2006)
http://www.theregister.co.uk/2006/03/03/symantec_security_glitch/
Symantec shares slip on poor results (1 February 2006)
http://www.theregister.co.uk/2006/02/01/symantec_shares_slip/
Sony 'rootkit' settlement clamps down on DRM (29 December 2005)
http://www.theregister.co.uk/2005/12/29/sony_settles_rootkit/
Rootkits, cybercrime and OneCare (27 December 2005)
http://www.theregister.co.uk/2005/12/27/security_review_2005/
Hackers download pirate movies onto compromised PCs (21 December 2005)
http://www.channelregister.co.uk/2005/12/21/bittorrent_botnet_attack/
Hidden-code flaw in Windows renews worries over stealthy malware (31 August 2005)
http://www.theregister.co.uk/2005/08/31/spyware_writers_get_more_sophisticated/
Symantec anti-virus flaw hits 30 products (10 February 2005)
http://www.theregister.co.uk/2005/02/10/symantec_uberbug/
© Copyright 2008