'Keylogger text' spooks Symantec
Boo to a (Norton) ghost
Posted in Security, 3rd March 2006 13:50 GMT
Free whitepaper – Vulnerability management buyer's checklist
Script kiddies have latched onto a minor glitch in Symantec security software to boot users off Internet Relay Chat (IRC) channels. Typing “startkeylogger” or “stopkeylogger” in an IRC channel results in the involuntary logoff of users of Norton Firewall and Norton Internet Security suites, The Washington Post reports.
The commands mimic those used by the infamous Spybot worm, a botnet client with multiple variants, some of which spread over IRC and peer-to-peer file-swapping networks, that installs a backdoor onto compromised systems. Symantec’s software doesn’t recognise the context of the commands and therefore takes fright, exiting IRC channels with the response “Read error: Connection reset by peer” whenever the dreaded Spybot-style phrases are uttered. A number of IRC channels have reportedly started filtering out the phrase.
Symantec said it would fix the bug, which is best described as a “minor quirk”. IRC channels are full of pranksters and mischief makers who’ve undoubtedly had some fun with the Symantec glitch, even though it’s unlikely to have affected more than a handful of people. ®
Free whitepaper – Avoiding 7 common mistakes of IT security compliance

Analyst Keynote: The Register Agile Data Center Summit
Analyst Keynote: The Register Agile Data Center Summit
Enabling the Agile Data Center
Breaching Fort Apache.org - What went wrong?
Snow Leopard security - The good, the bad and the missing
US Dems fill inboxes with 419 scams
BlockMaster SafeStick hardware-encrypted USB drive