Protecting your ID

You are here: silicon.com > Research > Special Reports > Protecting your ID

Protecting your ID

Norton Internet Security flaw lets in hackers

Oops

By Robert Lemos

Published: 22 March 2004 08:35 GMT

A software component of Norton Internet Security could allow hackers to use the application as a backdoor into a person's computer system, security researchers warned.

The flaw occurs in an ActiveX component used by security firm Symantec's flagship desktop security program, Norton Internet Security, according to an advisory published by research firm NGSSoftware. The security hole could be used to run an attack program that would then take control of the computer that the software was trying to protect.

"The attack can be achieved either by encouraging the victim to visit a malicious web page or placing a script within...an HTML email," the advisory stated.

Symantec's Antispam software has a similar issue caused by a different ActiveX component. ActiveX is a Microsoft technology for creating scripts, small programs that can add functionality to a computer or a website.

Symantec released fixes for the flaws that can be downloaded from its site, using LiveUpdate, the standard update mechanism included with the programs.

"To date, Symantec has not had any reports of any related exploits, and exploit code has not been posted, but we will continue to evaluate this issue," the company. "Symantec issued a fix on 18 March for customers to download via LiveUpdate."

Last December, Symantec fixed a problem that affected a small percentage of the more than 1.2 million users of the company's Norton Antivirus 2004, Norton Internet Security 2004, Norton Antispam 2004 and Norton SystemWorks 2004. For those customers, the applications would mistakenly ask for a product activation code every time a PC was rebooted, and eventually the program would become locked.

Robert Lemos writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure
Protecting your ID News

BT plans passport checks to slash ID fraud
But you'll still need to keep an eye on your bin...

'Witness intimidation' hampering fraud convictions
Courts and legal system are ill-prepared for hearing technical cases...

Zombies are after your ID
Bot nets are increasingly looking to steal valuable personal information...

SurfControl rides the spyware wave
But warns time is running out for anybody favouring "buy" rather than "build" as an entry strategy...

Bloggers become spyware spreaders
Unwitting accomplices...

RELATED RESEARCH

Make your voice heard

silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.

Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.

Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.

For more about the Research Panel and how to join, click here



Quick Sitemap Links: