NEWS A hole in Symantec's Norton Anti-Virus software has been exposed by the dangerous SirCam worm, which has been able to pass through companies' email gateways undetected. The problem, caused by a morphing of the malicious email's header text, is also thought to affect other anti-virus products, including Baltimore Technologies' MAILsweeper. A spokeswoman for Symantec said: "There is a problem with catching the virus at the email gateway. We are aware that other vendors are having problems too. "A problem of this kind is very rare. Once every six months or so a new virus comes along which re-writes the rules and causes real trouble. This seems to be doing this." She stressed that the worm should still be picked up by Symantec's server and desktop anti-virus software, and urged users to update. The difficulty is caused by the worm's ability to control the header (hidden text which describes an email to the computer) which contains it. The morphed email header fools the gateway scanner into thinking the email contains no attachment. Baltimore Technologies said: "Certain messaging characteristics generated during the creation of the worm by its own SMTP routines, may pass through [current] detection mechanisms." The company has issued an update to fix the hole in its MAILsweeper product, available at http://www.mimesweeper.com/support/threatlab/threatinfo/W32SirCamDetection.asp. Symantec's spokeswoman was unable to say at time of publishing whether the firm had issued a patch. However, not all vendors have fallen victim to this new trait. Network Associates - which sells McAfee - claims to be immune, as does Sophos. Graham Cluley, senior technology consultant at Sophos, said: "This new threat just underlines why it is so important not to just rely on gateway anti-virus, but keep your desktop software up-to-date as well."
Virus shields 'useless' against SirCam
"Once every six months or so a new virus comes along which re-writes the rules and causes real trouble..."
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Keeping flash drives secure with biometric authentication
People and organisations hand over their most valuable and vital personal information to government agencies. It is...
-
Detection systems guard against network intrusion
How do the different types of intrusion prevention system (IPS) work? Inline systems sit on the network like layer-two...
-
How malware threats have changed
These days, cybercriminals have four core weapons: targeted attacks, infecting websites, social networking and mobile...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




