Welcome | Sign In
TechNewsWorld.com
Security

Veritas Security Flaw Attacked

Print Version
E-Mail Article
Reprints
Veritas Security Flaw Attacked

"It is extremely difficult for enterprises to keep ahead of a vulnerability like this, particularly when the timeframe to deploy the patch is so small as it was with this vulnerability," Ed Moyle, president, SecurityCurve, told TechNewsWorld.


The National Cyber Alert System warned yesterday of active exploits of a security flaw in Veritas Backup Exec Software. The system is part of the U.S. Homeland Security's Computer Emergency Readiness Team (U.S.-CERT). The alert said a buffer overflow could allow hackers to take over a computer and remotely execute malicious code.

"The vulnerability discovered in the Veritas remote agent is a significant one, as it allows an attacker to remotely execute code on a target machine running the backup agent," Ed Moyle, president, SecurityCurve, told TechNewsWorld. "One mitigating factor is that Veritas is enterprise software and most corporate firewalls block port 10000 (the port used by the backup agent) from outside their network, which helps to prevent attacks from impacting corporate entities."

Flaw Found in March

The flaw in the software, used to trigger back ups of data files on Windows servers in case of computer crashes or other problems, was first discovered in March by security firm iDefense.

Veritas has issued patches for the vulnerability, which the company and iDefense announced last week.

U.S.-CERT said in the warning that the exploit code is publicly available and that it has seen a spike in attack attempts, a situation Moyle said was to be expected.

"In most cases, once a vulnerability is published, exploit code, software that attacks the vulnerability, is published as well," he said. Once exploit code does become available, the frequency of active attack spikes for a period of time after the publication, as it is very easy for attackers to gain access to the exploit and use it to break into machines."

Delay in Installing Patches

The patches will take care of the problem, but they are not always promptly installed.

"It is extremely difficult for enterprises to keep ahead of a vulnerability like this, particularly when the timeframe to deploy the patch is so small as it was with this vulnerability," Moyle said.

"In this case, the patch for this flaw became available on the 22nd and exploit code was available on the 24th. Most IT departments understand the need to install patches quickly, but I think that in this case, the small window of time between when the patch was released and when exploit code was available made this incident a particularly difficult one for enterprises to address."


Print Version E-Mail Article Reprints More by Susan B. Shor


Related News Alerts

IDefense Activate Alert | Search Archives

More by Susan B. Shor

Salesnet President Jonathan Tang Ready to Take On Salesforce.com
February 07, 2006
"We think it's Salesnet's time now. We've been around since the beginning, we've been lying low, but you're going to start to see more of us. We've done it through organic growth and happy customers. We continue to focus on customers."
Comcast Follows Time Warner in Offering 'Family' Programming Tier
December 23, 2005
"The demand for this type of tier is coming from the FCC and Christian conservatives. It has nothing to do with legitimate consumer demand," Todd Chanko, senior analyst at Jupiter Media, told the E-Commerce Times.
High-Risk Flaw Found in Symantec's Software
December 22, 2005
"Part of the significance of this vulnerability announcement is that your machine can be exploited without you needing to do anything at all. You don't even have to open an e-mail or attachment, and this happens with the default configuration of the product," said Forrester Research senior analyst Michael Gavin.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network