All the latest UK technology news, reviews and analysis

Antivirus admin tools open to abuse

by John Leyden

18 Apr 2000

Be the first to comment

  • Tweet this

Management tools used to streamline antivirus software updates can pose a security risk, a security testing company has warned.

NTA Monitor's warning came after Trend Micro instructed users to update from version 3.5.0 to 3.5.1 of its OfficeScan suite because of major security issues with its server-based management system.

Roy Hills, NTA Monitor's testing development director, said security issues involving the management functions of corporate virus checkers have become "a real threat".

Users reported two flaws in OfficeScan 3.5.0. The first was that system administration tasks were not protected by log-in mechanisms and could be performed by anyone who knew the URL of the admin web pages. The second leaves desktop PCs running OfficeScan vulnerable to denial of service attacks.

Dale de Kok, a member of Trend Micro's technical support team, admitted that there is a problem with web-based installations of OfficeScan on Windows NT servers, which has been fixed in version 3.5.1.

"Previous versions of OfficeScan would allow intruders within a firewall to initiate a denial of service attack on the OfficeScan client, as well as to capture OfficeScan commands," he said. "These commands could be replayed and used to change other OfficeScan client configurations."

The vulnerability has been fixed by encrypting server to client commands using MD-5 Message-Digest Algorithm, added de Kok.

"Problems with the management utilities of antivirus software suites are not a new risk, but they have suddenly become a real threat," said Roy Hills, adding that businesses need to review how they configure antivirus software suites.

He said it is common practice to implement software upgrades by mailing someone a .reg file, which is merged into users' registries. This could be an avenue for infection, he said, advising administrators to configure their antivirus or content checking software to block particular download types.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

31%

1%

12%

56%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Project Manager - Credit Risk - Finance IT - Investment Bank

Project Manager - Credit Risk - Finance IT - Investment...

Infrastructure Configuration Manager/Analyst/Data Modeler/IB

Infrastructure Configuration Manager/Analyst/Data Modeler...

Lead Perl Developer, Apache, SQL, Unix/Linux, INVESMENT BANK

Lead Perl Developer, Apache, SQL, Unix/Linux, Shell Scripting...

Perl Developer, Web and JEE App Servers, INVESTMENT BANK

**Perl /Java Developer, Web/ JEE application servers...

To send to more than one email address, simply separate each address with a comma.