<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
	xsi:schemaLocation="http://www.digitaltrends.com/xml/digitaltrends.xsd"
	>
<channel>
	<title>Comments on: Symantec Confirms Serious AV Security Flaw</title>
	<atom:link href="http://www.digitaltrends.com/computing/symantec-confirms-serious-av-security-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.digitaltrends.com/computing/symantec-confirms-serious-av-security-flaw/</link>
	<description>Digital Trends is your home for technology news, CE product reviews, mobile app reviews and daily videos.</description>
	<lastBuildDate>Fri, 17 Feb 2012 02:32:44 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: SUCKS to be you!</title>
		<link>http://www.digitaltrends.com/computing/symantec-confirms-serious-av-security-flaw/#comment-52311</link>
		<dc:creator>SUCKS to be you!</dc:creator>
		<pubDate>Sat, 18 Feb 2006 21:10:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitaltrends.com#comment-52311</guid>
		<description>you should&#039;a bought a MAC!  Then at least you&#039;d wouldn&#039;t have these issues!&lt;br /&gt;
&lt;br /&gt;
friends don&#039;t let friends use Windows..</description>
		<content:encoded><![CDATA[<p>you should&#039;a bought a MAC!  Then at least you&#039;d wouldn&#039;t have these issues!</p>
<p>friends don&#039;t let friends use Windows..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephen Neitzke</title>
		<link>http://www.digitaltrends.com/computing/symantec-confirms-serious-av-security-flaw/#comment-52310</link>
		<dc:creator>Stephen Neitzke</dc:creator>
		<pubDate>Sun, 25 Dec 2005 17:26:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.digitaltrends.com#comment-52310</guid>
		<description>You write:  &quot;To date, there are no known exploits of this bug.&quot;&lt;br /&gt;
&lt;br /&gt;
If .rar can be used on photographs of scantily-clad actresses and models (in my defense, cheesecake, not porno), then I&#039;ve probably got an &quot;exploit&quot; of this bug to talk about.&lt;br /&gt;
&lt;br /&gt;
On Tue 13 Dec 2005 -- late evening, end of my computer day -- I clicked on an Italian actress&#039; photo in Google Images.  Instantly, there were multiple blinks/resets of my browser window and a new toolbar appeared.  I immediately took my cable modem offline and ran a full scan with the Norton AV.  The toolbar disappeared.  (It was &quot;Adware.FastLook&quot;, sourced from two files, kthjt.dll and rdt.ini.  The Norton AV scanner deleted those and eleven Registry keys.)  The anti-spyware capabilities of NIS 2006 were why I&#039;d upgraded last October.  Satisfied, I shut down the computer for the night.&lt;br /&gt;
&lt;br /&gt;
On boot-up next morning, before taking the modem online, I had a hijacked browser (complete with DNS numbers for servers in the Amsterdam area, instead of my Tulsa ISP&#039;s numbers), a new spyware scanner (UnSpyPC -- complete with desktop shortcut icon), a stack of virus alerts for trojans and spyware, more new and hidden processes than I could keep track of, and Norton ripping out more Registry keys than I knew it was capable of.&lt;br /&gt;
&lt;br /&gt;
The search function and AV scanner was used continually.  It was clear from the beginning that the toolbar was only the first of a long line of concealed files and registry keys that somehow got past Norton&#039;s &quot;Auto Protect&quot; scanning of code coming into my machine from the Internet.  I was quickly angry that this package contained code for known, 2-5-year-old trojans.  This should be simple stuff to spot.&lt;br /&gt;
&lt;br /&gt;
I was unstudied and unprepared for this onslaught.  I didn&#039;t know the term, &quot;rootkit&quot;, until about Day 7.  I kept notes, but, in hindsight, frequently did not focus on important events.&lt;br /&gt;
 &lt;br /&gt;
However, I did start a process of using my Norton logs to trap remote IP numbers and malware exe file names.  Use of frequent reboots, short periods online, and Norton&#039;s &quot;block/allow traffic&quot; button all lit up the logs with malicious numbers and file names.&lt;br /&gt;
&lt;br /&gt;
I know the URL of the site that hit me with this rootkit payload.  I know 4 ranges of IP&#039;s to which the trojans attempted to deliver info from my machine -- two in the Amsterdam area and two in California.  (This hacker does not work alone.)  And I will blab all to anyone who&#039;s interested.&lt;br /&gt;
&lt;br /&gt;
The hacker did not ever have complete control of my machine, but it was a close call.  The margin, I think, was that I&#039;d locked the AV options with a strong password last October -- after setting all of those options for maximum capabilities.  It&#039;s clear that he did not breach the AV options password.&lt;br /&gt;
&lt;br /&gt;
The Norton AV software and I countered everything he vomitted out of the rootkit for the first six days.  On boot-up, Day 7, the machine went straight into Safe Mode.  It took me seven hours of flailing to find and correct the altered bullet list at Run &gt; &quot;msconfig /P&quot;.&lt;br /&gt;
&lt;br /&gt;
Exhausted (I&#039;m a 60-something disabled guy with many med problems), I napped and returned a few hours later.  The machine had been offline and traffic-blocked while I slept.  On return, there was a stack of ten virus alerts waiting for me -- all &quot;access denied&quot; -- detailing five different trojans and spyware packages.  Took notes and ran the AV scanner.  All ten rogue-code instances were snuffed.&lt;br /&gt;
&lt;br /&gt;
That was early evening, 19 Dec.  And it was the end of episode one.  There&#039;s been no further malware activity that I can detect.  The rootkit seems spent.&lt;br /&gt;
&lt;br /&gt;
I&#039;m sure the rootkit is still in there.  The OS has displayed continual instabilities since that last burst of activity on 19 Dec.  With WinXP Home, it&#039;s impossiblle for me to wipe the hard drive and reinstall.  I&#039;ll have to buy the pricey XP Pro upgrade to get that capability.&lt;br /&gt;
&lt;br /&gt;
&quot;Denial of service&quot; law has been violated and I want a hide to nail to the proverbial barn door.&lt;br /&gt;
&lt;br /&gt;
Symantec&#039;s failure to stop known rogue code at the threshold rankles me.&lt;br /&gt;
&lt;br /&gt;
Microsoft&#039;s failure to give even a modicum of protection to rogue code writing to their NT kernal is jaw-jacking.  Clearly, Microsoft is on the hacker&#039;s side, once the hacker is inside.&lt;br /&gt;
&lt;br /&gt;
Thanks to Microsoft&#039;s incompetence, I&#039;ve had no life but this battle for 12 days.  I figure it will be another two weeks of study and spyware tools deployment before I can feel somewhat comfortable with the defense -- and, even then, the jaundiced eye will be turned until one of the major AV producers gets off their butt and develops a multifaceted  counterattack for rootkits.&lt;br /&gt;
&lt;br /&gt;
Whoever does it well gets my money.  Symantec, having had brand loyalty from me for 4 years, is now out in the cold.  Discovering that they have mommy-coddled rootkit hackers because Sony wanted to use rootkits as an anti-piracy gimmick is still a flaming wound on the back of my neck. &lt;br /&gt;
&lt;br /&gt;
I&#039;m looking for somebody to sue for the price of the XP Pro upgrade that I figure to have to use many times over the coming year or so.  I have a very modest disability income.  It&#039;s a constant budget  fight between meds and food.  Giving Microsoft an incompetency reward of $200 will be a hardship deal in many ways..  &lt;br /&gt;
&lt;br /&gt;
Wound-licking aside, I have a strong sense that this experience was just the hacker sounding out the defense -- just playing, just kidding around, just seeing what&#039;s possible.  Other than the endemic instabilities caused by the rootkit&#039;s deep corruption of the OS, there was no machine damage done, no files harmed or exported.&lt;br /&gt;
&lt;br /&gt;
As the rootkit technology passes into meaner hands, I expect a lot of horror stories.  WinXP users should start now to relearn the Win3.x ways of wipe disk and reinstall.  The process takes planning, and it will be the only real removal tool that we&#039;ll have for a long while..&lt;br /&gt;
&lt;br /&gt;
The hacker learned a lot from me -- and I from him.  I think we&#039;re all in for a long run of rootkit dominance.&lt;br /&gt;
&lt;br /&gt;
 </description>
		<content:encoded><![CDATA[<p>You write:  &#8220;To date, there are no known exploits of this bug.&#8221;</p>
<p>If .rar can be used on photographs of scantily-clad actresses and models (in my defense, cheesecake, not porno), then I&#039;ve probably got an &#8220;exploit&#8221; of this bug to talk about.</p>
<p>On Tue 13 Dec 2005 &#8212; late evening, end of my computer day &#8212; I clicked on an Italian actress&#039; photo in Google Images.  Instantly, there were multiple blinks/resets of my browser window and a new toolbar appeared.  I immediately took my cable modem offline and ran a full scan with the Norton AV.  The toolbar disappeared.  (It was &#8220;Adware.FastLook&#8221;, sourced from two files, kthjt.dll and rdt.ini.  The Norton AV scanner deleted those and eleven Registry keys.)  The anti-spyware capabilities of NIS 2006 were why I&#039;d upgraded last October.  Satisfied, I shut down the computer for the night.</p>
<p>On boot-up next morning, before taking the modem online, I had a hijacked browser (complete with DNS numbers for servers in the Amsterdam area, instead of my Tulsa ISP&#039;s numbers), a new spyware scanner (UnSpyPC &#8212; complete with desktop shortcut icon), a stack of virus alerts for trojans and spyware, more new and hidden processes than I could keep track of, and Norton ripping out more Registry keys than I knew it was capable of.</p>
<p>The search function and AV scanner was used continually.  It was clear from the beginning that the toolbar was only the first of a long line of concealed files and registry keys that somehow got past Norton&#039;s &#8220;Auto Protect&#8221; scanning of code coming into my machine from the Internet.  I was quickly angry that this package contained code for known, 2-5-year-old trojans.  This should be simple stuff to spot.</p>
<p>I was unstudied and unprepared for this onslaught.  I didn&#039;t know the term, &#8220;rootkit&#8221;, until about Day 7.  I kept notes, but, in hindsight, frequently did not focus on important events.</p>
<p>However, I did start a process of using my Norton logs to trap remote IP numbers and malware exe file names.  Use of frequent reboots, short periods online, and Norton&#039;s &#8220;block/allow traffic&#8221; button all lit up the logs with malicious numbers and file names.</p>
<p>I know the URL of the site that hit me with this rootkit payload.  I know 4 ranges of IP&#039;s to which the trojans attempted to deliver info from my machine &#8212; two in the Amsterdam area and two in California.  (This hacker does not work alone.)  And I will blab all to anyone who&#039;s interested.</p>
<p>The hacker did not ever have complete control of my machine, but it was a close call.  The margin, I think, was that I&#039;d locked the AV options with a strong password last October &#8212; after setting all of those options for maximum capabilities.  It&#039;s clear that he did not breach the AV options password.</p>
<p>The Norton AV software and I countered everything he vomitted out of the rootkit for the first six days.  On boot-up, Day 7, the machine went straight into Safe Mode.  It took me seven hours of flailing to find and correct the altered bullet list at Run > &#8220;msconfig /P&#8221;.</p>
<p>Exhausted (I&#039;m a 60-something disabled guy with many med problems), I napped and returned a few hours later.  The machine had been offline and traffic-blocked while I slept.  On return, there was a stack of ten virus alerts waiting for me &#8212; all &#8220;access denied&#8221; &#8212; detailing five different trojans and spyware packages.  Took notes and ran the AV scanner.  All ten rogue-code instances were snuffed.</p>
<p>That was early evening, 19 Dec.  And it was the end of episode one.  There&#039;s been no further malware activity that I can detect.  The rootkit seems spent.</p>
<p>I&#039;m sure the rootkit is still in there.  The OS has displayed continual instabilities since that last burst of activity on 19 Dec.  With WinXP Home, it&#039;s impossiblle for me to wipe the hard drive and reinstall.  I&#039;ll have to buy the pricey XP Pro upgrade to get that capability.</p>
<p>&#8220;Denial of service&#8221; law has been violated and I want a hide to nail to the proverbial barn door.</p>
<p>Symantec&#039;s failure to stop known rogue code at the threshold rankles me.</p>
<p>Microsoft&#039;s failure to give even a modicum of protection to rogue code writing to their NT kernal is jaw-jacking.  Clearly, Microsoft is on the hacker&#039;s side, once the hacker is inside.</p>
<p>Thanks to Microsoft&#039;s incompetence, I&#039;ve had no life but this battle for 12 days.  I figure it will be another two weeks of study and spyware tools deployment before I can feel somewhat comfortable with the defense &#8212; and, even then, the jaundiced eye will be turned until one of the major AV producers gets off their butt and develops a multifaceted  counterattack for rootkits.</p>
<p>Whoever does it well gets my money.  Symantec, having had brand loyalty from me for 4 years, is now out in the cold.  Discovering that they have mommy-coddled rootkit hackers because Sony wanted to use rootkits as an anti-piracy gimmick is still a flaming wound on the back of my neck. </p>
<p>I&#039;m looking for somebody to sue for the price of the XP Pro upgrade that I figure to have to use many times over the coming year or so.  I have a very modest disability income.  It&#039;s a constant budget  fight between meds and food.  Giving Microsoft an incompetency reward of $200 will be a hardship deal in many ways..  </p>
<p>Wound-licking aside, I have a strong sense that this experience was just the hacker sounding out the defense &#8212; just playing, just kidding around, just seeing what&#039;s possible.  Other than the endemic instabilities caused by the rootkit&#039;s deep corruption of the OS, there was no machine damage done, no files harmed or exported.</p>
<p>As the rootkit technology passes into meaner hands, I expect a lot of horror stories.  WinXP users should start now to relearn the Win3.x ways of wipe disk and reinstall.  The process takes planning, and it will be the only real removal tool that we&#039;ll have for a long while..</p>
<p>The hacker learned a lot from me &#8212; and I from him.  I think we&#039;re all in for a long run of rootkit dominance.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Content Delivery Network via cdn.digitaltrends.com

Served from: www.digitaltrends.com @ 2012-02-16 19:12:43 -->
