Most Popular Stories
- A 'mobile help desk' in every pocket, from Salesforce.com
- How hackers can eavesdrop on prevalent videoconferencing systems
- Survey finds many users blow by SharePoint security
- Risk certification answers a clear demand
- What happens when the CIO is also the CFO
- Researchers expose security holes in SCADA systems
Events
- BlackBerry World – Register Now & Save!
May 1-3, 2012 — Orlando, FL - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA - MDSL Telecom Expense Management Roadshow
Feb 21–23, 2012 — New York, Houston, Chicago - Northwestern University Master's in Information Systems
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Whitepaper: Mobile Device Management Buyer's Guide: An Insider's View of the Market
- 5 Ways to Reduce Enterprise Mobililty Costs with Wireless Telecom Expense Management
- IMPROVING THE MANAGEMENT OF FEDERAL GOVERNMENT IT ASSETS THROUGH BETTER COMMUNICATION WITH THE IT INDUSTRY
- The E-discovery Toolbox: What you should look for in a unified e-discovery solution
- Ringing in Growth - How Service Bureau-based Outsourcing is a Win-Win Approach for Communications Service Providers
Symantec warns against use of pcAnywhere in wake of code theft
Symantec has issued a warning to its customers to disable pcAnywhere remote access software after verifying that the source code was indeed stolen in a 2006 breach. A group of hackers identifying itself as the "Lords of Dharmaraja" have claimed credit for this as well as for stealing the source code of two other Symantec security applications. According to various reports, the source code is currently being distributed to hackers hunting for zero-day vulnerabilities to exploit.
Speaking to Wired, Symantec spokesman Cris Paden admitted that the company had not previously known that the source code for pcAnywhere had been stolen. "We knew there was an incident in 2006...But it was inconclusive at the time as to whether or not actual code was taken or that someone had actual code in their hands." Recent reports led the company to examine six-year-old server logs and conclude that a source code theft had indeed occurred.
For now, Symantec has released a white paper (.pdf) outlining its recommendations and possible remediation steps that businesses can take. In it, Symantec conceded that pcAnywhere customers have "increased risk" due to an "increased ability to identify vulnerabilities and build new exploits." In the white paper, Symantec recommended that users disable pcAnywhere until the release of a final set of software updates that "resolve currently known vulnerability risks."
The radical suggestion by the security giant to disable pcAnywhere suggests that Symantec is aware of security vulnerabilities which the company has dithered in patching--a fact that does not bode well for its reputation. The greater damage however is probably in its active customer base, which likely chose pcAnywhere over other free or commercial remote access software for the perceived security offered by the Symantec-branded software.
So far, Symantec released a patch on Monday that eliminates three known vulnerability in pcAnywhere 12.5 on Windows, according to a report on TechNewsWorld. Customers are also advised to upgrade to pcAnywhere 12.5 and make use of endpoint protection.
For more:
- check out this article at CRN
- check out this article at TechNewsWorld
- check out this article at Wired
Related Articles:
Symantec source code stolen; company plays down theft
Symantec buys LiveOffice cloud storage vendor
March hack the result of RSA security lapse, says researcher
Related Stories
- Symantec drops warning against use of pcAnywhere, but questions remain
- Symantec source code stolen; company plays down theft
- Texas water plant hacker: Password was just 3 characters
- DigiNotar hacker claims he can issue fake Windows updates
- Hackers seek bragging rights on RankMyHack
- Bug in Trendnet webcams exposes them to public viewing
- Microsoft's Patch Tuesday for February has 9 security bulletins
- Chrome 17's new features enhance speed, security
- Hackers tried to extort $50K from Symantec over source code
- Adobe: Focus on defenses, not bug hunting
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceCRO | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2012 FierceMarkets. All rights reserved. |
![]() |




