Big Data. Big Decisions
InformationWeek
Special Coverage Series


Symantec pcAnywhere Remote Attack Code Surfaces

Researchers warn that even fully patched pcAnywhere is vulnerable to newly revealed exploits.

Anonymous: 10 Facts About The Hacktivist Group
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
Code has been published that attackers could use to crash fully patched versions of pcAnywhere on any Windows PC, without first having to authenticate to the PC.

The exploit details arrived Friday in the form of a Pastebin post from Johnathan Norman, director of security research at Alert Logic. Advertised as a "PCAnywhere Nuke," the Python code can be used to create a denial of service (DoS) by crashing "the ashost32 service," he said in the post. "It'll be respawned so if you want to be a real pain you'll need to loop this...my initial impressions are that controlling execution will be a pain." He said the exploit works even against the most recent, fully patched version of pcAnywhere (version 12.5.0 build 463 and earlier).

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

"Symantec is aware of the posting and is investigating the claims," said Symantec spokeswoman Katherine James via email. "We have no additional information to provide at this time."

Symantec last month recommended that users disable pcAnywhere unless absolutely required, until the company had an opportunity to release a patch (which it did last month) to address a critical vulnerability that would allow attackers to remotely execute arbitrary code on a user's PC. That vulnerability was discovered by Edward Torkington at NGS Secure, who said he was withholding full details of the bug until April 25, 2012, to give people time to patch their pcAnywhere installations.

[ Learn 10 Strategies To Fight Anonymous DDoS Attacks. ]

Torkington's bug, however, apparently isn't the only vulnerability that researchers have recently unearthed. "I've been working on the remote preauth PCAnywhere vulnerability reported a few weeks ago and stumbled on a few other flaws during my research," Norman said on his blog. "Not sure what I'm going to do with all of them."

Concerns have been mounting over the security of the remote-access tool pcAnywhere since Symantec confirmed that the source code for the application had been stolen in 2006. But Symantec realized that the theft had occurred only after the hacking group Lords of Dharmaraja last month released what they said was a snippet of source code from Symantec's Norton Utilities to Pastebin.

Since then, officials at Symantec said the hackers had attempted to extort the company, offering to not release the source code in exchange for $50,000. After Symantec refused to pay, the hackers shared the source code with Anonymous, which promptly released it via BitTorrent.

The worry is that with the source code now widely available, attackers could potentially identify zero-day attacks that would allow them to take control of pcAnywhere, thus gaining direct access to a PC.

Notably, Norman's research was conducted without using the leaked source code. "If I had the source code, I could potentially get into legal trouble with Symantec," he said via email. But thanks to the leak, "it is now effectively open source, which will likely result in many other vulnerabilities being released soon...by guys like me."

Those worries intensified Friday, after an anonymous review of the pcAnywhere source code appeared on the Infosec Institute's website, detailing that much of code base, at least as of version 12.0.2, dated from 2002. In addition, it said, the leaked code includes full source code for Symantec's LiveUpdate on Windows, Macintosh, and Linux.

According to the review, the source code that leaked in 2006 also included source code and documentation for pcAnywhere versions 9.2 through 12.0.2, and the code was "heavily commented with dates for all changes." According to those date stamps, "a surprising amount of the core code originates from what is now 10 years ago with only a few added changes, mainly to accommodate changes in Windows versions."

Still, having a largely extant base isn't surprising, according to the review. "This makes sense considering the huge expense and undertaking of periodically re-writing an existing product, especially when Windows strives so hard to keep backwards compatibility and does not warrant big changes to be made of the developer."

But the release of the source code is a cause for concern. "For hackers, the sky is the limit as hackers now have all of the juicy details of the pcAnywhere product as well as accompanying source code for all related components. pcAnywhere is now pcEverywhere," according to the review. "We now know how their LiveUpdate system works thanks to the included architecture plans and full source code, which is also used to update Symantec's current antivirus products.

"The only hope for Symantec and pcAnywhere is that these days users typically do not run their home or office computers with the ports required for this product open to the Internet," according to the review. "So attacks for this particular product across the Internet are minimal. However, hackers always seem to find a way."

To protect company and customer data, we need to determine what makes it so vulnerable and appealing. We also need to understand how hackers operate, and what tools and processes they rely on. In our How (And Why) Attackers Choose Their Targets report, we explain how to ensure the best defense by thinking like an attacker and identifying the weakest link in your own corporate data chain. (Free registration required.)



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.