Symantec: Anonymous stole source code, users should disable pcAnywhere
arstechnica.com
arstechnica.com
> Symantec released a patch fixing three vulnerabilities
> in pcAnywhere version 12.5 (the current version) on
> Monday, and said it will continue issuing patches
> "until a new version of pcAnywhere that addresses all
> currently known vulnerabilities is released."
Sounds like they've been sitting on a bunch known vulnerabilities. At least this acts as a kick in the pants to actually fix them.The security professionals who do this for a living, and study this should disclose fully, but a corporate entity will never. They cannot because of shareholders, and there are way to many bugs out there and it would be embarrassing cleaning up that much crap.
Security vulnerabilities are sometimes architectural problems, some are related to ignorance, but a LOT more are just stupid bugs and people not writing code that is correct. A good attacker doesn't care how they get in, there is always a way.
It's a losing battle, just ask EWD.
http://www.cs.utexas.edu/~EWD/transcriptions/EWD03xx/EWD340....
\\ Edit: Words are tough.
So somebody stole the source code five years ago and they're starting to fix some of the glaring vulnerabilities today because this somehow got in the news?
That's reason enough to stay away from all network-enabled Symantec products, I would expect them to be equally insecure if this is the way they do things.
EDIT: Never mind.. it did.. wow.. well supposedly nothing was released publicly until just now though. Someone was just sitting on it. Ex-employee?
Even if the code was never stolen at all, this to me is at very least a shocking lack of due diligence and at worst completely and utterly unprofessional ignorance of the importance of security (to the point where if I'd paid for that particular software in the last X years I'd be considering action to get a refund on the basis that the software was not fit for purpose).
It was primarily design for scanning email attachments, but the client is OK for usage on your desktop. Also, it only detects threats but doesn't clean the infected files - which is OK, because you shouldn't trust AV software to clean your files. Once your computer is compromised, you're better off formatting your hard-drive and reinstalling everything from scratch (which is why it's always a good idea to have periodic backups of your work).
When someone is proud of their work, they like to show it off, and this is true of programmers as well. If I make a neat program, and I'm really proud of the job I did writing it, I want to show that off by showing people the source code -- thus increasing my epenis/karma/reputation points etc. Conversely, if I presided over a software product that I knew had bugs and I needed to release said product regardless, I would have to keep the source code tucked away so that nobody could tell how bad said product is.
Second paragraph, way off base. Reasons for keeping source code private are far more likely to be based on a business plan, not on coders being embarassed about their work.
That means you're looking in the wrong place. You don't want Remote Desktop. On Windows XP you want Remote Assistance, and from Windows Vista you want Windows Desktop Sharing. Same underlying protocol, but different semantics -- the session stays open on both ends.