Slashdot Mirror


Google Security Engineer Issues Sophos Warning

angry tapir writes "Google security engineer Tavis Ormandy discovered several flaws in Sophos antivirus and says the product should be kept away from high value information systems unless the company can avoid easy mistakes and issue patches faster. Ormandy has released a scathing 30-page analysis (PDF) 'Sophail: Applied attacks against Sophos Antivirus,' in which he details several flaws 'caused by poor development practices and coding standards,' topped off by the company's sluggishly response to the warning he had working exploits for those flaws. One of the exploits Ormandy details is for a flaw in Sophos' on-access scanner, which could be used to unleash a worm on a network simply by targeting a company receiving an attack email via Outlook. Although the example he provided was on a Mac, the 'wormable, pre-authentication, zero-interaction, remote root' affected all platforms running Sophos. (Ormandy released the paper as an independent researcher, not in his role as a Google employee.)"

4 of 89 comments (clear)

  1. MS Security Essentials on a Mac? by dclozier · · Score: 4, Funny

    I don't think there's an app for that. ;)

  2. Re:Official Sophos Response. by Anonymous Coward · · Score: 2, Funny

    Best practice
    Sophos customers are reminded of the following best practice:

    0. Uninstall Sophos

  3. Re:release the lawyers! by Anonymous Coward · · Score: 2, Funny

    Again with the $10,000 bets! Mitt, shouldn't you be focused on the election right now?

  4. Re:Can someone explain by cbhacking · · Score: 4, Funny

    I could email you a PDF to install that replacement for you...

    No, not a PDF on *how* to install it, one that *would* do so (or rather, cause Sophos to do so) as soon as it entered your email server! :-)

    --
    There's no place I could be, since I've found Serenity...