Slashdot Mirror


Antivirus Software Could Make Your Company More Vulnerable (csoonline.com)

itwbennett writes: Since June, researchers have found and reported several dozen serious flaws in antivirus products from vendors such as Kaspersky Lab, ESET, Avast, AVG Technologies, Intel Security (formerly McAfee) and Malwarebytes. Many of those vulnerabilities would have allowed attackers to remotely execute malicious code on computers, to abuse the functionality of the antivirus products themselves, to gain higher privileges on compromised systems and even to defeat the anti-exploitation defenses of third-party applications. And evidence suggests that attacks against antivirus products are both possible and likely. Some researchers believe that such attacks have already occurred, even though antivirus vendors might not be aware of them because of the very small number of victims. Among the emails leaked last year from Italian surveillance firm Hacking Team there is a document with exploits offered for sale by an outfit called Vulnerabilities Brokerage International. The document lists various privilege escalation, information disclosure and detection bypassing exploits for multiple antivirus products, and also a remote code execution exploit for ESET NOD32 Antivirus with the status 'sold.'

5 of 74 comments (clear)

  1. cost and benifit by fermion · · Score: 4, Insightful

    I don't know if it is possible to have a MS Windows running on the internet without a anti virus software. So the question is not which AV software has vulnerabilities, as all software has this issue, but which provides significantly more protection than risk. Or if there is better way to protect MS Windows machines than AV software.

    --
    "She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
    1. Re:cost and benifit by gilgongo · · Score: 4, Insightful

      If it's any help (and if you're referring to desktop Windows computers behind standard domestic NAT-ed router/firewalls), then with the exception of WSE since it came out (WinVista?), I've *never* run anti-virus on any Windows installation in our 4-person home in over 20 years.

      About once a year I boot each machine from something like Trinity Rescue Disk and run a sweep using two or three different anti-virus packages. This might come up with perhaps one or two low-risk infections (usually Java), but that's it.

      I assume therefore that if the people using the machines are not in the habit of visiting certain types of website, and aren't inclines to open attachments they're not expecting, then all will be well.

      --
      "And the meaning of words; when they cease to function; when will it start worrying you?"
    2. Re:cost and benifit by DarkOx · · Score: 3, Insightful

      Yes its possible if you don't do stupid things and don't foul up Windows security. the vast majority of liabilities/vulnerabilities on modern Windows desktops arise directly from PBCAK (Person between chair and keyboard). I personally use a mixture of Slackware and OSX at home but I do security work and I can tell you if you are following the rules below on Windows 8 and later its very unlikely anyone is going to pop your box.

      [Stuff that comes out of box if you don't f**k it up]
      0) Have a strong password.
      1)Leave UAC enabled.
      2)Leave the windows firewall on and with recommended settings, even if you are behind NAT and or some other hardware firewall.
      3)Install updates promptly.
      4)Don't run things from sources you don't trust.
      4a) If you really must run stuff from untrusted sources have a separate user account to download and execute that stuff with that you do not use to handle any information you don't want public, and for goodness sake don't let it elevate.
      5) Do not install Flash
      6) Do not install the Java browser plugins.

      [Mostly painless things you can do to really harden windows boxen]
      7) Install EMET
      8) Install KB2871997 and disable wdigest

      [annoying but still a good practice]
      9) logoff (not just lock) your desktop when not in use. Optionally suspend or hibernate the system, instead.

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
  2. Re:Not quite AV, but close by ls671 · · Score: 4, Insightful

    Every piece of software is a potential security hole. AVs, firewalls, encryption layers like SSL or what not constitute no exceptions.

    --
    Everything I write is lies, read between the lines.
  3. Re:Not quite AV, but close by Bert64 · · Score: 3, Insightful

    Exactly, which is why things should be kept simple - the less code you have running the less you have to keep track of.

    --
    http://spamdecoy.net - free throwaway anonymous email - avoid spam!