论文部分内容阅读
全球第一大安全软件厂商Symantec公司的软件素有盛誉,其客户包括世界上最大的公司、美国政府机构,以及无数的普通消费者。但是,位于美国加州的一家信息安全公司eEye Digital Security发现了Symantec公司的拳头产口诺顿杀毒软件中的一个漏洞,这个漏洞可以让黑客获得系统控制权、盗取机密数据、删除文件甚至肆意安装间谍软件。eEye在其网站上发布了一个该漏洞的简要消息,并没有透露更多如何利用漏洞的细节,以免信息太详细被黑客所利用。但eEye公司向Syniantec公司和本公司的一些大客户提供了比较详细的漏洞情况。cEye的“首席黑客”Marc Maiffret还向美联社记者当场演示了如何利用该漏洞进行攻击。eEye公司的演示表明,这个漏洞发生在诺顿第十版的杀毒软件中,包括其企业版。Symantec公司的另外一个囊括杀毒和防火墙软件的产品包则没有显现这个漏洞。据统计,全球约有2亿台企业和个人电脑安有Symantec的杀毒软件,仅在美国企业的使用率就高达60%。分析认识,一旦漏洞被证实,这对众多诺顿杀毒软件用户来说将是一种极为严重的威胁,因为利用这个漏
The world’s largest security software vendor Symantec has a reputation for software that includes the largest corporations in the world, U.S. government agencies, and countless average consumers. However, eEye Digital Security, a California-based information security company, found a flaw in Norton antivirus software at Symantec Corp., a fablet that could give hackers system controls, steal confidential data, delete files and spy on spies software. eEye posted a brief message on its website about the vulnerability and did not reveal more details on how to exploit the vulnerability to prevent it being used in too much detail by hackers. However, eEye provided more detailed vulnerabilities to Syniantec and some of its larger clients. cEye’s “Chief Hacker” Marc Maiffret also told AP reporters on the spot how to exploit the vulnerability. The demonstration by eEye shows that the vulnerability occurred in Norton’s tenth edition of antivirus software, including its Enterprise Edition. The other Symantec product suite that includes anti-virus and firewall software does not show this vulnerability. According to statistics, there are about 200 million enterprises and PCs in the world with Symantec anti-virus software, which is only up to 60% of the U.S. businesses. Analysis, once the loopholes confirmed, which for many Norton anti-virus software users will be a very serious threat, because the use of this leak