Attackers seek vulnerable Veritas Backup installations
Users urged to apply patch
June 30, 2005 12:00 PM ETIDG News Service -
Attackers are already exploiting security flaws reported by Veritas Software Corp. last week in its remote backup agent to take control of computers running the software, according to the U.S. Computer Emergency Readiness Team (US-CERT).
US-CERT urged users of the software, Veritas Backup Exec Remote Agent for Windows Servers, to apply a security patch issued by Veritas.
The software is used to remotely trigger backup of data on servers. It listens for commands addressed to it on TCP Port 10,000, but there is a flaw in the way it authenticates those commands. If attackers send an overlong password, the software may crash, and if the overlong password is formed in a particular way, the computer can be forced to execute code of the attackers' choice with the privileges of the local system, allowing them to take control of the computer.
Veritas notified customers of the danger on June 22 and immediately issued a patch for affected versions of the software. It said it had been notified of the flaw by security consultancy iDefense Inc.
In the days since Veritas revealed the danger, US-CERT has seen an increase in the number of computers scanning TCP Port 10,000, which it believes are attempts to locate vulnerable systems, it said yesterday. Code to exploit the flaw is publicly available, it said, and it has received credible reports that this code is being used to take control of systems.
US-CERT urged companies running the affected software to immediately apply patches issued by Veritas, or to use a firewall to filter traffic arriving on Port 10,000 so as only to accept commands from backup servers.
Reprinted with permission from
Story copyright 2009 International Data Group. All rights reserved.
Viruses
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
The State of PCI DSS Compliance at Organizations Today
Download this resource today!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Why Email Must Operate 24/7 and How to Make This Happen
Learn how to avoid an email outage by implementing a hosted email continuity solution.
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Eradicate Spam & Gain 100% Asurance of Clean Mailboxes
Get this paper now!
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Mastering eDiscovery: The IT Manager's Guide to Preservation, Protection & Production
Get this paper now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
