Anonymous claims to have released source code of Symantec's pcAnywhere
The hacker group had earlier released emails between a hacker and a person said to be a Symantec representative
Symantec could not immediately comment on whether the hackers had indeed released the source code of its product. "It happened so recently that we're still in the process of analyzing and won't be able to confirm until the morning," a spokesman said via email.
Earlier on Monday, an email string posted on Pastebin referred to negotiations over payment for the source code between one Sam Thomas, purported to be a Symantec employee, but using a Gmail mail id, and a person named Yamatough. The name of the hacker is similar to the Twitter handle of YamaTough in Mumbai who is associated with the hacker group, Lords of Dharmaraja, that had earlier claimed it had access to the source code of some Symantec products.
"We will pay you $50,000.00 USD total," Thomas said in an e-mail earlier this month. He however wanted assurances that the hacker would not release the code after payment, and offered to pay $2,500 a month for the first three months, with payments starting the next week.
"After the first three months you have to convince us you have destroyed the code before we pay the balance. We are trusting you to keep your end of the bargain," he added.
Yamatough rejected the offer stating that "our offshore people wont let us securely get the money because they wont process amounts less than 50k a shot".
By late Monday, Yamatough gave Symantec 10 minutes to decide which way it would go. "After that two of your codes fly to the moon PCAnywhere and Norton Antivirus totaling 2350MB in size (rar)," the hacker said. "We can't make a decision in ten minutes. A We need more time," Thomas replied. A
Symantec said the offer of $50,000 to the hacker was part of a law enforcement investigation.
The company did not however disclose the name of the investigative agency. "Given that the investigation is still ongoing, we are not going to disclose the law enforcement agencies involved and have no additional information to provide," the company said in a statement.
Symantec said that in January an individual claiming to be part of Anonymous attempted to extort a payment from Symantec in exchange for not publicly posting stolen Symantec source code they claimed to have in their possession. "Symantec conducted an internal investigation into this incident and also contacted law enforcement given the attempted extortion and apparent theft of intellectual property," it added.
Symantec admitted in January that its network was compromised and source code stolen, according to reports, backing away from earlier claims that a third party had been attacked.
- Silicon Valley's 19 Coolest Places to Work
- Is Windows 8 Development Worth the Trouble?
- 8 Books Every IT Leader Should Read This Year
- 10 Hot Hadoop Startups to Watch
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- Radicati: Cloud Business Email - Market Quadrant 2013 Google was named the top cloud business email provider in a recent report by research firm Radicati. Out of 14 key players, Google...
- Tablets in the Enterprise: A Checklist for Successful Deployment How can you enterprise manage and secure tablets in order to protect corporate data while providing access to the information and applications employees...
- Enterprise Mobility: A Checklist for Secure Containerization The advantages and disadvantages of the multiple approaches to containerization. Learn More>>
- Enterprise File Sync & Share Checklist File sync and share has changed the way people work and collaborate in today's tech-savvy world. Gone are the email roadblocks, clunky FTP...
- Live Webcast LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- LIVE EVENT: 5/7, The End of Data Protection As We Know It. Introducing a Next Generation Data Protection Architecture. Traditional backup is going away, but where does this leave end-users?
- On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy... All Security White Papers | Webcasts