Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Latest News
    • Blogs
    • Security Watch

    Hackers’ Threat to Publish Symantec Source Code Not a Reason to Worry

    Written by

    Fahmida Y. Rashid
    Published January 6, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      A group of hackers has claimed that it has stolen the source code to Symantec’s flagship antivirus product, according to a Pastebin post.

      This may just be an antivirus company’s worst nightmare come true.

      The group, named Lords of Dharmaraja, claimed to have breached an Indian military server and stolen several documents and files, according to the post, which appeared on the text-sharing site on Jan. 5. Pastebin has since removed the page, but a copy is still available on Google Cache.

      To prove their claims, the group posted excerpts of various documents they’d obtained, including an internal document from April 1999 that discussed the application programming interface for the company’s Definition Generation Service.

      “As of now we start sharing with all our brothers and followers information from the Indian military intelligence servers,” according to the post. The group has discovered “source codes of a dozen software companies,” they added.

      The leaked document merely explains how the software is designed to work, such as what inputs are accepted and what outputs are generated, Cris Paden, senior manager of corporate communications at Symantec, told eWEEK. While the document contains function names, no actual source code was present in that document, according to Paden.

      The fact that the hackers claimed to have discovered source code for several types of software on the breached military server is not a surprise, as many governments require companies to supply source code to prove it isn’t spyware, Rob Rachwald, director of security strategy at Imperva, told eWEEK. He said it wasn’t unusual, especially when working with the military.

      The group breaching military servers should be of bigger concern than the possibility of leaked source code, Stephen Cobb, a security evangelist for ESET, told eWEEK. A security breach on such sensitive servers could “prove harmful to cooperation between public and private sectors,” Cobb said.

      Lords of Dharmaraja promised to post actual source code for Norton Antivirus online once they lined up some mirror sites. “We are working out mirrors as of now since we experience extreme pressure and censorship from US and India government agencies,” the group wrote.

      Symantec is still investigating the incident, according to Paden. “As for the second claim of additional code, we cannot confirm or deny those claims as we are still analyzing the information,” Paden said.

      While it “clearly is undesirable” for any antivirus vendor or software vendor to have their source code made public, it does not necessarily mean the protection the software provides has been compromised, Chester Wisniewski, a senior security adviser at Sophos, told eWEEK. It could provide attackers with the knowledge needed to exploit undiscovered or unpatched vulnerabilities, but shouldn’t provide “any miracle insights” needed to defeat the product, according to Wisniewski.

      Imperva’s Rachwald also noted that the only people to benefit from looking at the source code are likely to be Symantec competitors who would be able to look at how the company built its antivirus engine. There isn’t “much” malware writers can learn from the source code, since they don’t need to know how the engine works to defeat it, according to Rachwald. Antivirus software runs on signatures, and developers have been effectively creating malware that can evade detection for quite some time now, Rachwald said. Antivirus software tends to have a poor rate of detection, as low as 20 percent to 30 percent, because criminals are testing their code against security products and using encryption and other methods to ensure they slip through, he said.

      If the source code also dates back to 1999, then the information is likely to be of interest to only “software historians” interested in how software was created a decade ago, Aryeh Goretsky, a researcher for ESET, told eWEEK. It takes roughly two years to create a new antivirus engine, and although there may be certain elements that still stay the same, there’s enough of a generational gap that attackers won’t be able to find vulnerabilities in the source code that can be used to exploit modern versions of the software, he said.

      While an actual source code leak could turn out to be embarrassing for Symantec, it won’t impact Symantec that much in the market, either, according to Goretsky. “It happened to both Kaspersky a year ago and Microsoft in 2004, and neither seemed to suffer any ill effects, economically,” Goretsky said.

      If all the attackers have is a 12-year-old API document, the contents of which can be reverse-engineered from publicly available information, then Symantec and their customers can have “some confidence that the sky is not falling,” Wisniewski said.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.