News
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
Go Back   Dev Hardware ForumsGENERAL GooSH!™News

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Display Modes
 
Unread Dev Hardware Forums Sponsor:
  Trader Rating: 2 · #1  
Old January 20th, 2007, 02:02 AM
Dngrsone's Avatar
Dngrsone Dngrsone is offline
Designated Asshole
Dev Hardware God 8th Plane (8500 - 8999 posts)
 
Join Date: May 2004
Location: In the space between you and I
Posts: 8,781 Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)  Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2
Time spent in forums: 7 Months 6 Days 2 h 36 m 30 sec
Reputation Power: 14221
Symantec used rootkit for Norton SystemWorks

Reference

Another case of "it seemed like a good idea at the time"...
__________________
Ask Questions the Smart Way


"In front of a monitor is a dangerous place from which to view the world." --Terri Wells

Enable BSOD: Control Panel/Systems, Advanced Tab, hit the Settings button under Startup and Recovery, and under the System Failure area, uncheck the Automatically Restart checkbox.

Reply With Quote
  Trader Rating: 0 · #2  
Old January 20th, 2007, 02:08 AM
butmunch butmunch is offline
Moz
Dev Hardware Frequenter (2500 - 2999 posts)
 
Join Date: Aug 2004
Location: Leeds
Posts: 2,798 butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)butmunch User rank is Major General (70000 - 90000 Reputation Level)  Folding Points: 241 Folding Title: Novice Folder
Time spent in forums: 3 Weeks 2 Days 4 h 10 m 48 sec
Reputation Power: 778
Send a message via MSN to butmunch
Not suprised... it's nigh on completley impossible to uninstall norton.. I hate it.
__________________

Reply With Quote
  Trader Rating: 0 · #3  
Old January 20th, 2007, 05:56 AM
mrps2man's Avatar
mrps2man mrps2man is offline
Not a n00b DevH'er
Dev Hardware Frequenter (2500 - 2999 posts)
 
Join Date: Apr 2004
Location: P:\aris\France
Posts: 2,826 mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)  Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 2 Days 4 h 55 m 42 sec
Reputation Power: 132
The lesson 4 or 5 years ago was don't use Norton. The lesson today is don't use Norton.

Rootkit or no rootkit, Norton sucks. I don't think that what they did is particularly wrong. They judged that it would be safer to hide files, they hid them, and that's all. Nothing malicious involved. They may be stupid, but if the "experts" said that it was better, then that's what they did.
__________________

Have a computer? Want to save lives? It's easier than you think! Join DevHardware's Folding team today!

Reply With Quote
  Trader Rating: 2 · #4  
Old January 20th, 2007, 11:31 AM
Dngrsone's Avatar
Dngrsone Dngrsone is offline
Designated Asshole
Dev Hardware God 8th Plane (8500 - 8999 posts)
 
Join Date: May 2004
Location: In the space between you and I
Posts: 8,781 Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)Dngrsone User rank is General 199th Grade (Above 100000 Reputation Level)  Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2Folding Points: 510577 Folding Title: Super Ultimate Folder - Level 2
Time spent in forums: 7 Months 6 Days 2 h 36 m 30 sec
Reputation Power: 14221
It isn't the fact that they hid files-- everyone does that-- it's entirely in the way that they hid those files. They weren't content with setting the Hidden attribute or stashing them in the Windows directory and registry-- they had to hide them from Windows itself-- nothing should be hidden from the OS, unless it's to work around a feature of the OS, and that's likely for a nefarious purpose. How long will it be before someone decides that this is part of an NSA "Big Brother" conspiracy?

I don't see the need to go to such lengths to hide files... Symantec has been riding on the reputation that Norton's built up some 15-20 years ago, and the majority of their customer base is corporate-- the users are not sophisticated and are not likely to have the permissions to mess around with those files unless they are admins looking to remove Norton's for what ever reason.

I think it was a bad idea and I feel that there was some other intent other than protecting "Norton's-critical" files from random deletion.

Reply With Quote
  Trader Rating: 0 · #5  
Old January 20th, 2007, 11:41 AM
mrps2man's Avatar
mrps2man mrps2man is offline
Not a n00b DevH'er
Dev Hardware Frequenter (2500 - 2999 posts)
 
Join Date: Apr 2004
Location: P:\aris\France
Posts: 2,826 mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)mrps2man User rank is First Lieutenant (10000 - 20000 Reputation Level)  Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1Folding Points: 280995 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Weeks 2 Days 4 h 55 m 42 sec
Reputation Power: 132
Unless they were not hiding them from the end-user as much as from other malicious software. If the OS can't see the files, there are less chances that somebody can take advantage of them.

In any case, I still don't see why it is wrong to use a rootkit to do what you consider to be improving the security and functionality of your software. If I learned that my AV software was hiding files for me, to be quite honest, I wouldn't really care; if it does its job, I don't want to know about it. The moment it starts causing problems for me, then it'll become an issue, but the only problem here is people saying "oooh, that's bad". Nobody is trying to hurt you, in fact, they were trying to help (not that they are very good at it these days )

Reply With Quote
  Trader Rating: 1 · #6  
Old January 20th, 2007, 02:39 PM
cy's Avatar
cy cy is offline
Lappie Folder
Dev Hardware Intermediate (1500 - 1999 posts)
 
Join Date: May 2006
Location: The Folding Farm
Posts: 1,704 cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)cy User rank is General 44th Grade (Above 100000 Reputation Level)  Folding Points: 128349 Folding Title: Super Ultimate Folder - Level 1Folding Points: 128349 Folding Title: Super Ultimate Folder - Level 1Folding Points: 128349 Folding Title: Super Ultimate Folder - Level 1Folding Points: 128349 Folding Title: Super Ultimate Folder - Level 1Folding Points: 128349 Folding Title: Super Ultimate Folder - Level 1Folding Points: 128349 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 3 Months 3 Weeks 6 Days 2 h 11 m 27 sec
Reputation Power: 3881
The problem I want to know about is;
A system that was bought with Norton installed by the Mfgr.(HP)
The owner wants it removed and goes into remove programs and uninstalls it.
Is it gone or hiding in there to cause
1.) A hole for other malicious software?
2.) A problem for the new security software?
3.) Is it sitting there wasting my space?
4.) Is this not a "Back Door" into the system?
Comments on this post
mrps2man agrees: That's a good question! Given the pain Norton software is to uninstall, I wouldn't be surprised if
it did leave a bunch of garbage behind!
__________________

Asus model G50Vt SP. Laptop with Vista OS 64/32/(XP soon), Intel Centrino 2 Duo Mobile processor p8400 2.26GHz,
Nvidia’s GeForce 9800M GT Graphics Card , RAM 4G 800 Mhz RAM and 2 HDDs 320G 7200RPM

Reply With Quote
  Trader Rating: 2 · #7  
Old January 23rd, 2007, 09:43 AM
Nilpo's Avatar
Nilpo Nilpo is offline
Dev Hardware God 1st Plane (5500 - 5999 posts)
 
Join Date: May 2004
Location: Salem, OH
Posts: 5,746 Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)Nilpo User rank is General 146th Grade (Above 100000 Reputation Level)  Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 1 Month 1 Week 6 Days 4 h 33 m 40 sec
Reputation Power: 10703
Send a message via ICQ to Nilpo Send a message via AIM to Nilpo Send a message via MSN to Nilpo Send a message via Yahoo to Nilpo Send a message via Google Talk to Nilpo Send a message via Skype to Nilpo Send a message via XFire to Nilpo
Facebook MySpace Orkut
Is it gone or hiding in there to cause
1.) A hole for other malicious software?

I would hope it's gone.

2.) A problem for the new security software?

Doubtful. But not impossible.

3.) Is it sitting there wasting my space?

Very little space from what I understand.

4.) Is this not a "Back Door" into the system?

No, it isn't.
Comments on this post
theblackmages agrees!
Osiris32 agrees: There you are Nilpo, your 1 (one) point.
__________________
Don't like me? Click it.

Scripting problems? Windows questions? Ask the Windows Guru!

Stay up to date with all of my latest content. Follow me on Twitter!

Help us help you! Post your exact error message with these easy tips!

Reply With Quote
Reply

Viewing: Dev Hardware ForumsGENERAL GooSH!™News > Symantec used rootkit for Norton SystemWorks


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump




 Free IT White Papers!
 
Create the Optimal Architecture for your Critical Applications
Warburton's the largest independently owned bakery in the UK faced a number of difficult challenges in providing the most robust yet efficient IT infrastructure for their organization's success. IBM's services combined with their xSeries servers created the perfect platform for their SAP environment with sufficient flexibility, and did so in very time effective fashion.

 
Five Best Practices for Deploying a Successful Service-Oriented Architecture
This white paper describes the benefits you can expect with SOA, and how IBM can help take your business there.

 
Gartner Magic Quadrant for Application Delivery Controllers
Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses of solutions, and provides Magic Quadrant reporting for a quick comparison across all vendors. Learn from Gartner how you can benefit from an all-in-one device like Citrix NetScaler that delivers the highest levels of availability, performance and security.

 
Knowledge is Power
What you don't know can hurt you, and is likely costing you money and increasing your security risks during an era of scarce resources. This white paper proposes six key strategies that enterprise security managers can use to improve their network defense posture.

 
Rationalizing the Multi-Tool Environment
The rationalized multi-tool approach is flexible, scalable and cost effective. It provides the necessary input to the IT service management business processes. It preserves prior investments in monitoring tools, empowers technologists to select the best tools with which to do their jobs, and enhances effective response to incidents.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
     
 




© 2003-2010 by Developer Shed. All rights reserved. DS Cluster 7 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek