Your Antivirus can be a Door for Hackers

11.12.2008

The affected software include many popular commercial and open source antivirus software such as AVG, F-Secure (F-Prot), Sophos, ClamAV, BitDefender & Avast. Other software could also be vulnerable. Organizations can learn more on technical details, potential impact and remediation recommendations on iViZ "Green Cloud Security" website www.greencloudsecurity.com.

To ensure user security iViZ "Green Cloud Security" follows the practice of responsible disclosure. The vulnerability details are disclosed first to the affected vendor before being made public. Bikash Barai said "We work closely with the vendors to help them with details and also in developing the solution. The vulnerability is disclosed in public only after coordinating with vendors and ensuring their users' safety. To ensure that our research cannot be maliciously used by attackers, the proof of concept exploits that demonstrate such real attacks in public are not released."

Companies and businesses in sectors such as banking, finance and insurance, IT/ITES and consulting, online retail, e-commerce, manufacturing, telecommunications, R&D, media among others are highly susceptible to such risks and should make it mandatory to conduct periodic penetration testing to assess the security of their systems and networks. Networks and Applications could include off-the-shelf products (operating systems, applications, databases, networking equipment etc), bespoke development (dynamic web sites, in-house applications etc) and wireless (WIFI, Bluetooth, IR, GSM, and RFID).