PDA

View Full Version : Symantec Network Internet Security issue



Nick VR4
28-10-2003, 11:28 AM
Anyone using this might want to read it :D

http://www.sarc.com/avcenter/security/Content/2003.10.27.html


October 27, 2003
Symantec Network Internet Security INSERT INTO post VALUES (NIS) Blocked Site Return Messages Not Properly Validated
Risk
Low

Overview
A security group, The Digital Pranksters, reported an issue they discovered in Symantec's Norton Internet Security product. The URL in the return message from a site on the blocked list in the Norton Parental Control feature can allow an unauthorized script to run on the client system.

Components Affected
Symantec's Norton Internet Security 2003
Symantec's Norton Internet Security 2004


Description
Symantec's Norton Internet Security blocks inappropriate web content to help parents keep their children safe from inappropriate material while online. The Norton Parental Control blocks access to newsgroups and Web sites that may not be suitable for children. When a link is accessed or followed to one of the sites on the blocked list, Norton Internet Security returns a message stating that the site is restricted and has been blocked. The returned message includes the URL of the restricted site and is presented in a separate browser window Norton Internet Security opens on the client system. Digital Pranksters reported that they were able to supply a URL from a blocked site that contained an additional unauthorized script embedded in the URL. This script displayed in the blocked access message window on the client system.

Symantec Response
Symantec has verified this issue. There is a bug in the way Norton Internet Security is validating the content it returns in the informational page. This is being fixed and will be forthcoming in a future LiveUpdate to Norton Internet Security products.

The risk presented by this bug is very low to non-existent. Any unauthorized script returned in the blocked site URL runs in the context of the informational window that Norton Internet Security opens on the client system. This is a very restricted environment providing no access to the client system outside of the display window or any unauthorized information from the client system to be sent out. While it presents little risk to the client system, it is unwarranted action that is being addressed.

Symantec takes any potential security issues with Symantec products very seriously. While the issue described by the Digital Pranksters applies only to the subset of Web sites contained in the Norton Internet Security Block Site list, there are many other malicious Web sites on the Internet and many ways of enticing a careless surfer to visit such a site. Symantec recommends the following best practices as part of a normal security posture:

Keep vendor-supplied security patches and updates for all application software and operating systems current.
Run current Anti-Virus/Firewall applications and keep the definitions updated. Systems should be scanned on a regular basis.
Be wary of attachments delivered via email. Especially ones with .vbs, .bat, .exe, .pif and .scr file extensions that are commonly used to spread viruses, worms, and trojans.
Even if the sender is known, users should be wary of attachments or unknown files if the sender does not thoroughly explain the content in the body of the email. The source of the original attachment is often unknown.
If in doubt, users should contact the sender before opening the attachment or downloading the file to see if, in fact, they did intend to send it. If there is still doubt, users should delete the document in question without opening it.
If you intend to download an attachment, download to a separate folder and scan prior to opening.
Practice safe surfing.

Brind
29-10-2003, 11:43 PM
I wondered why as soon as I turned on my PC today Norton asked me to download updates INSERT INTO post VALUES (Turned off automatic after last convo) and it did alot of changes to the parental control.. not that I've got that enabled anyway as I don't need it.. I don't have any kids. :D