Trend Micro Flaw Could Have Allowed Attacker To Steal All Passwords (csoonline.com) 62
itwbennett writes: Trend Micro has released an automatic update fixing the problems in its antivirus product that Google security engineer Tavis Ormandy discovered could allow "anyone on the internet [to] steal all of your passwords completely silently, as well as execute arbitrary code with zero user interaction." The password manager in Trend's antivirus product is written in JavaScript and opens up multiple HTTP remote procedure call ports to handle API requests, Ormandy wrote. Ormandy says it took him 30 seconds to find one that would accept remote code. He also found an API that allowed him to access passwords stored in the manager. This is just the latest in a string of serious vulnerabilities that have been found in antivirus products in the last seven months.
Anyone still uses that crud? (Score:2)
Honestly who uses Trend Micro? every single company I have been to uses Eset NOD32 or the less IT educated companies use the McAfee corporate garbage.
Re: (Score:3)
Re: (Score:3, Insightful)
Antivirus is for checking off a box to make the legal eagles happy. It isn't for real protection, because most machines get nailed by 0-days or vulnerabilities in browser add-ons.
Want real protection? Use AdBlock and NoScript, or at least run your browser in a sandbox or VM. Antivirus tends to be ineffective against malvertising, which seems to be the #1 infection vector these days.
Re: (Score:2)
Re: (Score:2)
I always used System Center Endpoint Protection on Windows 7 systems.
Re: (Score:2)
Re: (Score:2)
...because I only ever use passwords while in my office.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
This used to be the case.
Symantec has surprised me by making a pretty fast centrally managed product. All of the big companies I have worked for are running SEP.
For years, Symantec was synonymous with slow/fat/bloated but now that is AVG.
Trend has always been a pretty good performer as well.
The best AV solution I ever came across both in performance and effectiveness was Sunbelt's Viper... then it was bought by GFI and got bad.
we're using something called 'APK' over here (Score:5, Funny)
The weird thing is that when I try to search for reviews of this product, everything that turns up in Bing seems to be written by people with mental disorders. I guess it's probably anti-astroturfing by commercial competitors.
Just wow ... (Score:5, Insightful)
The stupidity of this is epic.
So you've got a security product, and users can be idiots and give you all their passwords ... and then using unsuitable technology you're going to reveal them.
Jesus fucking Christ on a flaming pogo stick ... a password manager written in javascript??? It opens multiple HTTP RPC ports????
Are Trend that lazy and incompetent and just pushing crap out the door so they can claim to have one??? And we're supposed to trust you to have a security product???
This is beyond belief. It sounds like they're just phoning it in, and people should be loudly told to stay away from this pile of crap.
Re: (Score:1)
Wait a minute... A password "manager"? On your computer? Attached to the internet??
Ohhh, Muurrrrder! I mean, who cares if it's written in Emacs, or straight up binary?
Re: (Score:2)
Accepting incoming connections makes no sense at all.
If it bends over and hands out your password to any passerby who stumbles on an open port, then everyone will care.
Password managers need to handle encryption, not just take incoming API calls, and generally act like security makes a difference.
Reading TFA indicates this is none of those things.
You could take some time and competently write this in damned near anything -- even emacs if it's got a decent crypto library. Or you can do what it sounds like T
Re: (Score:3)
Grammatically incorrect, but eerily semantically accurate.
Re:Just wow ... (Score:4, Insightful)
The more you read, more stupid. Consult security (Score:2)
The you understand about their code in this case, the more stupid you see. Most flaws I can understand, someone overlooked something. These people at Trend Micro were beyond incompetent, utterly clueless.
Security professionals do exist who have been securing (and breaking) systems since the early days of the web. If you're a security company, hire a few of those people. Not only will they help you write software that doesn't stupidly open all of your customers to remote code execution, but by understanding
Re: (Score:2)
Re: (Score:2)
It even comes free with their antivirus product. I am glad I never used it.
Re: (Score:2)
It is an optional installation. I said no to the install when it asked if I wanted the free product.
Re: (Score:2)
Trendmicro always had bad ratings with av-total and other security firms in terms of crippling performance. Good news is really bad ones like Norton have improved in this area. My figure is if the product slows down performance then it has to be poorly coded. My guess is right after hearing this
Re:Just wow ... (Score:4, Insightful)
It's possible the developer was clueless, but it's also possible something more like this happened:
1) Developer writes rapid prototype in JavaScript intending to convert it to C.
2) PHB sees it and says "Wow, that's great! No time to perfect it! We gotta get this feature out the door now!"
3) Developer says "...but..."
4) PHB says: "No buts, we'll fix it in the next release." (unless something else important comes up, which has a statistical probability of nearly 100%)
I've seen both happen plenty of times in software development.
Re: (Score:2)
Re: (Score:2)
If you want a password manager written in Javascript, there are ways of doing it properly. Clipperz.is [clipperz.is] is a good example. First and foremost, it is open source. Secondly, it lets you export a read-only copy of the application as a single, self-contained html file that you can run locally and export from again. Or you can export cleartext json+html if you wish to transfer the data elsewhere. Furthermore, everything is encrypted by default and no cleartext leaves your browser. Cleartext is extracted on as-ne
Dang it! (Score:1)
The NSA probably helped add this "flaw" and promised to pay the TrendMicro CEO $5M per year hush money. Now that it is fixed, he will have to give up all that easy money.
Re: (Score:2)
The NSA probably helped add this "flaw" and promised to pay the TrendMicro CEO $5M per year hush money. Now that it is fixed, he will have to give up all that easy money.
Humorous, but the NSA aren't stupid and wouldn't pay for such low hanging fruit.
User-Agent: Secure Browser (Score:1)
Enough said
You used what to write what? (Score:5, Insightful)
>> The password manager in Trend's antivirus product is written in JavaScript
You're letting your web app developers write security software now? How is Trend still even in business?
Re: (Score:3)
No, they're letting their web developers pretend to write security software, when they clearly have no idea of what the hell they're doing.
This sounds like something you get summer students or a random web-site to code for you.
I can't decide if this is gross incompetence, or outright fraud.
Re:You used what to write what? (Score:5, Insightful)
Re: (Score:2)
Antivirus software is a business because Antivirus is more about marketing than about actually solving any problems.
There we go, FTFY.
Antivirus is nothing more than yet another insurance policy.
Corporations run it so they can claim some level of valid defense if they get infected, but other than bullshit legal wranglings, it pretty much does fuck-all to actually protect the enterprise.
Re: (Score:2)
No. Insurance pays out if you suffer a loss. AntiVirus? Go pound ...
Antivirus is a business because it allows companies plausible deniability when they get compromised (in MBA speak "best practices").
Re: (Score:2)
No. Insurance pays out if you suffer a loss. AntiVirus? Go pound ...
Antivirus is a business because it allows companies plausible deniability when they get compromised (in MBA speak "best practices").
Ironically, this exact reason was the "insurance" I was referring to. It does "pay out" in this sense because it grants companies this legal protection. Without this defense, risk and costs would be much higher.
Re: (Score:2)
I disagree.
Modern AV combined with ad blocking software makes a computer somewhat usable for the internet. As someone who supports pcs modern AV software monitors processes and inspects services to make sure no suspicious activity happens.
Re: (Score:2)
modern AV software monitors processes and inspects services to make sure no suspicious activity happens.
If you're depending on that to keep computers safe, you're going to be sorely disappointed.
All a virus writer has to do is test his malware against the major anti-virus software packages, to make sure it's not detected. Simple.
Re: (Score:2)
Underwritten by the NSA. In light the Juniper scandal, I mean this seriously.
As I always say. . . (Score:3)
the more software you have installed the slower and more vulnerable your system becomes.
Re: (Score:3)
even this is relevant... how sad
Re: (Score:2)
we know it's you, sexconker
Obligatory: All Your Password are Belong to Us (Score:2)
http://i.imgur.com/1nyVayo.jpg [imgur.com]
Wait, what???? (Score:2)
.
Un - friggin' - believable.
Our diversity and multicultural workforce are key (Score:1)