Symantec on Monday said that while worm-scanning activity against its corporate antivirus software had increased over the weekend, the number of infected systems had dropped.
According to the security company's own DeepSight sensor network, scanning activity on TCP port 2967 is up. That scanning, said Symantec, is thought to originate with what it calls the "Sagevo" worm, also known as "Big Yellow."
"We're seeing a decrease in the number of unique IP addresses," says Vincent Weafer, senior director with Symantec's security response team. "But we're seeing more scanning activity. That actually makes sense, because as there are fewer unpatched systems, the remaining [infected systems] send out even more scans looking for a target. It eventually reaches a saturation [point]."
The number of IP addresses associated with port 2967 scanning has fallen off 80% since late last week, Weafer said.
Friday, eEye Digital Security issued a warning that a new worm was on the loose and attacked enterprise systems that hadn't been patched for flaws first revealed in May for Symantec AntiVirus and Symantec Client Security, two of the vendor's business security products. The vulnerabilities were patched in June.
"We have received only three submissions [of Sagevo] from customers," said Weafer. "It's just not significant."
Sagevo/Big Yellow is the second threat to exploit the patched flaws in AntiVirus and Client Security. The first, "Spybot.acyr," began circulating Nov. 28. "We saw the same kind of peak two weeks ago with Spybot, but that quickly died down," Weafer says, because it ran out of possible targets.
"Product updates are made available to enterprises," says Weafer in answer to criticisms last week by EEye's chief technology officer Marc Maiffret, who said too many software developers don't take patching seriously. "But we have to give the control to them." Pushing patches on businesses is the wrong approach, Weafer says.
Instead, Symantec relies on e-mailed alerts to inform business customers of its software updates, and the corporate-only portal that the company maintains. The scheme seems to work. When Symantec touched base with its larger enterprise customers to verify that they had deployed the June patches for AntiVirus and Client Security, most had, Weafer said.
"But," admits Weafer, "there are pockets [of unprotected systems]."
We just talk about it news and computer games.
Subscribe to:
Post Comments (Atom)
Blog Archive
-
▼
2006
(62)
-
▼
December
(62)
- Living room new Internet battlefield: Apple vs. Mi...
- Next-gen turns on ‘Gears,’ Wii
- Google Blog Search outpaces Technorati
- Ford US cars to get bluetooth, Microsoft operating...
- Digital downloads hit the charts
- Microsoft to Special Bloggers: Freebie Vista-Loade...
- Today's kids: NASA is irrelevant
- Samsung announces new, thinner microchip
- Geeks need video games
- TOP ONE: Protecting polar bears: Your e-mails
- The PlayStation 2 Still Rocks
- Demand Surge Slowed iTunes Site During Holiday Rush
- Media, tech cos probe possible high-def DVD hack
- TOP NEWS: Top Searches For 2006
- Microsoft Says No Favorable Coverage Expected In L...
- Microsoft's Vista: New operating system, same flaws
- What were we looking for online in 2006?
- Lotus Notes 7.0.2 finally out for OS X
- New Samsung Fuel Cell Dock Powers Laptop for a Ful...
- Microsoft patent claim sparks firestorm of controv...
- Windows Vista security flaw uncovered
- Console yourself these holidays
- Wikipedia-like search engine in development
- Christmas iPods Lead To iTunes Delays
- Microsoft patent claim sparks firestorm of controv...
- Linksys announces iPhone family of Voice Over IP s...
- Korean-Developed Fuel Cell ‘Can Run Laptop for a M...
- Jimmy Wales, founder of online encyclopedia Wikipe...
- Wikipedia Founder Plans Search Engine
- 2006 in review: Videogames
- 2006: The year in Apple
- Elpida begins mass production of DDR2 on 70nm
- Real robots
- Why Microsoft/Novell is good for Linux
- Microsoft Xbox 360 Console Cost Reduction Delayed ...
- Apple takes no. 2 in BW 'Tech Hot Growth 50'
- Nintendo touts Opera browser for Wii
- Samba guru quits Novell for Google over GPL contro...
- Wikipedia founder to launch search engine
- Happy Holidays: Have a Database
- Flaws Are Detected in Microsoft’s Vista
- UK queen's Christmas message on podcast
- Xbox Buyers Get Extended Warranty, Repairs Paid Ba...
- Hasta la Vista
- Grant funds open-source challenge to Google library
- Wii: Internet Telly for Dummies Now Available
- Microsoft plans showy consumer intro for Vista, Of...
- Microsoft extends Xbox 360 warranty to 1 year
- Dirty air doesn't worry experts
- Google overtakes Yahoo in user visits: Industry Tr...
- Living with (or without) Internet Explorer 7.0
- Open-source leader leaving Novell for Google
- As of today Wii can surf
- Face-Off: New Software Recognizes Faces on Web
- YouTube to meet Japan media over copyright worries
- Zune can finally handle Vista
- Free Opera Internet Browser for Nintendo Wii
- Medieval II: Total War Goes Gold
- Google buys mobile mash-up mapping technology
- Symantec: More patched systems, fewer potential vi...
- ICAC issues guidelines on ID protection
- Oracle's pipeline is crammed, execs say
-
▼
December
(62)
No comments:
Post a Comment