|
Comments
Did you read today's front page stories & breaking news?
SYS-CON.TV
|
i-Technology News Veritas Security Hole Attacked
Backup Exec Remote Agent for Windows Victimized
Jun. 30, 2005 05:00 PM
A security flaw in a Veritas Software backup tool can be exploited,
according to the U.S. Computer Emergency Readiness Team. Malicious code to
exploit a vulnerability in Veritas Software's Backup Exec Remote Agent for
Windows is publicly available, and the organization has received reports of
attacks and has seen an increase in scanning activity on TCP Port 10000, an
indication that hackers are looking for vulnerable systems. The buffer overflow flaw in the Veritas software could allow an intruder to
gain control of a vulnerable system. The tool is used to trigger backup of data
on Microsoft Windows servers, to protect the data from computer crashes,
storage system catastrophes and other risks. It listens for commands addressed
to TCP Port 10000 and accepts links to the backup server before the backup.
However, it fails properly validate incoming packets, Veritas said in an
advisory last week.
The Backup Exec Remote Agent bug is one of several flaws in Backup Exec
products that Veritas provided fixes for last week. The problem was discovered
by security company iDefense, the storage company said. Reader Feedback: Page 1 of 1
Your Feedback
SOA World Latest Stories
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
|
SYS-CON Featured Whitepapers
Most Read This Week |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||