RE: Symantec LiveUpdate

From: Steven Vallarian (svallarianat_private)
Date: Wed Feb 27 2002 - 07:52:37 PST

  • Next message: Roman Drahtmueller: "SuSE Security Announcement: mod_php/mod_php4 (SuSE-SA:2002:007)"

    In the same key, there is a REG_DWORD called 	PasswordIsEncrypted, that is
    set to 0. 
    
    I figure that this key is used to tell Liveupdate to decrypt the encrypted
    password in the password key, but I haven't been able to find out how to get
    LiveUpdate to encrypt the password when it sets it.
    
    Steven V>
    
    
    > ----------
    > From: 	Javier Sanchez[SMTP:jsanchez157at_private]
    > Sent: 	Monday, February 25, 2002 11:14 AM
    > To: 	bugtraqat_private
    > Subject: 	Symantec LiveUpdate
    > 
    > Norton Antivirus Corporate Edition includes LiveUpdate.  LiveUpdate stores
    > 
    > Username and Password information in cleartext in the registry.  Depending
    > 
    > on your implementation, you may not need LiveUpdate installed at all on
    > your 
    > clients.
    > 
    > I brought this to Symantec's attention months ago.  Since then a new
    > version 
    > of LiveUpdate has been released.  The information is still not encrypted.
    > 
    > Any user with the client installed can run "regedit" search for "password"
    > 
    > and viola!
    > 
    > Here's a "fix":
    > Paste the following into a .reg file (i.e. nav.reg) and push it out to
    > your 
    > clients via login script or whatever:
    > REGEDIT4
    > 
    > [HKEY_LOCAL_MACHINE\SOFTWARE\INTEL\LANDesk\VirusProtect6\CurrentVersion\Li
    > veUpdateSource]
    > "Login"=-
    > "Password"=-
    > 
    > 
    > 
    > 
    > 
    > _________________________________________________________________
    > Chat with friends online, try MSN Messenger: http://messenger.msn.com
    > 
    > 
    



    This archive was generated by hypermail 2b30 : Fri Mar 01 2002 - 02:32:21 PST