CFO Expectations of IT


Follow us





Symantec backtracks, admits own network hacked

Warns pcAnywhere users they face increased risk, confirms theft of source code of prominent consumer programs

Symantec has backed away from earlier statements regarding the theft of source code of some of its flagship security products, now admitting that its own network was compromised.

In a statement provided to the Reuters news service, the security software giant acknowledged that hackers had broken into its network when they stole source code of some of the company's software.

Previously, Symantec had denied that its own network had been breached, and instead pointed fingers at an unnamed "third party entity" as the attack's victim. Evidence posted by a hacker nicknamed "Yama Tough" -- a self-proclaimed member of a gang calling itself "Lords of Dharmaraja" -- indicated that the information was obtained from a server operated by the Indian government.

Two weeks ago, Symantec spokesman Cris Paden said that the hacker made off with source code of Symantec Endpoint Protection 11.0 and Symantec Antivirus 10.2, enterprise products between five and six years old.

At the time, Paden downplayed the seriousness of the theft.

Today, however, Paden said that source code of Norton Antivirus Corporate Edition, Norton Internet Security, Norton Utilities, Norton GoBack and pcAnywhere, had been stolen.

Some of those -- Norton Internet Security and Norton Utilities -- are among Symantec's most prominent consumer-grade products.

Symantec missed one bullet, however.

Last Saturday, Yama Tough promised to release more than a gigabyte of the source code for Norton Antivirus -- the hacker did not specify which version -- but he said the group has since reconsidered.

"We've decided not to release code to the public until we get full of it," Yama Tough wrote on Twitter Monday . "1st we'll own evrthn we can by 0din' the sym code & pour mayhem."

In the message, "0din'" likely stands for "zero-daying," meaning attacks launched against unpatched vulnerabilities.

Also on Monday, Yama Tough claimed that he had some or all of the source code for pcAnywhere, a multi-platform remote access suite that Symantec sells.

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

"PCAnywhere code is being released to blackhat community for 0d expltin!," said Yama Tough, again on Twitter .

Paden confirmed Yama Tough's claim when he told Reuters that pcAnywhere users face "a slightly increased security risk" because of the hacker's activities.

"Symantec is currently in the process of reaching out to our pcAnywhere customers to make them aware of the situation and to provide remediation steps to maintain the protection of their devices and information," Paden said.

Paden did not reply to Computerworld's requests for comment on Symantec's revised statement.



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

The cloud 2015 vision

Cloud computing is an important transition and a paradigm shift in IT services delivery - one that promises large gains in efficiency and flexibility at a time when demands on data centers are growing exponentially. The tools, building blocks, solutions, and best practices for cloud computing are evolving and challenges to deploying cloud solutions need to be considered.

The consumerisation of technology

iPads are the must-have fad. Android is the rising mobile platform -- Everywhere you turn, the news is about personal, smart, mobile devices and their impact on business and on IT.

Big data analytics

Broadly, there are two ways to think of Big Data technologies. The first is as an extension of what many organisations are already doing with business analytics. Gaining insight from business information is something that has been happening for decades, but the challenges and opportunities are now greater than ever before.

Virtualisation: benefits, challenges and solutions

The majority of organisations have already implemented server virtualisation and most intend to implement additional server virtualisation during the next year. The primary factors driving the movement to deploy server virtualisation are cost savings and the ability to dynamically provision and move VMs among physical servers. There are however, a number of significant challenges associated with server virtualisation.


CIO UK - Business - Technology - Leadership

On Demand Webcast
Analyse Data In Real Time


Increasingly businesses require the ability to analyse information quickly. Find out how to handle growing data volumes more efficiently while reducing the cost of managing your organisation's IT landscape

Watch now

SAP Logo

What do CFOs expect from IT?


Watch our sister publication's latest webcast.
Hear a case study from the Guardian News and Media's Technology Director, Andy Beale, and join the discussion on the role of the CFO in technology innovation.

Watch Discussion

CFO World webcast in assocation with Google

On Demand Webcast:
Maximising business flexibility with virtualisation


Register for this on demand webcast and find out how technologies can enable cost effective and secure virtualisation from your server deployments.



Watch now

Dell VMware logo


CFO Expectations of IT


* *