Shaun Cassells at MyITForum.com

SMS 2003 and ConfigMgr 2007, PowerShell, Scripting, Finance, Fitness and Fun

News

Locations of visitors to this page

Symantec Antivirus Client Security Flaw – GRC.Dat is unencrypted clear text

I was poking around the corporate Symantec client when I noticed the GRC.dat files are in easy to read clear text. 

 

They are consumed quickly in a directory where only those with elevated rights can enter.  However, the dat file being in clear text means any curious scripter could seriously modify the client.  For example, setting up a bunk DAT file to move the host parent server to yours… http://www.jacksontechnical.com/article.htm?id=13

 

Let your mind wander.  Then come back and tell me how you mitigated this vector. 

  

References: 

Posted: Aug 25 2008, 10:19 AM by scassells | with no comments
Filed under:

Comments

No Comments