Outpost firewall security breached

Exploit defeats self-protection systems.

Security researchers at Matousec, known to VB readers from their firewall leak tests, have released details of an exploit taking advantage of a weakness in Agnitum's Outpost firewall product.

VB100

The attack exploits a weakness in the self-protection system used by Outpost to prevent tampering with its own files. Full details of the exploit are available online for malicious use, and no patch has yet been made available, as the vendor was informed of the problem at the same time as the public disclosure.

It is believed the flaw affects various versions between 3.0.5 and 4.0.1, and can only be exploited from the local system. The release from Matousec is here, with an alert from heise security here.

A response from Agnitum to the discovery and announcement of the exploit was posted on the company's blog on 23 January. The company states that it hopes to have a fix available before the end of January, but also questions the motives of the research group, Matousec, that initially identified the exploit.

Agnitum's statement can be read here.

17 January 2007

Tags:    del.icio.us  digg this! digg this

Quick Links



Poll

When do you install software updates?
As soon as they are released
As soon as I have some time
I take my time, but I always install them eventually
Only when I feel it is absolutely necessary
Never
Leave a comment
View 12 comments

Jobs Career Sidebar

Twitter Feed

virusbtn: RT @emailsecmatters: The typical spam message has sources as diverse as the spam lunch meat: http://ht.ly/2yucd
2 hours ago


virusbtn: Can anyone write a rap about our RAP tests (http://bit.ly/255ySQ) and submit it to the Symantec competition http://bit.ly/bOJg8r
6 hours ago


VB2010

VB2010 VB2010 will take place 29 September - 1 October 2009 at the Westin Bayshore, Vancouver, BC, Canada.
Virus Bulletin currently has 208,224 registered users.