Symantec has plugged a series of critical flaws in its Web Gateway appliances which included a backdoor permitting remote code execution on targeted systems. The flaws, discovered during a short crash test by security researchers at Austrian firm SEC Consult, created a means to execute code with root privileges - or the ability …
What a list
"SEC Consult identified six vulnerabilities with the technology in total, including: cross-site scripting; OS command injection; security misconfiguration; SQL Injection; and cross-site request forgery flaws"
If I'm not mistaken, OS command injection and SQL injection are simply due to the absence of input sanitization. If that is indeed the case, then BOOOOO !
Seriously? Cross Symantec Web Gateway off the list for consideration. I wonder which failed acquisition this technology is from?
I wonder if this is a bloated pig, too. Another good reason to wipe Norton/Symantec off you hard drive.
- DINO-SLAYER asteroid SAUR-O-CIDE was terrible bad luck, say boffins
- BEST BATTERY EVER: All lithium, all the time, plus a dash of carbon nano-stuff
- Stick a 4K in them: Super high-res TVs are DONE
- Review You didn't get the MeMO? Asus Pad 7 Android tab is ... not bad
- Russia: There is a SPACECRAFT full of LIZARDS in orbit above Earth and WE control it