Symantec Connect
  • Login
  • Register
  • Endpoint Management & Virtualization
    • All of Connect
    • Backup and Archiving
    • Endpoint Management & Virtualization
    • Storage and Clustering
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Endpoint Management & Virtualization Community BlogRSS

Patching the Vulnerabilities in DS6.8 and DS6.9

ianatkin's picture
ianatkin
May 22nd, 2008
Filed under: Altiris Deployment Solution, Endpoint Management & Virtualization Community Blog, Endpoint Management and Virtualization

I put this on the Altiris Forums a little while ago, but thought it might be useful to place here too.

The link below describes half-a-dozen security vulnerabilities which appear to be only fixed by UPGRADING to DS 6.9 plus the hotfixes www.symantec.com/avcenter/security. Here are the steps I took to remedy the problem.

I've tried to put together a mitigation list. The first draft is below. Can anyone comment on this? A mitigation list would help admins protect their servers now, and allow them to plan the upgrade to 6.9 at a more leisurely pace.

  1. For the SQL-injection vulnerability (exploitable), you have two mitigation options: Follow best practice and ensure that port 80 is heavily firewalled to restrict the Deployment Solution web console access to your management PCs only. Alternatively, you can disable the IIS services altogether, and install remote consoles as an alternative, and firewall SQL server accordingly.
  2. For the encryption weakness in the domain credential exposure (no current exploit), follow best practice ensure that the credentials you configure in Altiris are limited. For instance, the altiris services should *not* be running with administrator rights, and if you employ credentials for joining machines to domains ensure these accounts are limited, granting them the right to add computers to the domain only.
  3. For the GUI interface privilege vulnerability (no current exploit) you can mitigate by password protecting the Deployment Solution agent, and configuring it to be hidden. The interface cannot be activated thereafter without password entry. This might be heavy handed, but the exploit does not detail the level in the GUI at which this vulnerability emerges.
  4. Tooltip local privilege escalation (exploitable). As 3 above.
  5. Registry keys vulnerability which can lead to service disruption, and access to system information. Uncertain yet whether this is client based, or server. My advice is to follow best practice and ensure server access is restricted to key personnel.
  6. Install Directory local privilege issue (no current exploit). Restrict access to express share as per installation best practice. Only System, administrators and the altiris service account should have modification rights to the folder root.

Kind Regards,
Ian./

+2 (2 votes)
  • ianatkin's blog
  • Login or register to post comments
  • Comments RSS Feed
hamsalad's picture
hamsalad
1 year 33 weeks ago

Nice

Good list. Exactly what I was looking for!

0 votes
  • Login or register to post comments

Would you like to reply?

Login or Register to post your comment.

About Endpoint Management and Virtualization Community Blog

The Endpoint Management & Virtualization Community Blog is the perfect place to share short, timely insights including product tips, news and other information relevant to the Endpoint Management & Virtualization community. Any authenticated Connect member can contribute to this blog.
Filter by:

Recent Blog Posts

  • How to Install and Uninstall IBM Installation Manager using XML files
    WiseUser - March 18, 2010
  • Future Tech - Silverlight and phones (Altiris future mobiltity)
    Palvaran - March 16, 2010
  • Webcast - Redefining Endpoint Management with Altiris IT Management Suite 7.0 from Symantec
    ohzone - March 15, 2010
  • USB Swiss Army Knife: 7 Quick Fix
    riva11 - March 12, 2010
  • Cebit is over. What will be our next big show?
    erikw - March 12, 2010

Blog Tags

7.1 Agents Altiris Client Management Suite Altiris Deployment Solution Altiris IT Asset Management Altiris Notification Server Altiris Recovery Solution Altiris Server Management Suite Asset Management Suite Backup Exec Backup Exec System Recovery Basics Best Practice Beta CIO Digest Case Study Compatibility Configuring Customer Preview Customer Reference Database Dell Dell Management Products Demonstration Documentation Downloads Drivers Emerging Threats Endpoint Management and Virtualization Endpoint Protection (AntiVirus) Enterprise Vault Error messages Evaluating Features General Symantec Ghost Solution Suite HP Management Products Helpdesk Solution How to ITMS Industry Event Inside Symantec Installing Licensing Linux Local DS GURU Email group Mac OS ManageFusion Mobile & Wireless NetBackup New Release News News Performance Platforms & Hardware Problem Management Recovering Reporting Restore SP2 SecurityExpressions Service Pack 2 ServiceDesk Storage Foundation Symantec Connect Symantec Event TMS TechTips Tip/How to Tips/How To Training Troubleshooting Upgrade User Group VDI VMware Virtualization Virtualization Vision Vulnerabilities & Exploits Windows Windows Wise Application Packaging Wise Installation Development Wise Virtual Composer Workflow Solution Workspace Corporate Workspace Profiles Workspace Remote Workspace Streaming Workspace Virtualization XPF baltimore deployment hugo known_issue pcAnywhere solution webcast
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Privacy Policy
  • Symantec.com