Symantec Connect - Security - Blog Entries http://www.symantec.com/connect/item-feeds/blog/691%2C2741/feed/all/all en Articles 12.1 http://www.symantec.com/connect/blogs/articles-121 <p>&nbsp;</p> <table border="0" cellpadding="0" cellspacing="0" width="1692"> <tbody> <tr height="21"> <td class="xl66" height="21" width="1692">How to prevent SEP features from being disabled in the client GUI in SEP 12.1</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH168990</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Clients show &quot;No Symantec protection technologies are installed&quot; after migrating the SEPM from 11.x to 12.1</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH164677&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336009500</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to upgrade the Symantec Endpoint Protection Manager (SEPM) to Version 12.1 RU1</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH176260&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336036507</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to install clients using &quot;Client Deployment Wizard&quot; in the Symantec Endpoint Protection Manager 12.1</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH164308&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336072299</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection 12.1: Disabled option for reputation submissions in installation settings may be re-enabled for deployed clients</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH162045&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336098689</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Creating a managed .MSI package in Symantec Endpoint Protection 12.1</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH165483&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336121772</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">After installing Symantec Endpoint Protection 12.1 on a machine, you receive a warning that the trial license has expired even though the SEPM has an active non-trial license</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH171252&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336154035</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Best practices when deploying Symantec Endpoint Protection client package over saturated 64k WAN links</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl68" height="21">Symantec Endpoint Protection 11.x and 12.1 User Mode Considerations: Client Mode Registration explained</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH157004&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336228402</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection 12.1: Best Practices for Disaster Recovery with the Symantec Endpoint Protection Manager</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH160736&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336409813</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection Manager 12.1 (SEPM) fresh install with a new SQL database - graphical overview</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH169451&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336439852</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to move Symantec Endpoint Protection Manager 12.1 from one machine to another</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH171767&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336482705</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to upgrade/cross-grade Symantec Endpoint Protection 12.1 from Small Business Edition to Enterprise Edition</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH166993&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336512749</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl67" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection 12.1 - Non-persistent Virtualization Best Practices</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH180229&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329335886615</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to prepare a Symantec Endpoint Protection 12.1 client for cloning</td> </tr> <tr height="21"> <td class="xl65" height="21">www.symantec.com/business/support/index?page=content&amp;id=HOWTO54706</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection 12.1: Tamper Protection causes continuous reboot after cloning or sysprep</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH163030</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to repair duplicate IDs on cloned Symantec Endpoint Protection 12.1 clients</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH163349</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection 12.1 - Virtualization Best Practices</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH173650&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336592107</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How-to Documents for Symantec Endpoint Protection 12.1</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH163705&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336726211</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to prepare Symantec Endpoint Protection clients on virtual disks for use with Citrix Provisioning Server</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH123419&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336758094</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Scan tasks fail on Symantec Endpoint Protection 12.1 clients when tasks are run from the Symantec Endpoint Protection Integration Component</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH163130&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336829109</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection Manager (SEPM) installation returns the error: &quot;The server schema is older than the database schema, the configuration cannot continue.&quot;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH178820&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336914399</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection 12.1 RU1 Client-only patch</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH174706&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336943469</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Migration from Symantec Endpoint Protection Manager 12.1 stops at Cscript.exe</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH180824&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329336983988</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Unable to open the Symantec Endpoint Protection client interface after migrating to 12.1 on Windows 7 64-bit</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH164707&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337024438</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to uninstall Symantec Endpoint Protection 12.1 client from Windows XP and Windows 2003 32-bit and 64-bit operating systems manually</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH163585&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337057115</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection 12.1: VPN client is identified as a potential risk by SONAR</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH162189&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337087586</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">SEP 12.1 LiveUpdate Engine cannot connect through a proxy server using NTLM authentication</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH173767&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337117265</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to Block or Allow Devices in Symantec Endpoint Protection</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH175220&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337147942</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">What is the Endpoint Protection 12.1 IIS ISAPI proxy and when is it installed?</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH180596&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337174265</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to debug the Symantec Endpoint Protection client</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH102412&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337208323</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Symantec Endpoint Protection 12.1 Manager counts Symantec Endpoint Protection 11.0 clients as seats towards the license.</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH178829&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337249630</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">How to use a custom port for the Embedded database on Symantec Endpoint Protection 12.1</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH157461&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337295235</td> </tr> <tr height="21"> <td class="xl65" height="21">&nbsp;</td> </tr> <tr height="21"> <td class="xl66" height="21">Many *.qsp files are detected as a virus in C:\Windows\Temp folder in Symantec Endpoint Protection</td> </tr> <tr height="21"> <td class="xl65" height="21">http://www.symantec.com/business/support/index?page=content&amp;id=TECH173652&amp;actp=search&amp;viewlocale=en_US&amp;searchid=1329337324796</td> </tr> </tbody> </table> <div class="og_rss_groups"></div> http://www.symantec.com/connect/blogs/articles-121#comments Security Security Community Blog 12.1 12.x Endpoint Protection (AntiVirus) Endpoint Protection Small Business Wed, 15 Feb 2012 20:29:28 +0000 Swapnil 2128211 at http://www.symantec.com/connect Why is Symantec Connect (Forum) Important? http://www.symantec.com/connect/blogs/why-symantec-connect-forum-important <p>I have seen administrators of SEP, DLP, SSIM&nbsp;etc to be on Connect invariably. They don&#39;t refer to admin guide of SEP, DLP etc as much as they refer to forum, article, download on Connect. Why is that? Why can&#39;t Symantec develop admin guide just like the articles on Connect?</p> <p>I think the&nbsp;answer is simple!</p> <p>Admin guide developed by Symantec is about the product. For example, admin guide of SEP will talk about the using SEP, using its feature, product functionality etc.So, its actually product documentation.&nbsp;Whereas, Connect has the solution of practical challenges that administrators find in day to day operation. So, Connect is more about the implementation of product in a specific environment. Now, there can be 1000s of different environment and providing the solution of challenges of each environment differently is difficult for any product vendor. Also, given different environment, how product would behave is difficult to ascertain!</p> <p>Connect has questions, articles, download for the different scenarios, that administrator has faced already or facing currently. These administrator can talk with each other here and get mutually benefited.</p> <p>Therefore, product documentation is about the product functionality, features etc, whereas Connect is about the solution practical challenges that is faced by administrators on the ground. And both of them are equally important.</p> <p>I am writing this because, I have heard from some entry level admins that people trust Connect more than the admin guide itself. I have explained them and writing here my views for other entry level admins. This may help them in understanding the value of each one of them (admin guide and Connect)</p> <div class="og_rss_groups"></div> http://www.symantec.com/connect/blogs/why-symantec-connect-forum-important#comments Security Security Community Blog Admin Guide Administrators Connect Practical Issues Tue, 14 Feb 2012 08:42:05 +0000 AR Sharma 2125151 at http://www.symantec.com/connect Traveliing light in a time of digital thievery http://www.symantec.com/connect/blogs/traveliing-light-time-digital-thievery <p><a href="http://www.nytimes.com/2012/02/11/technology/electronic-security-a-worry-in-an-age-of-digital-espionage.html">http://www.nytimes.com/2012/02/11/technology/electronic-security-a-worry-in-an-age-of-digital-espionage.html</a></p> <div class="og_rss_groups"></div> http://www.symantec.com/connect/blogs/traveliing-light-time-digital-thievery#comments Security Security Community Blog Mon, 13 Feb 2012 00:26:54 +0000 bruceparker 2123301 at http://www.symantec.com/connect SEP 12.1 is now Available http://www.symantec.com/connect/blogs/sep-121-now-available <p>Powered by Symantec Insight&trade;, Symantec&trade; Endpoint Protection is fast, powerful security for endpoints. It offers advanced<br /> defense against all types of attacks for both physical and virtual systems. Seamlessly integrating the essential security tools<br /> you need into a single, high performance agent with a single management console, Endpoint Protection provides world-class<br /> protection without slowing you down.</p> <div class="item-list"><ul class="attachment-list"><li class="first"><a href="http://www.symantec.com/connect/sites/default/files/SEP 12.1 Datasheet.pdf">SEP 12.1 Datasheet.pdf</a></li> <li class="last"><a href="http://www.symantec.com/connect/sites/default/files/5 Reasons to Upgrade to SEP 12.1.pdf">5 Reasons to Upgrade to SEP 12.1.pdf</a></li> </ul></div><div class="og_rss_groups"><ul class="links"><li class="og_links first last"><a href="/connect/oguser/hawaii-security-compliance-user-group"><span>Hawaii Security & Compliance User Group</span></a></li> </ul></div> http://www.symantec.com/connect/blogs/sep-121-now-available#comments Security Security Community Blog 12.1 12.x Endpoint Protection (AntiVirus) Endpoint Protection Small Business Hawaii Security &amp; Compliance User Group Fri, 10 Feb 2012 20:15:02 +0000 Tmullen 2122311 at http://www.symantec.com/connect Microsoft Privilege Exploitation in 2011 http://www.symantec.com/connect/blogs/microsoft-privilege-exploitation-2011 <p>2011 is quickly fading in the rear view mirror so here&rsquo;s a brief analysis on <a href="http://technet.microsoft.com/en-us/security/bulletin" target="_blank">Microsoft vulnerabilities\patches</a> and privilege risk for the year. As mentioned in the <a href="http://www.arellia.com/2011/05/31/malicious-software-and-privilege-exploitation/">Introduction on Privilege Exploitation</a>, privilege exploitation is where the malicious software takes advantage of the rights of the logged in user to change the configuration of the local computer.</p> <p>Here is a summary of privilege exploitation in 2011 and 2010 for comparison:</p> <table border="1" cellpadding="0" cellspacing="0" width="496"> <tbody> <tr> <td nowrap="nowrap" valign="bottom" width="222">&nbsp;</td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center"><strong>2011</strong></p> </td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center"><strong>2010</strong></p> </td> <td nowrap="nowrap" valign="bottom" width="76"> <p align="center"><strong>2010 to 2011</strong></p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="222">&nbsp;Bulletins</td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">100</p> </td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">106</p> </td> <td nowrap="nowrap" valign="bottom" width="76"> <p align="center">-5.7%</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="222">&nbsp;Vulnerabilities</td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">213</p> </td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">269</p> </td> <td nowrap="nowrap" valign="bottom" width="76"> <p align="center">-20.8%</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="222">&nbsp;Bulletins with Privilege Exploitations</td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">46</p> </td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">59</p> </td> <td nowrap="nowrap" valign="bottom" width="76"> <p align="center">-22.0%</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="222">&nbsp;Vulnerabilities with Privilege Exploitations</td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">91</p> </td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">157</p> </td> <td nowrap="nowrap" valign="bottom" width="76"> <p align="center">-42.0%</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="222">&nbsp;% of Bulletins with Privilege Exploitation</td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">46.0%</p> </td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">55.7%</p> </td> <td nowrap="nowrap" valign="bottom" width="76">&nbsp;</td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="222">&nbsp;% of Vulnerabilities with Privilege Exploitation</td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">42.7%</p> </td> <td nowrap="nowrap" valign="bottom" width="53"> <p align="center">58.4%</p> </td> <td nowrap="nowrap" valign="bottom" width="76">&nbsp;</td> </tr> </tbody> </table> <p>As you will observe, there was a general improvement in the number of bulletins, vulnerabilities, those with privilege exploitation.</p> <p>Each bulletin has one or more vulnerabilities that apply to one or more operating systems or applications. Here is a listing of affecting software and the number vulnerabilities with privilege exploitation:</p> <table border="1" cellpadding="0" cellspacing="0" width="189"> <tbody> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center"><strong>Software</strong></p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center"><strong>Vulnerabilities</strong></p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">IE 6</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">29</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">IE 7</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">29</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">IE 8</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">29</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">XP</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">26</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">Vista</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">26</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">Office</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">25</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">Server 2008</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">24</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">7</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">24</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">Server 2003</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">23</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">IE 9</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">21</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">Excel</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">14</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">Visio</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">5</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">PowerPoint</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">2</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">Forefront</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">1</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">Groove</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">1</p> </td> </tr> <tr> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">Visual Studio</p> </td> <td nowrap="nowrap" valign="bottom" width="66"> <p align="center">1</p> </td> </tr> </tbody> </table> <p>As you can see, Internet Explorer is the top for vulnerabilities with privilege exploitation. Exploits in this case are likely a malicious URL either on a website or in an e-mail that allow the malicious user or software to run commands and calls at the privilege of the running user. If the user is a member of the administrators group, game over.</p> <p>Of the operating system vulnerabilities with privilege exploitation exposure, here are some of the most frequently affected components (there are many others):</p> <ul> <li>.NET</li> <li>Silverlight</li> <li>Windows Media Player \ Center</li> <li>OLE</li> </ul> <p>Removing end user administrator rights is not a silver bullet, but it will reduce the risk to malicious software not to mention additional benefits around system stability and support costs. Here is another way to think about these statistics. If you could do one thing to reduce the impact of a car accident by 40%, would you do it? Start buckling those seat belts and start removing end user administrator rights. For more information on the latter, look at <a href="http://www.arellia.com/application-control-solution/">Arellia Application Control Solution</a>.</p> <p><b>About Arellia: </b>Arellia provides solutions for securing local administrator accounts and groups, privilege management and whitelisting, and compliance remediation. Arellia products are integrated with the Symantec Management Platform and sold exclusively through Symantec.</p> <div class="og_rss_groups"></div> http://www.symantec.com/connect/blogs/microsoft-privilege-exploitation-2011#comments Security Security Community Blog Fri, 10 Feb 2012 17:13:30 +0000 stebro 2121861 at http://www.symantec.com/connect We live in a Mobile world http://www.symantec.com/connect/blogs/we-live-mobile-world <p>I am absolutely blown away with what is going on in the mobile world and the latest numbers from IDC demonstrate the fact that mobile is breaking every record. A <strong><em>year on year growth of 57% for Smartphone shipments </em></strong>compared to last year. Do I need to say more? These devices will be used for business and private matters and they function merely as a pc. So what is the difference?&nbsp; I think that we don&rsquo;t consider that question enough, we simply use it together with all the features we can get our hands on; mobile banking and payments, browsing the web, reading emails, downloading apps, gathering intelligence, and the list goes on... So why should we separate the way we manage mobile devices from any other device or endpoint connected to our network?</p> <p>Adaptive Mobile did a report last year on the mobile threats and their key conclusions were that <strong><em>mobile scams are way more profitable </em></strong>than the traditional pc scams (2% conversion rate compared to 0,000008%) and guess what, this will only make it more attractive as there is more money to be made by criminal minds. In addition the methods to compose mobile malware and similar will be faster, since the structure and base are already in place and only small adjustments are needed to make it work in the mobile world. So again, the difference between securing mobile devices and any other device or endpoint should not be that big, they all need to be managed to provide the possibility to protect the information on the device, or information being accessed through the mobile device.</p> <p>We are rapidly approaching Mobile World Congress 2012 and mobile briefings, meetings, analysis, events, planning and more is part of my mobile world. It will be a great show (the forecasted 60&nbsp;000 attendees kind of confirm that) and I look forward to demonstrating the&nbsp;up and coming solutions for the mobile world, that will contibute to making it a&nbsp;secure mobile world.</p> <p><strong>Visit Symantec at MWC 2012 - hall 8 at booth #A171 and <a href="void(0)/*291*/">schedule a meeting </a>with our business or technical experts.</strong></p> <div class="og_rss_groups"><ul class="links"><li class="og_links first last"><a href="/connect/groups/emea-endpoint-management-and-mobility-group-emm"><span>EMEA Endpoint Management and Mobility Group (EMM)</span></a></li> </ul></div> http://www.symantec.com/connect/blogs/we-live-mobile-world#comments Security Security Community Blog Authentication Services Data Loss Prevention (Vontu) Endpoint Encryption Mobile Security Symantec Endpoint Management (EPM) Partners EMEA Endpoint Management and Mobility Group (EMM) Fri, 10 Feb 2012 08:53:17 +0000 Marie Pettersson 2121011 at http://www.symantec.com/connect how to set the password to enable the USB access of User end http://www.symantec.com/connect/blogs/how-set-password-enable-usb-access-user-end <p><strong>Problem</strong></p> <p>Need to set the password to disable Smc service</p> <p>&nbsp;</p> <p><strong>Cause</strong></p> <p>For the Security Purpose required to Set the password</p> <p>&nbsp;</p> <p><strong>Solution</strong></p> <p>Go to SEPM.</p> <p>Login Console with Admin Id.</p> <p>Go client Tab and then choose the Group where you want to set the password.</p> <p>Under that Group choose the policy TAB.</p> <p><img alt="" src="https://www-secure.symantec.com/connect/imagebrowser/view/image/1973351/_original" /></p> <p>Click on General Setting then tab on Security Setting.</p> <p>There four option avail</p> <p><img alt="" src="https://www-secure.symantec.com/connect/imagebrowser/view/image/1973361/_original" /></p> <p>Check the &quot;Require a password to stop the client service&quot;</p> <p>Enter the passwor that have mention on right hand side of the security tab.</p> <p>Then ok and then right click on that Group and update the content.</p> <p>It will set the password to stop the SEP.(command smc -stop)</p> <div class="og_rss_groups"></div> http://www.symantec.com/connect/blogs/how-set-password-enable-usb-access-user-end#comments Security Security Community Blog 11.x Endpoint Protection (AntiVirus) Fri, 03 Feb 2012 15:15:57 +0000 sumitgupta786 2111181 at http://www.symantec.com/connect Who Will Protect Your Data? http://www.symantec.com/connect/blogs/who-will-protect-your-data <p>Managing the continued increase in data is a major issue for organisations. IDC predicts that we stored 1.8 zetabytes of information in 2011 (1.8 x 1021 bytes), and that this will increase to 7.9 zetabytes &nbsp;stored by 2015 [1].</p> <p><img alt="" src="/connect/imagebrowser/view/image/2104991/_original" /></p> <p>Figure 1. Graph of data being stored worldwide [1].</p> <p>&nbsp;</p> <p>At the same time, the value of data is also growing. The annual Cost of a Data Breach study by the Ponemon Institute, shows a clear year on year increase in the costs incurred per data record compromised when data is lost or stolen. [2]</p> <p><img alt="" src="/connect/imagebrowser/view/image/2105021/_original" /></p> <p>Figure 2. Graph of total costs incurred per data record breached [2].</p> <p>Other factors may dramatically increase the cost of dealing with lost data; proposed EU legislation will fine companies up to 5% of turnover for contravening data protection laws [3]. Therefore, in the environment in which we operate, more and more information is being created, this information is increasingly valuable, and we will risk major fines if part of this growing mountain of data is compromised.</p> <p>Hence, the profession of information security which seeks to secure this data, the systems in which it resides, and the networks upon which it travels, against disclosure or loss while ensuring that this data is available when required to authorised users. It is relief to know that the number of people working in information security worldwide is growing at about 11% per year, with in excess of 700,000 working in the domain in the EMEA region [4].</p> <p>However, there are 20.8 million registered companies in the EU alone [5]. If we assume that the 700 000 information security workers all work in the EU, which is certainly an over estimation, this implies that there is a single information security worker for every 34 companies.</p> <p>The average number of employees per company across organisations of all sizes within Europe is only 4 people [5]. Therefore we can assume that there will be an unequal distribution of these relatively rare information security employees. We can envisage that large companies will have teams of employees dedicated to protecting valuable data, while it is unimaginable that the &lsquo;average&rsquo; company will dedicate one quarter of their workforce to information security. So who will protect the data of small businesses?</p> <p>The security of data is one of the factors driving the uptake of cloud services. By pooling data from many companies within a cloud environment, the costs of securing this data can be shared across a large number of companies. In this way a small number of information security workers can ensure that the data of a large number of companies is secure against attack or loss.</p> <p>Customers of cloud services need to ensure that data protection and security is specified in their service level agreement with the cloud provider. Equally, the end customer will have to consider how their data is used and accessed within their local network, but when it comes to large amounts of data, keeping it in the cloud is probably the safest option.</p> <p>&nbsp;</p> <p><strong>References.</strong></p> <p>1. The 2011 Digital Universe Study: Extracting Value from Chaos. IDC.</p> <p><a href="http://idcdocserv.com/1142" target="_blank">http://idcdocserv.com/1142 </a></p> <p>2.&nbsp; 2010 Cost of a Data Breach. Ponemon Institute.</p> <p><a href="http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/2010%20Global%20CODB.pdf" target="_blank">http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/2010%20Global%20CODB.pdf</a></p> <p>3.&nbsp; Data breach law: Companies facing fines of five per cent of turnover. Silicon.com.</p> <p><a href="http://www.silicon.com/technology/security/2011/12/06/data-breach-law-companies-facing-fines-of-five-per-cent-of-turnover-39748307/" target="_blank">http://www.silicon.com/technology/security/2011/12/06/data-breach-law-companies-facing-fines-of-five-per-cent-of-turnover-39748307/</a></p> <p>4.&nbsp; The 2011 (ISC)2 Global Information Security Workforce Study. ISC2</p> <p><a href="https://www.isc2.org/uploadedFiles/Industry_Resources/FS_WP_ISC%20Study_020811_MLW_Web.pdf" target="_blank">https://www.isc2.org/uploadedFiles/Industry_Resources/FS_WP_ISC%20Study_020811_MLW_Web.pdf</a></p> <p>5.&nbsp;&nbsp; Are EU SMEs recovering from the crisis? Annual Report on EU Small and Medium sized Enterprises 2010/2011. European Commission - DG Enterprise.</p> <p><a href="http://ec.europa.eu/enterprise/policies/sme/facts-figures-analysis/performance-review/pdf/2010_2011/are_the_eus_smes_recovering.pdf" target="_blank">http://ec.europa.eu/enterprise/policies/sme/facts-figures-analysis/performance-review/pdf/2010_2011/are_the_eus_smes_recovering.pdf</a></p> <div class="og_rss_groups"></div> http://www.symantec.com/connect/blogs/who-will-protect-your-data#comments Security Security Community Blog Managed Security Services Tue, 31 Jan 2012 11:53:24 +0000 MartinLee 2105041 at http://www.symantec.com/connect 4 Tips to Combat the Uncommon Cold http://www.symantec.com/connect/blogs/4-tips-combat-uncommon-cold <p>Aliens have invaded earth with the intent to wipe out mankind. But ex-scientist turned cable technician, David Levinson (Jeff Goldberg), helps mobilize a plan to use the &ldquo;common cold&rdquo; or computer &ldquo;virus&rdquo; to fight back against the alien species and bring down their defenses in the 1996 movie <a href="http://www.imdb.com/title/tt0116629/">Independence Day</a>.<br /> &nbsp;<br /> While the story is fiction, the potential damage that a virus or malware can do to businesses and peoples&rsquo; lives is all too real. In fact, attackers unleashed an average of more than nine new threats every second in 2010.<br /> &nbsp;<br /> The healthcare industry knows firsthand about virus outbreaks. Take the <a href="http://www.symantec.com/connect/blogs/downadupconficker-and-april-fool-s-day-one-year-later">Conficker</a> virus that infected hundreds of MRI devices around the world. In fact, healthcare leads the industry in data breaches with more than 400 health information breaches involving over 12 million records over the past two-plus years.<br /> &nbsp;<br /> According to Jon Oltsik, senior principal analyst at the <a href="http://www.enterprisestrategygroup.com/">Enterprise Strategy Group (ESG)</a>, one reason the healthcare industry is more vulnerable than others is that information is shared across a wider array of devices. It resides not only on laptops and workstations but also on clinical, testing, and monitoring systems. Further, healthcare devices must meet high performance and maximum availability requirements around the clock. So what is healthcare IT doing to make sure services are available 24x7, while protecting patient data?<br /> &nbsp;<br /> In the January CIO Digest article, &ldquo;<a href="http://www.symantec.com/ciodigest/article2.jsp?aid=jan12_healthcare">4 Tips to Combat the Uncommon Cold</a>&rdquo; I had the opportunity to talk with ESG analyst Jon Oltsik and key IT decision makers from <a href="http://www.symantec.com/resources/customer_success/detail.jsp?cid=continuum_health_partners">Continuum Health Partners</a>, <a href="http://www.symantec.com/resources/customer_success/detail.jsp?cid=drfirst">DrFirst</a>, <a href="http://www.symantec.com/resources/customer_success/detail.jsp?cid=servicio_andaluz_de_salud">SAS</a>, and <a href="http://www.symantec.com/resources/customer_success/detail.jsp?cid=royal_liverpool">The Royal Liverpool and Broadgreen University Hospitals NHS Trust</a> to uncover best practices around protecting vast number of endpoints to deliver high quality patient care. Check out the other healthcare related stories in this issue on <a href="http://www.symantec.com/ciodigest/article2.jsp?aid=jan12_cover">Barnabas Health</a> and the <a href="http://www.symantec.com/ciodigest/article2.jsp?aid=jan12_cover">Italian National Cancer Institute</a>.<br /> &nbsp;<br /> Products referenced in healthcare feature:</p> <ul> <li>Altiris Asset Management Suite</li> <li>Altiris IT Management Suite</li> <li>Altiris Client Management Suite</li> <li>Altiris Server Management Suite</li> <li>PGP Universal Gateway Email</li> <li>PGP Whole Disk Encryption</li> <li>Symantec Data Loss Prevention</li> <li>Symantec DeepSight Threat Management System</li> <li>Symantec Endpoint Encryption</li> <li>Symantec Network Access Control</li> <li>Symantec Protection Suite&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<br /> -&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Symantec Endpoint Protection<br /> -&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Symantec AntiVirus for Endpoint Security</li> <li>Symantec Validation and Identity Protection (VIP)</li> <li>VeriSign Secure Site SSL Certificate with Extended Validation</li> </ul> <div class="og_rss_groups"><ul class="links"><li class="og_links first last"><a href="/connect/groups/healthcare-online-group"><span>Healthcare Online User Group</span></a></li> </ul></div> http://www.symantec.com/connect/blogs/4-tips-combat-uncommon-cold#comments Security Security Community Blog Data Loss Prevention (Vontu) Endpoint Encryption Endpoint Protection (AntiVirus) Network Access Control PGP Universal Servers and KMS Symantec Protection Center (SPC) Web Gateway Healthcare Online User Group Mon, 30 Jan 2012 18:37:23 +0000 Ctrox 2103601 at http://www.symantec.com/connect Test your password : Password Security Scanner http://www.symantec.com/connect/blogs/test-your-password-password-security-scanner <p>Password Security Scanner is a free password tool that allows to test the security of passwords stored locally. This utility scans all passwords stored by popular Windows applications, and the result is a detailed information of every stored password such as total number of characters, number of numeric characters, number of lowercase/uppercase characters, number of repeating characters, and password strength is displayed, without revealing the actual passwords.</p> <p> You can use this tool to determine whether the passwords used by other users are secured enough, without watching the passwords themselves.</p> <p><img alt="" src="/connect/imagebrowser/view/image/2096661/_original" /><br /> &nbsp;</p> <p><strong>Supported applications</strong> :</p> <ul> <li>&nbsp;&nbsp;&nbsp; Internet Explorer 4.0 - 9.0</li> <li>&nbsp;&nbsp;&nbsp; Mozilla Firefox (All Versions)</li> <li>&nbsp;&nbsp;&nbsp; Dialup/VPN passwords of Windows</li> <li>&nbsp;&nbsp;&nbsp; MSN/Windows Messenger</li> <li>&nbsp;&nbsp;&nbsp; Microsoft Outlook</li> <li>&nbsp;&nbsp;&nbsp; Windows Live Mail</li> </ul> <p> Password Security Scanner is a portable application and doesn&#39;t require any installation process.</p> <p> <strong>System requirements</strong> : from Windows 2000 and up to Windows 7.</p> <p> <strong>Link </strong>: <a href="http://www.nirsoft.net/utils/password_security_scanner.html">Password Security Scanner</a>&nbsp;&nbsp;</p> <div class="og_rss_groups"></div> http://www.symantec.com/connect/blogs/test-your-password-password-security-scanner#comments Security Security Community Blog Wed, 25 Jan 2012 12:07:06 +0000 riva11 2096671 at http://www.symantec.com/connect