Skip to main content

BlackICE security vulnerability discovered

posted onFebruary 11, 2002
by hitbsecnews

Source: AP

A programming mistake in a popular consumer Internet protection program can give hackers control over a user's computer, the publisher disclosed Friday.
All current versions of BlackICE Defender and BlackICE Agent, both made by Atlanta-based Internet Security Systems, running on Microsoft Windows 2000 and Windows XP are vulnerable to the attack.

The company released an update Friday evening that plugs the hole. It can be downloaded through the ISS Web site, or through the program itself.

Researchers at eEye Digital Security in Aliso Viejo, Calif., found the problem while probing a related hole in the product discovered earlier this week that lets hackers shut down the target computer. The patch fixes both problems.

BlackICE is designed to protect home computers - particularly ones with high-speed connections - from hacker attacks. Market researcher IDC recently named Internet Security Systems as the worldwide leader in intrusion detection products.

The problem, known as a "buffer overflow," is deep within BlackICE, said eEye's "Chief Hacking Officer," Marc Maiffret.

"It's basically the worst you can get," Maiffret said. "It lets you bypass any sort of protection that might be there."

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th