Skip to main content

Tavis Ormandy slams Sophos security

posted onNovember 7, 2012
by l33tdawg

Google security engineer Tavis Ormandy claims that Sophos anti-virus has a number of serious security flaws and should be kept away from important computer systems.

Ormandy claims that Sophos needs to avoid easy mistakes and issue patches faster.

In a 30-page analysis with the catchy title "Sophail: Applied attacks against Sophos Antivirus", he listed several flaws "caused by poor development practices and coding standards". Sophos made matters worse by not responding quickly enough to the warning he had working exploits for those flaws. For example Sophos' on-access scanner could be used to launch a worm by targeting a company receiving an attack email via Outlook, he claimed.

Source

Tags

Sophos Security Google

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th