Google security researcher: Keep Sophos away from high value systems


Recommended Posts

Google security engineer Tavis Ormandy discovered several flaws in Sophos antivirus and says the product should be kept away from high value information systems unless the company can avoid easy mistakes and issue patches faster.

Ormandy has released a scathing 30-page analysis ?Sophail: Applied attacks against Sophos Antivirus?, in which he details several flaws ?caused by poor development practices and coding standards?, topped off by the company?s sluggishly response to the warning he had working exploits for those flaws.

One of the exploits Ormandy details is for a flaw in Sophos? on-access scanner, which could be used to unleash a worm on a network simply by targeting a company receiving an attack email via Outlook. Although the example he provided was on a Mac, the ?wormable, pre-authentication, zero-interaction, remote root? affected all platforms running Sophos.

Ormandy released the paper (PDF) as an independent security researcher and concludes: ?nstalling Sophos Antivirus exposes machines to considerable risk. If Sophos do not urgently improve their security posture, their continued deployment causes significant risk to global networks and infrastructure.?

http://www.cso.com.a..._value_systems/

sophailv2.pdf

And, in fact, do a search if your favorite security suite has been cracked/activation-bypassed or otherwise defeated by warez release groups. And then keep away from it and demand your money back, if possible. It's useless. There aren't many left these days, but they do happen. If warez people could pwn it, somebody with more evil intentions can and will do it as well, and you just might happen to be in the middle of it.

I am a sophos partner and this concerns me greatly how they've declined. I will have a talk with them about this. I am pretty irritated at all these issues....

I am a sophos partner and this concerns me greatly how they've declined. I will have a talk with them about this. I am pretty irritated at all these issues....

remixedcat,

I would be very interested in hearing what they say to you on this. I couldn't see an official response on their site to this when I looked last night. I have their enterprise console out in a few places too.

remixedcat,

I would be very interested in hearing what they say to you on this. I couldn't see an official response on their site to this when I looked last night. I have their enterprise console out in a few places too.

I will be contacting them shortly...

sophos contacted.... awating response..

Thanks, I would hope that they will get independent verification of their assertion that these were fixed circa September and have some sort of statement prepared to show changes in their development process. If they do that I see no need to switch and compliment Google for giving them lead-time.

Edit: I just checked the main console and it seems that 10.2 doesn't automatically apply on rollout if you have your update manager configured to 10.x recommended. The Mac's have gone to 8.0.8.1 automatically though. So don't forget to check your update manager configs!

You're welcome... I got a response so far... will get a more detailed one later:

Hello Liz ,

Thank you for your email and taking the time to share with us the concerns you have.

Below is some information you may want to review .

Sophos has written about his findings on Naked Security http://nakedsecurity.sophos.com/2012/11/05/tavis-ormandy-sophos/

We have forwarded your email to the proper Sophos Team . They will be

the best suited to address the questions and concerns you have.

They will be reviewing the email and questions to determine the best source of action and

provide you with the correct information .

Again, thank you for notifying us of the concerns you have so that we can ensure that they are addressed for you.

Let us know if you need any further assistance.

All the best .

Regards,

got another response from Sophos:

Thanks for reaching out with this.

We most definitely appreciate Mr. Ormandy?s work with Sophos.

We can only get better with independent work like his.

As a security company, keeping customers safe is our primary responsibility. As a result, we periodically receive third party reports about areas of our products and those of other software companies. We welcome this scrutiny and are committed to investigating all vulnerability reports and implementing the best course of action in the quickest time period.

You can find our fixes and rollouts for the flagged bugs here:

http://www.sophos.com/en-us/support/knowledgebase/118424.aspx

For the updater issues, please take a look at this article which explains the root causes and how we?ve updated our solutions and procedures to prevent this from occurring in the future.

http://www.sophos.com/en-us/support/knowledgebase/shh-root-cause-analysis.aspx

Although this is not a an excuse, false positive updates are a reality that have hit every single major security company out there including McAfee, Symantec, and Trend.

It is also important to note that no serious security company can claim that their software protects everything. Threats are always evolving and changing and it is up to us to change and grow with the times.

With respect to Mr. Ormandy, he has indicated that he has not reviewed any other security software with this examination. I suspect that if he were to review other solutions his results would be quite similar and in most cases much more revealing.

Let me know if you need any other help on this.

I?ll be glad to provide any further assistance.

Take care.

remixedcat,

Thanks for coming back with that, it is exactly what I wanted (expected) to hear.

I had Anti-Virus 10.0.9 / 8.0.8.1 out already and Anti-Virus 10.2.1 went out over night. The knowledge base links were quite useful.

Sure, I haven't been presented with any reason to approach management and say that there is a problem that looks like it will undermine the security of the network or of users.

Mistakes and bugs happen in software development; reactionist responses about flocking to a competitor in the face of them just aren't helpful or realistic when you have spent out for site licenses. If their response had been anything else (i.e. "we *may* fix it in SAV11 after you re-license next year [but then again we may not]") or any attempt to downplay or spin it was used then after a threat assessment my response may have been different. In all honesty I find SAV Enterprise Console to be pretty tidy, yes there are a few limitations that I have issue over, but it works - and I prefer it to the likes of F-Secure's equivalent.

Also the thought of having to do a mobile device recall and changing Mac's to another vendor really doesn't appeal on the greater scheme of good uses of one's time :rofl: .

It looks like about 1/3 of my endpoints have picked up 10.2.0 or higher as of right now; about normal for a version change at this point. As usual there is one on the 4th floor that is refusing to update... they only do it because I'm on the ground floor *sigh*

:rolleyes:

Agreed. I did like their responses as well. They were also very prompt with the replies and I profusely thank them for it.

This topic is now closed to further replies.
  • Posts

    • Price Drop: Save 86% on Microsoft Office 2021 Professional Plus lifetime digital license by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where you can save 86% on a lifetime license to Microsoft Office 2021 for Windows. This bundle is for families and small businesses who want classic Office apps and email. It includes Word, Excel, PowerPoint, Outlook, Teams, and OneNote. A one-time purchase installed on 1 Windows PC for use at home or work. Lifetime license for MS Word, Excel, PowerPoint, Outlook, Teams, & OneNote One-time purchase installed on 1 Windows PC for use at home or work Instant Delivery & Download – access your software license keys and download links instantly Free customer service – only the best support! Microsoft Office Professional 2021 (for Windows) includes: Microsoft Office Word Microsoft Office Excel Microsoft Office PowerPoint Microsoft Office Outlook Microsoft Office Teams Microsoft Office OneNote Microsoft Office Publisher Microsoft Office Access No faffing about with subscriptions, just classic apps that don't expire. Good to Know ONE-TIME PURCHASE INSTALLED ON 1 DEVICE Redemption deadline: redeem your code within 30 days of purchase Access options: desktop Full versions No subscriptions – no monthly/annual fees Version: 2021 Updates included* *Support for this version of Office ends on Oct 13, 2026 A lifetime subscription to Microsoft Office 2021 Professional normally costs $219.99, but this deal can be yours for just $29.97, that's a saving of $190. For full terms, specifications, and license info, click the link below. Get Microsoft Office Professional 2021 for just $29.97, or learn more Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • The only reason I want to know where you from is because if you are not from the U.K, then why should you care what we in the U.K do or don't do? Racist I am not, I am fed up with the amount coming over here and feel they can come over here and think we need to support them. Do you know how much it costs this country to support these people coming over here? Even when we give them a place to live it is not good enough. We had a barge that was being used to house immigrants, oh but that was not good enough. A mate said to me at the time, when he was homeless, he would have been happy to live on the barge, instead of ending up sleeping on a bench on the beach. I am not scared to say what my family heritage is, unlike you who is scared to say where they are from or where they live. Father side U.S, mother side Wales, still have family living in the U.S. A mate who sadly died a few years ago, had a load of people from different races recording in his studio, I got on with all of them. Skin colour don't bother me, where they are from don't bother me. Religion don't bother me as long as they don't push it onto me and it is not crazy stuff. I am not religious. But if you are not living in the U.K, then why should you care if we are in the E.U or not? This the problem, too many people poking their noses into where it don't belong. But you believe what you believe, if you think I am racist, then be it, I really do not care. Just grow a pair
    • If he hasn't been able to figure that out, then why is he obsessed with tariffs? Because that's one of the most prominent tools to level the playing field when you have high cost of labor.
    • Microsoft released Windows 11 KB5102558, KB5095615 Setup and Recovery updates by Sayan Sen This past week Microsoft released the newest preview update (C-release) under KB5095093. Alongside those, Microsoft also released new dynamic updates. For those who may not know, dynamic updates bring improvements to the Windows Recovery process in the form of Windows Recovery Environment (WinRE) updates, which are also called Safe OS updates. The dynamic updates also affect the Setup file binaries in the form of Setup updates. These Dynamic Update packages are meant to be applied to existing Windows images prior to their deployment. Dynamic Updates also help preserve Language Pack (LP) and Features on Demand (FODs) content during the upgrade process. VBScript, for example, is currently an FOD on Windows 11 24H2. This time both recovery and setup updates were released for Windows 11. The company writes: "KB5095186: Safe OS Dynamic Update for Windows 11, version 26H1: June 23, 2026 This update makes improvements to the Windows recovery environment (WinRE). After installing this update, the WinRE version installed on the device should be 10.0.28000.2335. KB5102558: Setup Dynamic Update for Windows 11, versions 24H2 and 25H2: June 23, 2026 This update makes improvements to Windows setup binaries or any files that setup uses for feature updates in Windows 11, version 24H2 and Windows 11, version 25H2. KB5095615: Safe OS Dynamic Update for Windows 11, versions 24H2 and 25H2: June 23, 2026 This update makes improvements to the Windows recovery environment (WinRE). After installing this update, the WinRE version installed on the device should be 10.0.26100.8737." Microsoft notes that both the Recovery and Setup updates will be downloaded and installed automatically via the Windows Update channel.
  • Recent Achievements

    • Conversation Starter
      jessse3334 earned a badge
      Conversation Starter
    • Reacting Well
      JuvenileDelinquent earned a badge
      Reacting Well
    • One Month Later
      Excellence2025 earned a badge
      One Month Later
    • Week One Done
      Excellence2025 earned a badge
      Week One Done
    • Week One Done
      flexorcist earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      201
    3. 3
      PsYcHoKiLLa
      151
    4. 4
      Steven P.
      73
    5. 5
      macoman
      62
  • Tell a friend

    Love Neowin? Tell a friend!