[NT] Norton Local Registry Protection Bypass (SuiteOwners)



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Norton Local Registry Protection Bypass (SuiteOwners)
------------------------------------------------------------------------


SUMMARY

Norton applications protect their own registry keys against actions by
other applications.

The protection can be bypassed for the SuiteOwners key, allowing to load
malicious DLLs.

DETAILS

Vulnerable Systems:
* Norton Personal Firewall 2006 version 9.1.0.33
* Other versions of Norton Personal Firewall 2006 and Norton Internet
Security 2006 suspected.

Norton protects its own registry keys against actions of other
applications. This protection can be bypassed for registry key
'HKLM\SOFTWARE\Symantec\CCPD\SuiteOwners' using API functions RegSaveKey
and RegRestoreKey. This registry key is also used to store some important
information such us names of libraries, for example 'NISProd.dll'. Using
RegSaveKey and RegRestoreKey a malicious application can modify values in
'SuiteOwners' such that Norton loads fake library into its own processes.
A malicious code in the fake library can manipulate any Norton component
and thus bypass every security protection of Norton.

Disclosure Timeline:
* 2006-08-21: Candidate for inclusion in the CVE list
* 2006-08-21: Vulnerability confirmed by popular information sources
* 2006-08-15: Advisory released
* 2006-08-15: Vendor notification


ADDITIONAL INFORMATION

The original article can be found at:
<http://www.matousec.com/info/advisories/Norton-DLL-faking-via-SuiteOwners-protection-bypass.php> http://www.matousec.com/info/advisories/Norton-DLL-faking-via-SuiteOwners-protection-bypass.php



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: Errors in Outlook Express since Windows Update April 2007
    ... When you installed NIS 2007, did you accept the option to make NIS the default Security Center, overriding the Windows Security Center? ... Norton AntiVirus Auto-Protect scans incoming files as they are saved to your hard drive, ... To make sure that Auto-Protect is providing the maximum protection, keep Auto-Protect enabled and run LiveUpdate regularly to ensure that you have the most recent virus definitions. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: ghostly mail ports
    ... Norton runs a proxy service for pop and smtp. ... Astaro Security Linux -- firewall with Spam/Virus Protection ...
    (Security-Basics)
  • Re: Norton Internet Security 25% off
    ... Windows security holes shielded ... Includes Norton Anti-Virus ... parental controls offer additional protection. ...
    (comp.os.linux.misc)
  • Re: After SP2 software will not work; Norton dragging their feet--a lot!
    ... reports of Live Update now downloading the proper fix so the Norton Internet ... Security 2004 is now compatible with SP2, ... Microsoft Windows MVP/Tablet PC ...
    (microsoft.public.windowsxp.customize)
  • Re: Some mail opens a blank page
    ... YW, Dan, and thanks again for your valuable feedback. ... Save that download link and Product or User ID for CA Internet Security ... and then run the Removal Tool to rid the machine of all Norton crapware. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)