Symantec expects Anonymous to publish more stolen source code

Confirms that BitTorrent file is pcAnywhere's source code after sting operation fails
  • Gregg Keizer (Computerworld (US))
  • — 08 February, 2012 06:12

Symantec today confirmed that the pcAnywhere source code published on the Web Monday by hackers who tried to extort $50,000 from the company was legitimate.

A company spokesman also said that Symantec expects that the rest of the source code stolen from its network in 2006 will also be made public.

Symantec's acknowledgement followed the appearance late Monday of a 1.3GB file on various file-sharing websites, including Pirate Bay, that claimed to be the source code of the pcAnywhere remote-access software.

Download activity for the BitTorrent file has been moderately brisk: As of mid-morning Tuesday, Pirate Bay identified 376 "seeders," the term for a computer that has a complete copy of the file -- and about 200 "leechers," or computers that have downloaded only part of the complete torrent.

The Anonymous hacking group claimed responsibility for posting the pcAnywhere source code.

"We can confirm that the source code is legitimate," said Cris Paden, a spokesman for Symantec, in an email reply to questions. "It is part of the original cache of code for 2006 versions of the products that Anonymous has claimed to have been in possession during the last few weeks."

Also on Monday, an individual or group going by the name "Yama Tough" had published a series of emails on Pastebin that detailed an attempt to extort $50,000 from Symantec.

Previously, Yama Tough had claimed responsibility for stealing the source code to pcAnywhere and other Symantec security software. At one point, Yama Tough had threatened to publish the source code, but then recanted.

The Pastebin-posted emails covered negotiations between Yama Tough and someone identified as "Sam Thomas," supposedly a Symantec employee, over payment for not disclosing the source code. In fact, Thomas was a pseudonym used by U.S. authorities, whom Symantec had alerted to the threat.

"In January, an individual claiming to be part of the 'Anonymous' group attempted to extort a payment from Symantec in exchange for not publicly posting stolen Symantec source code they claimed to have in their possession," said Paden. "Symantec conducted an internal investigation into this incident and also contacted law enforcement, given the attempted extortion and apparent theft of intellectual property. The communications with the person(s) attempting to extort the payment from Symantec were part of the law enforcement investigation."

Paden declined to identify the law enforcement agency, but the Federal Bureau of Investigation (FBI) has jurisdiction in extortion attempts that affect foreign or interstate commerce.

The negotiations went on for nearly a month -- the emails began on Jan. 18 -- but broke down when Yama Tough rejected Thomas' conditions, which included an offer of payments of $2,500 each month for the first three months, with the balance to be paid on proof that the copy of the stolen source code had been destroyed.

Yama Tough tried to spin a different story on Twitter.

"They've been tricked trolled into offering a bribe so the false statement be [sic] made we never had the code and lied =)," Yama Tough said yesterday in a tweet .

Symantec's Paden also said today that it expects Anonymous to shortly publish source code belonging to other products.

"We also anticipate Anonymous to post the rest of the code they have claimed have in their possession," Paden said. "So far, they have posted code for the 2006 version of Norton Internet Security and pcAnywhere. We also anticipate that at some point, they will post the code for Norton Antivirus Corporate Edition and Norton SystemWorks. Both products no longer exist."

Yama Tough promised that the source code for Norton Antivirus (NAV) Corporate Edition would hit the Web today. "NAV release coming in seven hours," Yama Tough said on Twitter about six hours ago.

Two weeks ago, Symantec took the unprecedented step of telling users of pcAnywhere to disable or uninstall the software until it could finish patching vulnerabilities it had uncovered. Symantec wrapped up that patching last week, and gave the all-clear to customers .

Symantec has also offered free upgrades to pcAnywhere 12.5 for users of editions prior to version 12.0.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer , on Google+ or subscribe to Gregg's RSS feed . His e-mail address is gkeizer@computerworld.com .

See more articles by Gregg Keizer .

Read more about cybercrime and hacking in Computerworld's Cybercrime and Hacking Topic Center.

Tags: anonymous, bittorrent, Cybercrime and Hacking, pirate bay, security, Security Hardware and Software, symantec

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CSO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
CSO Corporate Partners
  • FirEye
  • Clear Swift
  • Trend Micro
  • Sophos
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Identity & Access Management

Why choose NetIQ for Identity and Access Management

Security Awareness Tip
Software security company www.clearswift.com gives some advice this holiday season to make sure employees don’t end up on Santa’s naughty list!


At a fundamental business level, social media is a useful additional tool for communicating and collaborating with customers, colleagues and new business prospects. From an HR point of view, the social web is not only useful for recruitment but also as a knowledge network. At an employee level, social media is changing the way we work: Employees increasingly expect to be able to access personal technology and services in the workplace. As the lines between work and home life blur, staff are looking for greater flexibility in their roles; working from home is an increasing trend, but so too is ‘home-ing from work’, where staff expect to be able to perform personal tasks at work.

But social media brings risk and reward to business in equal measure. Information security is a key concern: Many organisations view social media channels as yet another route along which sensitive data can escape from the business, whether accidentally or maliciously. On top of this, senior management may be concerned about the amount of time employees spend on social networks.

This cultural shift raises new questions about trust in the workplace, the balance of power in employer / employee relationship and levels of control over people and content.


Organisations using content and web security technology can manage the way their staff use email and the internet without having to resort to a default position of mistrust. With a whopping third of ANZ employers completely blocking social media access at work, there’s a real danger of throwing the benefits of collaboration out with the risks.


It doesn’t have to be that way.

Trust breeds responsibility: People underestimate the amount of company time they spend on personal browsing. Allow staff to view their own web usage and foster more responsible behaviour without undermining trust.


Know limits: Set clear limits on personal surfing and communicate them to users. Alert them when they are approaching their limit. Help your people to play by the rules.


Share the load: Spread responsibility for usage reporting among managers and department heads so everyone gets to see how their usage impacts on the rest of the organisation. This also gives managers greater control and visibility into usage.


Need to know: Yes, you need reports and visibility. What you don’t need is employee data becoming common knowledge. Access control means reporting can be adjusted on a need-to-know basis.


Security ABC Guides

7 Ways to Protect Your Business Printers

Can a hacker burn down your business by remotely setting one of your printers on fire? Researchers at Columbia University have recently proposed such a scenario, although HP quickly denied that it's possible. However, even if your printers can't be used as remote firestarters, there are many risks involved in networking a printer.