Google security researcher says Sophos antivirus is not safe

Posted on Wednesday, Nov 07 2012 @ 18:08 CET by Thomas De Maesschalck
Google logo
Google security engineer Tavis Ormandy speaks out against Sophos in a 30-page analysis called "Sophail: Applied attacks against Sophos Antivirus". In the report, Ormandy details several flaws in the antivirus software caused by "poor development practives and coding stanards". The security researcher advises companies to stay away from Sophos software, unless Sophos can avoid easy mistakes and issue patches faster. Full details at CSO.
One of the exploits Ormandy details is for a flaw in Sophos‘ on-access scanner, which could be used to unleash a worm on a network simply by targeting a company receiving an attack email via Outlook. Although the example he provided was on a Mac, the “wormable, pre-authentication, zero-interaction, remote root” affected all platforms running Sophos.

Ormandy released the paper (PDF) as an independent security researcher and concludes: “[I]nstalling Sophos Antivirus exposes machines to considerable risk. If Sophos do not urgently improve their security posture, their continued deployment causes significant risk to global networks and infrastructure.”

The Google security engineer courted controversy two years ago after he released attack code for a Microsoft Windows XP bug just five days after reporting it to Microsoft. He appears to have made no such error this time, giving Sophos two months to fix the flaws.

About the Author

Thomas De Maesschalck

Thomas has been messing with computer since early childhood and firmly believes the Internet is the best thing since sliced bread. Enjoys playing with new tech, is fascinated by science, and passionate about financial markets. When not behind a computer, he can be found with running shoes on or lifting heavy weights in the weight room.

Loading Comments