| Mime-Version: |
1.0 |
| Content-Type: |
text/plain; charset=US-ASCII |
| Date: |
Thu, 5 Jan 2006 14:46:56 -0500 |
| Content-Disposition: |
inline |
| Reply-To: |
|
| Subject: |
|
| From: |
|
| In-Reply-To: |
|
| Content-Transfer-Encoding: |
7bit |
| Sender: |
|
| Parts/Attachments: |
|
|
This thread may be a bit stale, but I resurrected it due to reports
regarding the WMF issue. The organization A-V Test ran a test yesterday
on various A/V products to see how they fared against WMF exploits.
I've included the results below. F-Prot, among others, did poorly.
But that was yesterday; by today they may have gotten up to speed too.
We use Symantec A/V, Enterprise Ed. (v. 8.1) here in Montpelier. We
are generally pleased with its effectiveness and management features,
but I won't argue that there aren't more cost-effective solutions out
there. Neither will I argue that Symantec doesn't put a dent in
resources, but, in our case, the dent hasn't been significant enough to
be concerned with. I guess we are lucky to have fairly recent equipment
in our crucial locations that can take the hit in stride.
I will mention though that we have had huge performance problems with
PC's that were not successfully updated to the 8.x A/V engine. Some
machines slipped through the cracks during the upgrade and retained the
7.x version. Those machines were slowed to a crawl by the updated
definitions (I guess). Whatever the actual cause, updating the engine
fixed the problem immediately.
Vince
=============================================================
Test results
AV-Test took a range of antivirus products and ran 206 malicious files
that exploit the unpatched WMF flaw through them. Some of the products
have holes, it turned out. These products detected all the malicious
files:
* BitDefender
* Computer Associates eTrust-VET
* F-Secure
* Kaspersky Lab
* McAfee
* Eset Nod32
* Microsoft OneCare
* Sophos
* Symantec
These missed just one file:
* Alwil Avast
* Clam AntiVirus
* Aladdin eSafe
These tools missed a number of samples (total in parentheses):
* Fortinet (18)
* AntiVir (24)
* eTrust-INO (25)
* Panda (25)
* Ikarus (26)
* Norman (26)
* Ewido (47)
* AVG (59)
* VirusBuster (61)
* QuickHeal (63)
* Trend Micro (63)
* Dr Web (93)
* VBA32 (110)
* Authentium Command (119)
* F-Prot (119)
|
|
|