[DISCUSSION] Symantec Endpoint Protection

Discussion in 'Application Software' started by CHEF-KOCH, Dec 14, 2013.

  1. BetaTesta

    BetaTesta MDL Member

    Aug 6, 2022
    180
    57
    10
  2. uber_stud_87

    uber_stud_87 MDL Novice

    Dec 25, 2012
    5
    2
    0
    #1522 uber_stud_87, Mar 20, 2023
    Last edited: Mar 20, 2023
    Those by @sorgthomas are the same.

    File: Symantec_Endpoint_Protection_14.3.0_RU6_b9210_Win64-bit_Client_EN.exe
    SHA256: 8dc1f9665c9c70ff08472827415f73f81b2c77ba67fff7ad8a24a7704694a349

    File: Symantec_Endpoint_Protection_14.3.0_RU6_Refresh_Win64-bit_Client_EN.exe
    SHA256: 8dc1f9665c9c70ff08472827415f73f81b2c77ba67fff7ad8a24a7704694a349
     
  3. cetipabo2

    cetipabo2 MDL Member

    Feb 8, 2015
    240
    50
    10
  4. sorgthomas

    sorgthomas MDL Novice

    Feb 3, 2014
    38
    32
    0
    Hello.
    Try again.
    It works
     
  5. ceo54

    ceo54 MDL Addicted

    Aug 13, 2015
    867
    361
    30
    Does this Anti-Virus software has real time protection against the malware that comes from plugging in the USB ?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. DLord

    DLord MDL Novice

    Aug 17, 2012
    33
    15
    0
    yes
     
  7. ceo54

    ceo54 MDL Addicted

    Aug 13, 2015
    867
    361
    30
    Thank you for the response.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  8. BetaTesta

    BetaTesta MDL Member

    Aug 6, 2022
    180
    57
    10
    #1532 BetaTesta, Mar 28, 2023
    Last edited: Mar 28, 2023
    Odd this version 14.3.9205.6000 is not included on such list
    s.png
    Btw server is having download issues cause I cannot download Symantec_Endpoint_Protection_14.3.0_RU6_Win64-bit_Client_EN.exe
     
  9. Sajjo

    Sajjo MDL Member

    Feb 6, 2018
    2,245
    3,258
    90
    @BetaTesta

    A mystery inside an enigma
    Give a few days and Broadcom may update their list
    14.3.9205.6000 is maybe redacted as well (for unknown reasons) - who knows
    I didn't know there was a 14.3.8289.5000 of RU5 - last release to run on x86 :cool:

    Thanks for pointing out
    :)
     
  10. Ray Willis

    Ray Willis MDL Junior Member

    Apr 15, 2015
    58
    45
    0
    Release New Version
    14.3 RU7 14.3.9681.7000 March 24th, 2023 :)
     
  11. Digital01

    Digital01 MDL Novice

    Jan 8, 2020
    16
    1
    0
  12. BetaTesta

    BetaTesta MDL Member

    Aug 6, 2022
    180
    57
    10
  13. Steelhead2

    Steelhead2 MDL Novice

    Dec 29, 2012
    7
    25
    0
    In my opinion, because MDL is a users forum, one of its primary purposes should be to promote good computer "hygiene" practices. To me, this means, in part, to encourage users to engage in practices that minimize the possibility of spreading malware. In other words, whenever possible, support the use of software (especially antivirus software) that mitigates the likelihood of installing software that compromises one's machine and minimizes the risk of spreading malware to others.

    In the case of anti-virus software, which is one of our first lines of defense against malware, it makes unimpeachable sense to me to only install on one's machine software that has been released by the manufacturer and is digitally signed so that its integrity is assured.

    When Broadcom distributes a new update to Symantec Endpoint Protection (SEP), it does so as a compressed, digitally signed, executable file. Broadcom appears to like the convention of referring to its files as having a "fingerprint" to demonstrate their validity.

    The most current release of SEP is reported by Broadcom at:

    h**ps://knowledge.broadcom.com/external/article/154575/versions-system-requirements-release-dat.html

    Here one finds that the most recent release of SEP is:

    Symantec_Endpoint_Protection_14.3.0_RU7_Win64-bit_Client_EN.exe

    This refers to Release Name - 14.3 RU7
    Version (build number) - 14.3.9681.7000
    Release Date - March 24, 2023

    Like previous versions, this latest version of SEP is both compressed and digitally signed; it is distributed by Broadcom as a 7-zip executable file. When executed, this extracts itself into a temporary file, executes the Setup file, and then clean-ups after the install is complete.

    So, what could possibly be the motivation for someone to extract this signed file and then re-compress it into another format such as the typically found *.rar format? Certainly there is no download benefit to the end user because the original file from Broadcom was already compressed. Furthermore, by extracting the original file and then re-compressing it, the digital signature information from Broadcom is lost. And, who knows whatever other changes may have been made to Broadcom's original executable?

    Regardless of how reputable the distributor is, there is simply no good reason to unpack the original Broadcom distribution file and there is no good reason for the end user to assume the risk of installing an antivirus program of unknown provenance.

    The point of my argument is simple: the integrity and authenticity of the re-compressed file is unknown because the digital signature from Broadcom has been lost. Consequently, a person who uses a re-compressed SEP antivirus program file of unknown provenance places their computer at risk of being compromised.

    I think the way forward is clear - don't do it. Wait until the digitally signed file from Broadcom is available.
     
  14. BetaTesta

    BetaTesta MDL Member

    Aug 6, 2022
    180
    57
    10
    Could you share Stranger1784's post or thread at ru-board please?