• Todas as comunidades
    • Todas as comunidades
    • Fóruns
    • Idéias
    • Blogs
Avançado

O que você está procurando? Pergunte a um especialista!

This forum thread needs a solution.
Kudos1 Stats

Norton Core allows remote access without challenge

I have some serious issues with Norton Core allowing remote access to its Admin functions and allowing remote connections to devices on my private network below are my concerns.

1. From my cell phone I could connect to my Western Digital NAS from external location. The Core device allowed a connection with out any setup or challenge. For 25 years I worked in Network Security and this counter to any rational reason to allow admin access to a private network without a proper challenge.  I was able to prohibit the access on the NAS device.

2. I discovered I could access my Norton Core router device with no challenge. This is not acceptable please review.  I would ask you as a InfoSec provider, do you allow you staff access to your central firewall and routers from their cell phones without a password challenge?

3. In my opinion a cell phone, I-pad, or tablet are the least secure devices in the todays world.

For the most part I like the Norton Core device, but beef up the security.  I am seriously thinking of putting a firewall between the Core device and Internet. Also you need to provide a syslog function.

Thanks

John Allen

(Updated subject - Admin.) 

Respostas

Kudos0

Re: Norton Core allows remote access without challenge

Is this the phone you used to set up the Core? If so, it is probably assumed that if you can administer the device you can access its resources.

I still agree with you that there should at least be an option to require authentication of subsequent access, especially if you are not on the local network.

Things happen. Export/Backup your Norton Password Manager data.
Kudos0

Re: Norton Core allows remote access without challenge

The Core recognizes the NAS as a NAS and probably expects it to be accessed remotely as that's what they do.  The server accessing the NAS is probably a known/trusted server/system with Norton.  I mean really.  I have a Seagate NAS and it would make sense that the Seagate NAS servers might communicate with it.

Kudos0

Re: Norton Core allows remote access without challenge

if a NAS device communicates thru a Firewall than it is no longer a NAS it is a file server and therefore more security should be built around it. 

Kudos0

Re: Norton Core allows remote access without challenge

The user should have full control around who has access and from where.

Kudos0

Re: Norton Core allows remote access without challenge

Does anyone from Norton read these issues?

Kudos0

Re: Norton Core allows remote access without challenge

JohnDAllen:

Does anyone from Norton read these issues?

How was it set up with your previous router? Is remote access via a simple port forward or have you made no changes to the Norton "core" router?

Kudos0

Re: Norton Core allows remote access without challenge

I have made no changes to the Norton Core Router to either deny or allow remote access.  Previous routers would not allow remote access to my network unless I made a rule to allow it.

Kudos0

Re: Norton Core allows remote access without challenge

JohnDAllen:

I have made no changes to the Norton Core Router to either deny or allow remote access.  Previous routers would not allow remote access to my network unless I made a rule to allow it.

The same should hold true for the "core" router. Explain the details of how you are seeing this remote access being possible.

Kudos0

Re: Norton Core allows remote access without challenge

Well this is what I did, while sitting in a restaurant about 15 miles from my house I accidently touched the icon for my NAS device and it displayed all my files with no challenge, then I touched my Norton Core icon and there on display with full access was my admin screen.  I was never able to access my devices from any were with my other routers without specific rules to allow access and at least a password challenge. I was able to change my NAS to deny access.

Kudos0

Re: Norton Core allows remote access without challenge

I assume you were signed into the Norton Core App.  You can sign out by clicking the menu button, selecting your account name at the top of the list, and scrolling down to the "Sign Out" button.

Kudos0

Re: Norton Core allows remote access without challenge

Thanks never knew that. I guess old people can still learn. Norton should sign you out when you exit the application like most web apps?  I just don't think my phone is the way to manage my network. 

Kudos0

Re: Norton Core allows remote access without challenge

Norton Core is brand new - we're all learning together!  Symantec included, I think.

Kudos0

Re: Norton Core allows remote access without challenge

They should have spent more time talking to real users. I still like their products, just wish they had warned me I would be a beta tester. This morning I woke up to my phone warning me that our network was being compromised, could not access any device so made my way to the router and it was flashing, I almost unplugged it but it quit, and I got a message on my phone that all was well, then a  message from the core router that an update was successful. It would of been nice if they had sent me the message earlier that they were going to push an update. I'm to old for this stuff.  Spent over 40 years in InfoSec, thought I could retire.  "Ha Ha"

This thread is closed from further comment. Please visit the forum to start a new thread.