Skip to content

ESET榮獲AV-Test最佳產品獎,以表彰最佳Windows防病毒軟件

BRATISLAVA – ESET, a global leader in cybersecurity, has been commended with Top Product awards in the latest AV-TEST Product Review and Certification reports in both the business and home consumer categories. ESET Endpoint Security 7.3 and ESET Internet Security 13.2 – ESET  security products for Windows in the business and consumer lineups, respectively – achieved Top Product awards with perfect Protection and Usability scores in the August and October 2020 tests.

AV-TEST, a leading independent testing organization, uses one of the largest collections of malware samples in the world to create a real-world environment for highly accurate in-house testing and realistic test scenarios.

The tests evaluated the best Windows antivirus software for both home and business users, with all vendors being assessed across three main categories: Protection, Performance and Usability. In both the consumer and business evaluations, ESET’s solutions scored a perfect 6 in the Protection category, which measures the protection against malware such as viruses, worms and Trojan horses, and a perfect 6 in the Usability category, which measures the impact of the security software on the usability of the computer. Both solutions also scored near-perfect scores of 5.5 in the Performance category, which measures the impact of the product on computer speed in daily usage.

In addition to the excellent results, this past summer ESET received its 100th AV-Test certificate – this milestone marks ten years since ESET achieved its first certificate from AV-Test in June 2010.

Roman Kováč, Chief Research Officer at ESET, commented, “It is extremely encouraging not only to continue to receive commendations for our home and business security solutions, but also to be recognized for ten years of consistent and outstanding results in third-party testing. At ESET, we are extremely proud of our work in making technology safer. This recognition from AV-Test reaffirms that our solutions are proven to work in real-world scenarios. Businesses and home users can be confident that they are in safe hands with ESET. After a year like no other, it has never been more important for your sensitive information and data to be protected with advanced security software both at work and at home.”

Learn more about ESET’s home and business solutions for Windows here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

DNS軟體Dnsmasq含快取下毒(Cache Poisoning)漏洞,將影響數百萬台設備

開源的熱門DNS軟體Dnsmasq含有7個安全漏洞,包含快取下毒(Cache Poisoning)漏洞及遠端程式攻擊漏洞

DNS快取下毒的結果可將使用者導至偽造的網站,而且目的地可能遭到竄改的流量除了一般的網路瀏覽之外,也可能是電子郵件、遠端桌面、語音通訊或軟體更新,駭客亦有機會接管這些受害裝置,或展開服務阻斷攻擊。

約有40家業者採用Dnsmasq,其影響涵蓋了思科、華碩、AT&T、Comcast,西門子、戴爾、Linksys、高通、摩托羅拉及IBM等知名企業。此外,利用Shodan搜尋全球網路,也顯示公開網路上將近100萬臺Dnsmasq伺服器。

Dnsmasq含有7個安全漏洞,其中3個屬於快取下毒漏洞,相關的漏洞主要與Dnsmasq匹配查詢及回應的方式有關;另外4個則為緩衝區溢位漏洞,現身於準備DNSSEC資料以進行驗證的程式碼中,這些漏洞波及Dnsmasq 2.82及以前的版本。

這幾個安全漏洞本身都只會造成有限的影響,但若是彼此結合或以特定的方式串連,便能建置出非常有效的多階段攻擊,這是因為當成功攻陷上述其中一個漏洞時,就會更容易開採其它的漏洞,而且串連攻擊的風險極高。而Dnsmasq也已於上周釋出Dnsmasq 2.83供用戶更新,ESET資安專家提醒用戶應盡快更新。

原文出處:https://www.welivesecurity.com/2021/01/20/dnspooq-bugs-devices-dns-cache-poisoning/

#若有任何資安需求,歡迎洽詢台灣二版資安專業團隊,服務電話:(02)7722-6899,或上官網查詢:https://version-2.com.tw/

關於 Version 2 Digital
資安解決方案 專業代理商與領導者
台灣二版 ( Version 2 ) 是亞洲其中一間最有活力的 IT 公司,多年來深耕資訊科技領域,致力於提供與時俱進的資安解決方案 ( 如EDR、NDR、漏洞管理 ),工具型產品 ( 如遠端控制、網頁過濾 ) 及資安威脅偵測應 變服務服務 ( MDR ) 等,透過龐大銷售點、經銷商及合作伙伴,提供廣被市場讚賞的產品及客製化、在地化的專業服務。

台灣二版 ( Version 2 ) 的銷售範圍包括台灣、香港、中國內地、新加坡、澳門等地區,客戶涵 蓋各產業,包括全球 1000 大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企業及來自亞 洲各城市的消費市場客戶。

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟體提供商,其 獲獎產品——NOD32防病毒軟體系統,能夠針對各種已知或未知病毒、間諜軟體 (spyware)、rootkits和其他惡意軟體為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲 得了更多的Virus Bulletin 100%獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳 能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事 處,代理機構覆蓋全球超過100個國家。

ESET Internet Security被AV-Comparatives授予傑出產品獎

BRATISLAVA – ESET, a global leader in cybersecurity, has received recognition with an Outstanding Product Award in AV-Comparatives’ Public Consumer Main Test Series for 2020. ESET Internet Security was assessed by the leading independent test lab, achieving Advanced+ level in all of AV-Comparatives’ tests.

For the 2020 Public Consumer Main Test Series, AV-Comparatives subjected 17 consumer security products for Windows to rigorous investigation. Programs were tested for their ability to protect against real-world internet threats, identify recent malicious programs, defend against advanced targeted attacks, and provide protection without slowing down PCs.

As well as receiving an Outstanding Product Award, ESET Internet Security received the Gold Award for False Positives, producing just five false positives and scoring higher than any other solution. It also earned Silver Awards for Malware Protection and Advanced Threat Protection.

Reviewers of the software were impressed with the solution’s ease of use and its clean and easy-to-navigate interface. They also commended ESET Internet Security for the useful search function of its settings dialog and the range of advanced options, as well as its safe default settings. They noted that the real-time file system protection is sensitive and reacts very quickly when needed, and highlighted the “excellent” help features.

Commenting on the results, Matej Krištofík, Product Manager for Home Windows, said: “Here at ESET, we are dedicated to safeguarding consumers and their data, and this award is a testament to that commitment. To protect consumers across the globe from cyber-risks, technology must be easy to deploy and navigate, so we are very proud that ESET Internet Security has been recognized for its ease of use. With technology taking up more room in our lives than ever before, ESET balances cutting-edge protection with an intuitive interface, and these results reflect this.”

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

SCADAfence研究人員發現了ABB所有AC500 V2產品中的DoS漏洞

Our Researchers Discover Another Vulnerability 

As part of our mission to secure the world’s OT, IoT and Cyber Physical infrastructures, we invest resources into offensive research of vulnerabilities and attack techniques.

CVE-2020-24685 is a CVSS 8.6 (CVSS v3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H) remote CPU DoS vulnerability in all of ABB’s AC500 V2 products with onboard ethernet are affected by this vulnerability (with latest firmware v2.5.4) that has been discovered by SCADAfence researcher Yossi Reuven.

ABB is one of the world’s leading electronics and electrical equipment manufacturing companies (holding an overall share in the world DCS market of 19.2%), and is in use by many of our customers. 

About The Vulnerability – CVE-2020-24685

AC500 V2 Series is one of ABB’s PLC offerings – designed as a compact entry-level PLCs for small applications. AC500 V2’s communication with Automation Builder (Engineering software package) is done via ABB proprietary wrapper protocol encapsulation of CoDeSys SDE protocol (which works on both TCP and UDP). 

A single specially crafted packet sent by an attacker over the ABB protocol on port 1200 will cause a denial-of-service (DoS) vulnerability. The PLC’s CPU will get into fault mode, causing a hardware failure. The PLC then becomes unresponsive and requires a manual (physical) restart to recover. In addition, the buffer overflow condition may allow remote code execution.

What SCADAfence Recommends Asset Owners To Do

Perform an Industrial Vulnerability Management Process

Please refer to our guide on this topic: https://www.scadafence.com/public-preview-a-comprehensive-guide-to-industrial-device-patching/

Monitor for Unauthorized Network Activity and Exploitation

Some devices will always remain unpatched. Monitoring is an early warning system that allows you to act before attackers have gained full control over your network.

Upgrade to the Latest Firmware

ABB has developed a new firmware version 2.8.5 fixing this vulnerability. This firmware version is released for the following affected PLC types:
* PM573-ETH
* PM583-ETH

Currently no firmware update is available to other products in the AC500 V2 line. When ABB makes such a patch available, we recommend asset owners to consider upgrading.

Prevent Unauthorized and Untrusted Access

– Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.

– Use within a LAN and block access from untrusted networks and hosts through firewalls.

Special Thanks & Recognition

The SCADAfence Research team would like to thank the ABB team for the collaboration.

ABB has published the advisory and released a firmware update to part of the product line.

SCADAfence is committed to continued research of offensive technologies and development of new defensive technologies.

Exploit PoC

We wrote a Python POC (GPLv3) script of the exploit in action.

Currently, there’s no patch available. As a result, we limit the access to the exploit to vetted individuals only. The exploit is only available for educational and legal research purposes.

Warning: The script will crash the PLC’s CPU – do not use it in production.

To get this free python exploit, please send an email to research@scadafence.com, identify yourself and explain how you’re going to use the exploit. We reserve the right to refuse any request.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.

ESET榮獲AV-Test最佳產品獎,以表彰最佳Windows防病毒軟件

BRATISLAVA – ESET, a global leader in cybersecurity, has been commended with Top Product awards in the latest AV-TEST Product Review and Certification reports in both the business and home consumer categories. ESET Endpoint Security 7.3 and ESET Internet Security 13.2 – ESET  security products for Windows in the business and consumer lineups, respectively – achieved Top Product awards with perfect Protection and Usability scores in the August and October 2020 tests.

AV-TEST, a leading independent testing organization, uses one of the largest collections of malware samples in the world to create a real-world environment for highly accurate in-house testing and realistic test scenarios.

The tests evaluated the best Windows antivirus software for both home and business users, with all vendors being assessed across three main categories: Protection, Performance and Usability. In both the consumer and business evaluations, ESET’s solutions scored a perfect 6 in the Protection category, which measures the protection against malware such as viruses, worms and Trojan horses, and a perfect 6 in the Usability category, which measures the impact of the security software on the usability of the computer. Both solutions also scored near-perfect scores of 5.5 in the Performance category, which measures the impact of the product on computer speed in daily usage.

In addition to the excellent results, this past summer ESET received its 100th AV-Test certificate – this milestone marks ten years since ESET achieved its first certificate from AV-Test in June 2010.

Roman Kováč, Chief Research Officer at ESET, commented, “It is extremely encouraging not only to continue to receive commendations for our home and business security solutions, but also to be recognized for ten years of consistent and outstanding results in third-party testing. At ESET, we are extremely proud of our work in making technology safer. This recognition from AV-Test reaffirms that our solutions are proven to work in real-world scenarios. Businesses and home users can be confident that they are in safe hands with ESET. After a year like no other, it has never been more important for your sensitive information and data to be protected with advanced security software both at work and at home.”

Learn more about ESET’s home and business solutions for Windows here.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.

謝謝你2020 –相當成功!

What a year.

What a year this has been to humanity, an epidemic has fundamentally changed the way we interact with one another, social distancing, lockdowns and restrictions in virtually everything we do. Covid-19 has changed the way we conduct business and shifted the way we secure our businesses.

Adversaries’ activities are at an all-time high, be it nation state actors or financially driven attackers. The ever-changing threat landscape is evolving faster than ever and OT networks and IoT devices are a core target for such malicious activities. Repeated attacks from threat actors sponsored by nation-states, such as the recent SolarWinds attack on Microsoft, FireEye, the US government, and around 18,000 other organizations, have prompted fears not only of significant physical damage and economic disruption but also of the increased possibility of all-out cyber warfare. You could describe the situation as an all-out war, only with no guns involved and not a single bullet shot.

In the midst of all of this, we felt that it is imperative to support the broader community and so with the outbreak of Coronavirus earlier this year, we offered all of our products for free for an initial term. And today, we are honored to protect some of the world’s largest organizations in manufacturing and critical infrastructure. In fact, the Japanese government publicly praised SCADAfence’s efforts to secure multiple Japanese organizations, completely free of charge.

Despite the Covid-19 pandemic and possibly because of the recent spike in attacks, our team at SCADAfence has managed to sustain our exponential growth and the continued scaling of our global footprint with rapid expansion in new markets, such as LATAM and APAC.

This rapid expansion can also be attributed to our technological advancements and innovation. Launching new features based on customers’ real needs, such as our User Activity Tracking, a feature that was built specifically for the new, work from home norm; and the SCADAfence Governance portal, which centrally monitors the adherence to industry standard and regulations.

One of the things we’ve always taken pride in is putting our customer’s needs as our top priority. To that end, SCADAfence has won 11 industry awards in 2020, more than all companies in the OT security industry combined – but that all pales in comparison to having the highest customer satisfaction rating on Gartner’s Peer Insights. Not to mention the feedback we’ve been receiving from our customers, here’s just one example:

 “SCADAfence has well exceeded all of our expectations in both service level and product quality. Their team has been extremely knowledgeable, customer-focused, and timely in all aspects of our interactions.”

Process Controls Engineer at a Fortune 100, O&G company.

There’s no doubt that 2020 has been a challenging year but also a year full of growth, dedication and grit. I’d like to thank our entire team for all their hard work, efforts and creativity. A big thank you to all of our partners and of course, our customers for choosing to work with us, it’s not a given and never will be.

If you’ve made it this far and even if you did not, I’d like wish you a great 2021!

Enjoy the holiday season and stay safe.

Happy new year!

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About SCADAfence
SCADAfence helps companies with large-scale operational technology (OT) networks embrace the benefits of industrial IoT by reducing cyber risks and mitigating operational threats. Our non-intrusive platform provides full coverage of large-scale networks, offering best-in-class detection accuracy, asset discovery and user experience. The platform seamlessly integrates OT security within existing security operations, bridging the IT/OT convergence gap. SCADAfence secures OT networks in manufacturing, building management and critical infrastructure industries. We deliver security and visibility for some of world’s most complex OT networks, including Europe’s largest manufacturing facility. With SCADAfence, companies can operate securely, reliably and efficiently as they go through the digital transformation journey.