**************************************************************************
Security Bulletin 9720 DISA Defense Communications System
August 12, 1997 Published by: DISN Security Coordination Center
(SCC@NIC.MIL) 1-(800) 365-3642
The DISN SECURITY BULLETIN is distributed by the DISN SCC (Security Coordination Center) under DISA contract as a means of communicating information on network and host security exposures, fixes, and concerns to security and management personnel at DISN facilities. Back issues may be obtained via FTP from NIC.MIL [207.132.116.5] using login= "anonymous" and password="guest". The bulletin pathname is scc/sec-yynn (where "yy" is the year the bulletin is issued and "nn" is a bulletin number, e.g. scc/sec-9705.txt). These are also available at our WWW site, http://nic.mil.
**************************************************************************
+ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - +
! !
! The following important advisory was issued by the Automated !
! Systems Security Incident Support Team (ASSIST) and is being !
! relayed unedited via the Defense Information Systems Agency's !
! Security Coordination Center distribution system as a means !
! of providing DISN subscribers with useful security information. !
! !
+ - - - - - - - - - - - - - - - - - - - - - - - -
- - - - - - - - - - - +
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
_____
___ ___ _____ ___ _____ | /
/\ / \ / \ | / \ | | / Integritas
/ \ \___ \___ | \___ | | < et
/____\ \ \ | \ | | \ Celeritas
/ \ \___/ \___/ __|__ \___/ | |_____\
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
SUMMARY: The McAfee and Symantec Norton computer AV software has
been site licensed for use by DOD and will be available for use as of 1 September 97. The software will be available for use by the DOD antivirus support community on 15 August 97. The DOD license was procured by the Defense Information Systems Agency (DISA) contract DCA100-98-F-0004 to Stream International (Symantec's Norton AntiVirus) and DCA100-98-F-0005 to McAfee is valid through 30 Sept 98.
BACKGROUND: The DOD site license for the IBMAV and Norman
software expires on 30 September 97. DOD personnel may continue to use the IBMAV software after the expiration date, however virus signature updates will no longer be issued.
IMPACT: Failure to maintain and use an up to date AV tool places
systems at risk of malicious code infection.
RECOMMENDED SOLUTIONS: Obtain, install, and begin using the DOD site
licensed McAfee and Norton AV tool as soon as possible. Ensure the AV tool is kept up to date by obtaining and installing the most current version of the software as soon as it is available from the DOD distribution centers.
Army: Army Computer Emergency Response Team (ACERT)
Hotline: 1-888-203-6332 (DSN: 235-1113)
Anonymous FTP: ftp.acert.belvoir.army.mil
Web Server: http://www.acert.belvoir.army.mil
Navy: NISE East, Charleston, SC Information Systems Security (INFOSEC)
Anonymous FTP: INFOSEC.NOSC.MIL (198.253.23.241)
Air Force: Air Force Information Warfare Center (AFIWC)
Anonymous FTP: afcert.csap.af.mil (192.203.2.249), Web Server: http://afcert.csap.af.mil (192.203.2.249), AFCA C4 Systems Security BBS: 618-256-4545 (DSN 576-4545)
Other: Automated Systems Security Incident Support Team (ASSIST)
Hotline: (800) 357-4231 (DSN: 327-4700)
Anonymous FTP: ftp.assist.mil (199.211.123.12)
Web Server: http://www.assist.mil (199.211.123.12)
Personnel from each DOD element should download the software from their respective MILDEP distribution centers. Personnel affiliated with non-MILDEP elements should use the ASSIST BBS or FTP servers.
***************
The following is a copy of the license terms, conditions and coverage: DOD-Wide Anti-Virus Software Enterprise License Agreement Between Defense Information Systems Agency and McAfee Software, Inc.
This Addendum to License and Warranty (the "Addendum") dated 16 July 1997 shall serve to amend the standard retail package product License and Warranty (the "Agreement") which accompanies Symantec's Antivirus packaged product which will govern the Symantec Software Product purchased by the Defense Information Systems Agency, ("DISA"), pursuant to the GSA Schedule buy of a DOD-wide antivirus software license. DISA is the purchasing agency for the Department of Defense ("DOD"). The terms of the Addendum shall control in the event of arty conflict between the Agreement and the Addendum.
The Agreement will be amended as follows.
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
ASSIST is an element of the Defense Information Systems Agency (DISA), Global Operations and Security Center (GOSC), which provides service to the entire DoD community. Constituents of the DoD with questions about ASSIST or computer security issues, can contact ASSIST using one of the methods listed below. Non-DoD organizations/institutions, contact the Forum of Incident Response and Security Teams (FIRST) representative. To obtain a list of FIRST member organizations and their constituencies send an email to docserver@first.org with an empty "subject" line and a message body containing the line "send first-contacts".
___________________________
Phone: (800)-357-4231 (DSN 327-4700) 24 hour hotline
Fax: (703) 607-4735 (DSN 327-4735) Unclassified
ASSIST Bulletins, tools and other security related information are available from:
To be added to our mailing list for ASSIST bulletins, send your e-mail address to:
assist-request@assist.mil In the subject line, type:
___________________________________
_________________
Back issues of ASSIST bulletins, and other security related information, are available from the ASSIST BBS at 703-607-4710, 327-4710, and through anonymous FTP from ftp.assist.mil (IP address 199.211.123.12). Note: ftp.assist.mil will only accept anonymous FTP connections from Milnet addresses that are registered with the NIC or DNS. If your system is not registered, you must provide your MILNET IP address to ASSIST before access can be provided.
ASSIST uses Pretty Good Privacy (PGP) as the digital signature mechanism for bulletins. PGP incorporates the RSAREF Cryptographic Toolkit under license from RSA Data Security, Inc. A copy of that license is available via anonymous FTP from net-dist.mit.edu (IP 18.72.0.3) in the file /pub/PGP/rsalicen.txt. In accordance with the terms of that license, PGP may be used for non-commercial purposes only. Instructions for downloading the PGP software can also be obtained from net-dist.mit.edu in the pub/PGP/README file. PGP and RSAREF may be subject to the export control laws of the United States of America as implemented by the United States Department of State Office of Defense Trade Controls. The PGP signature information will be attached to the end of ASSIST bulletins.
Reference herein to any specific commercial product,
process, or service by trade name, trademark manufacturer, or
otherwise, does not constitute or imply its endorsement, recommendation,
or favoring by ASSIST. The views and opinions of authors expressed
herein shall not be used for advertising or product endorsement
purposes.
****************************************************************************
* *
* *
* *
* *
* *
* *
* *
* *
****************************************************************************
PLEASE NOTE: Some users outside of the DOD computing communities may receive DISN Security Bulletins. If you are not part of the DOD community, please contact your agency's incident response team to report incidents. Your agency's team will coordinate with DOD. The Forum of Incident Response and Security Teams (FIRST) is a world-wide organization. A list of FIRST member organizations and their constituencies can be obtained by sending email to docserver@first.org with an empty subject line and a message body containing the line: send first-contacts.
This document was prepared as an service to the DOD
community. Neither the United States Government nor any of their
employees, makes any warranty, expressed or implied, or assumes
any legal liability or responsibility for the accuracy, completeness,
or usefulness of any information, product, or process disclosed,
or represents that its use would not infringe privately owned
rights. Reference herein to any specific commercial products,
process, or service by trade name, trademark manufacturer, or
otherwise, does not necessarily constitute or imply its endorsement,
recommendation, or favoring by the United States Government.
The opinions of the authors expressed herein do not necessarily
state or reflect those of the United States Government, and shall
not be used for advertising or product endorsement purposes.