"It appears there are plenty of holes and plenty of programs that are heavily used that are vulnerable," said Ken Dunham, senior engineer for the Verisign/iDefense Intelligence Team. "What that means is there is plenty of opportunity for attackers. There are a great many potential vectors that could be exploited."
Tech Industry Paper - Finding Strength Through Customer Service Poised to capitalize on an upturn in the economy, technology companies are focused on retention & service. This paper, from Convergys, provides the latest research on customer experience for B2B & B2C technology customers. Learn more.
Security institute SANS released its latest 20 most critical vulnerabilities list, warning of new attacks that are focused on applications, including backup and media software, and of hackers' increasing ability to embed attacks in sites to snare users simply visiting them.
The latest list of vulnerabilities includes software from a range of vendors, including Microsoft (Nasdaq: MSFT), Computer Associates (NYSE: CA), Veritas, RealNetworks (Nasdaq: RNWK), Apple (Nasdaq: AAPL) and Mozilla. The SANS security researchers said attackers are increasingly going beyond operating system attacks to reach users and their data through the applications they are using.
"We're publishing this list as a red flag for individuals as well as IT departments," said SANS director of research Alan Paller in a statement. "Too many people are unaware of these vulnerabilities, or mistakenly believe their computers are protected."
Holes for Hacks
The latest SANS vulnerability list indicated there were 422 new vulnerabilities discovered or reported during the second quarter of 2005, marking an increase of 10.8 percent from the first quarter and up 20 percent from last year's second quarter.
The vulnerabilities included operating system, browser, backup and security software holes, as well as several issues with Microsoft products, but also included media software such as RealNetworks' RealPlayer and a problem with Apple's iTunes MPEG4 file processing.
SANS warned that individuals and organizations that do not patch, update or otherwise correct the 20 most critical vulnerabilities run a heightened risk that remote, unauthorized hackers will take control of computers for ID theft, industrial espionage, spam or pornography.
Back Door in Backup
The latest critical vulnerability list from SANS also highlighted "worrisome" weakness in popular data backup products, which are designed to prevent catastrophes by recording copies of important data in storage, but may be opening the door to attacker access.
"Unfortunately, those products have become easy targets for attackers, and since they have access to substantially all data, the products weaknesses create real danger," SANS said in a statement.
Among the top 20 most critical vulnerabilities, SANS reported security holes in Computer Associates' BrightStor ARCServe Backup and Veritas backup software. Also on the list of potentially vulnerable software were: Oracle (Nasdaq: ORCL) Cumulative Update 2005; Apple Cumulative Security Updates 2005-005 and 006; and Mozilla and Firefox browsers. There were also security issues with Microsoft's Internet Explorer, Exchange Server, Message Queuing Service, Windows Shell Remote Code Execution and more.
Growing Sophistication
Ken Dunham, senior engineer for the Verisign/iDefense Intelligence Team, told TechNewsWorld the movement from operating system to applications is a natural evolution of attacker technique and technology, as well as response to operating system weakness.
Citing readily-available guides and discussions on reverse engineering and attacking software and systems, Dunham added that while operating systems have become more secure and organizations are now better at securing them, the same cannot be said about applications, even those that are heavily used.
"It appears there are plenty of holes and plenty of programs that are heavily used that are vulnerable," he said. "What that means is there is plenty of opportunity for attackers. There are a great many potential vectors that could be exploited."
Yahoo Buys Widget Maker Konfabulator July 25, 2005
The three-person software shop Konfabulator announced the buy by Yahoo in a note on its Web site, saying that the purchase would enable it to make the Konfabulator JavaScript runtime engine available for free. Yahoo said it would keep Konfabulator's development team of Arlo Rose, Perry Clarke and Ed Voas on board.
Related Stories
Microsoft Buys One Security Firm, Invests in Another July 21, 2005
In Finjan, Microsoft is investing in a security company that has been highly critical of the software giant in the past. Not long after Microsoft released Service Pack 2 (SP2) for Windows XP, Finjan put out a report saying it had found 10 "serious flaws" in the security update. Microsoft disputed that finding.
Vendors Move To Tighten Up Wireless Security Holes July 13, 2005
The IEEE 802.11x standard, which includes the Extensible Authentication Protocol (EAP), was designed to help close up the security holes. It outlines a way that vendors can change the way certificate information is sent to users. Vendors have taken the framework and extended it so there are a handful of different techniques to provide users with certificate data.
Adoption of Alternate E-Mail Security Technologies Pushed June 25, 2005
"Each protocol provides different answers to different problems involving e-mail security issues. But both new protocols deal with sender authentication," Thomas Gillis, senior vice president for worldwide marketing at IronPort Systems, said.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.