Quick Login   
 
Register AdminFusion Tutorials
 
Featured Sponsors


One.com Domain and Hosting


Register
Forum of the Month
Australian Webmaster
fotm

A webmaster forum specifically catering for Australian site owners. We discuss site development, marketing and management issues.

Tag Cloud
Latest Threads
Forum Stats
7,846 Members
164,851 Posts
35 Users Online

Please welcome our newest member, discotoast!

Affiliates
Go Back AdminFusion » The Break Room » Off Topic » A New 'Malicious Marketplace' for Internet Attacks
Welcome to the AdminFusion. AdminFusion is the ultimate resource for forum administrators and moderators. With exclusive articles, interviews with the experts, free downloadable skins, and the revolutionary post exchange system - PostFusion, AdminFusion is the place to go for all of your forum needs.  By joining AdminFusion, you will become part of a thriving admin community and immediately gain access to all of these resources. Registration is fast, simple and absolutely free so please join us today!
Want more than our forums? Try these: Post Fusion Forum Matrix
Old 11-23-2005, 02:05 PM   #1

shellspeare's Avatar

Title: Forum Enthusiast

Points: 16,350, Level: 38Points: 16,350, Level: 38Points: 16,350, Level: 38
Level up: 39%, 100 Points neededLevel up: 39%, 100 Points neededLevel up: 39%, 100 Points needed
Activity: 0%Activity: 0%Activity: 0%

Join Date: Aug 2005

Posts: 2,521

Location: England

shellspeare is on a distinguished road
Send a message via MSN to shellspeare  
 
Exclamation A New 'Malicious Marketplace' for Internet Attacks

A New 'Malicious Marketplace' for Internet Attacks
source: http://www.pcworld.com/news/article/0,aid,123651,00.asp

The SANS Institute report on 2005's top Internet vulnerabilities finds a trend toward attacking common user applications.

Erik Larkin, PC World
Tuesday, November 22, 2005
Internet criminals are increasingly targeting popular applications like backup software and Web browsers instead of the operating systems that run them, according to a new report from government and industry security experts.

Attackers now target backup and recovery programs, as well as "the antivirus and other security tools that most organizations think are keeping them safe," according to the SANS Top 20 report for 2005 on the most critical Internet vulnerabilities, released today.

The shift toward finding and exploiting vulnerabilities in programs represents a major change from past years, when Windows and other operating systems and Internet services like Web and e-mail servers were the preferred targets.

"Attackers are now targeting the whole range of applications that users are now installing on their systems," says Alan Paller, Director of Research at SANS.

That puts us back five or six years in terms of Internet security, says Paller, because while operating systems and other frequent targets of Internet attacks have implemented automatic updates to quickly close security holes, many programs with critical vulnerabilities don't have any such features.

"That means we're back to the Stone Age," Paller says. "Everything you worried about five or six years ago" is a concern once again, he says, when people have to discover and fix new vulnerabilities themselves.


Popular Software at Risk
In addition to holes in security and backup programs, critical vulnerabilities in instant messaging programs, Web browsers, file sharing applications, and media players are all listed among the Top 20.

About 60 percent of new vulnerabilities now affect client-side applications like Web browsers and media players, according to Gerhard Eschelbeck of Internet security company Qualys, which also participated in the report's research.

And those vulnerabilities are drawing all the wrong sorts of attention. According to SANS, unwanted network traffic targeting Symantec Veritas BackupExec rocketed to 500,000 instances within days of an announced security hole in the product, up from a previous maximum of about 50,000 instances.

Symantec wasn't alone. Microsoft Office, Internet Explorer, Firefox, and AOL Instant Messenger also suffered from serious reported vulnerabilities, as did RealPlayer and iTunes. Also, according to a previous report from the Yankee Group, the number of flaws reported in antivirus and other security programs is increasing at a far faster rate than for Windows.


Opportunities for Criminals
Applications represent an increasingly attractive target because operating systems and Internet services have become more resilient after years of steady attacks. Many programs, on the other hand, lack any means for automatic program updates. The delay between an announced vulnerability and the time that an administrator or home user manually updates the software represents a window of opportunity for Internet criminals.

New awareness of critical security holes in the network devices that guide Internet traffic represents the second important shift in the Top 20, according to the report.

"Compromises of network devices can provide attackers one of the most fruitful platforms for eavesdropping and launching targeted attacks," it states.


The Bottom Line: Profit
Additionally, "individuals are writing exploits . . .largely for profit," says Roger Cummings, director of the British Government's National Infrastructure Security Co-Ordination Centre. Cummings co-presented the report.

The marketplace could put major exploits in the hands of terrorists interested in threatening our countries' infrastructure, according to Cummings. That threat grows as we become increasingly dependent on larger networks that combine services and tasks, he says.

The public nature of the Internet, one of its great strengths, also can contribute to its vulnerability, Cummings says. Because the technologies that power the Internet are public knowledge, anyone can examine them for weaknesses. In the long run, that may result in more problems being fixed. But in the short term, before a program patch or other fix is available, those vulnerabilities can be exploited for real profit.

Government organizations within the United States, the United Kingdom, and Canada all contributed to the report, as did Internet security company TippingPoint. The SANS Institute has been producing the Top 20 report since 2000.
__________________
Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

 
Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Forum Posting Services - PPT Marketplace Links Toucan42 Buy and Sell 1 11-22-2006 09:46 PM
Malicious Hackers Exploit Windows Flaw shellspeare Off Topic 0 12-30-2005 12:07 PM

AdminFusion

All times are GMT +1. The time now is 10:57 AM. Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0 © 2005-2008 AdminFusion - All Rights Reserved



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72