tfh
Volume 18, Number 6 -- February 9, 2009

Web Site Vulnerabilities Continue Unabated, IBM X-Force Says

Published: February 9, 2009

by Alex Woodie

Hackers last year continued to compromise commercial Web sites using well-known techniques like SQL injection, putting corporate data in danger, but also raising the likelihood that businesses will infect their own customers with Trojan horses and malware. This was the warning issued by security researchers at IBM's Internet Security Systems subsidiary, which published its security report for 2008 last week. One of the bright spots: spam decreased slightly following the shut down of a major distributor.

In years past, the vast majority of security-related news and attention was related to Web browsers. Microsoft's Internet Explorer (IE), with a new security vulnerability popping up seemingly every other day, was vilified and ridiculed as a huge security liability. People moved in droves to alternatives like Mozilla's Firefox and Apple's Safari Web browsers, in the hopes of avoiding the viruses, worms, and other creepy-crawlies that could infect you via IE.

While IE did have its share of security problems, its attractiveness among hackers was largely a result of IE's dominating popularity. And when Microsoft finally took action to lock down IE, hackers had already moved on to greener fields. First, they moved up the stack to browser add-ons, like Flash and Acrobat. Then hackers ramped up their attacks on applications, including MS Office. But the focus remained on client-side vulnerabilities, as opposed to server-side problems.

Now, the tide has shifted, according to ISS X-Force, and hackers are ramping up their attacks on popular Web sites, which are run on massive clusters of servers housed in data centers.

The new trend has hackers utilizing vulnerabilities in Web application servers and Web middleware to snare large groups of visitors in a short amount of time. Once a popular Web site has been compromised, the hackers can easily re-direct victims to malicious Web sites of their choosing, where victims' PCs are loaded with browser exploit toolkits that do the hackers' bidding. The end result is horrible and predictable: identities are stolen, bank accounts are drained, and lives are devastated.

Web application vulnerabilities--such as SQL injection, cross-site scripting, and file include vulnerabilities (most common in PHP apps)--grew to account for 54 percent of all vulnerabilities in 2008, according to ISS X-Force, which would make them easily the fastest growing class of security vulnerabilities. The biggest offender in the class was SQL injection, which grew 134 percent last year, the group says.

Unfortunately, Web application vendors, as a whole, have not kept up with the spike in SQL injection techniques. Of all the security holes found in Web applications last year (nearly 4,000 them), 74 percent of them had no patch for the problem. That is, quite frankly, unacceptable.

"It is staggering that we still see SQL injection attacks in widespread use without adequate patching almost 10 years after they were first disclosed," says Kris Lamb, senior operations manager, X-Force Research and Development for IBM Internet Security Systems. "This is one of the oldest forms of mass attack still in existence today."

ISS X-Force could not determine why SQL injection attacks are spiking, but concluded that it's likely a combination of several circumstances, including the widespread prevalence of vulnerabilities, stepped up research by hackers, and a lack of patches from the vendors. All in all, the Web application problem is the "Achilles' heel of corporate IT security," ISS X-Force says.

The rate of discovery of all critical vulnerabilities continued its march upward in 2008, increasing 13.5 percent over the previous year, after slowing down in 2007. However, despite the increase in vulnerabilities, hackers were not exploiting them as often as they had in the past, ISS X-Force found.

This led the company to question how the security industry responds to vulnerabilities, and suggest that a more nuanced approach--one that takes into account how much hackers could profit from a given vulnerability--into account. Currently, the Common Vulnerability Scoring System (CVSS) looks primarily at the technical aspects of vulnerabilities, and not the potential financial gain, ISS X-Force says.

Security researchers logged a major victory against spam when the Silicon Valley Web hosting firm McColo was shut down last fall. The operations of McColo, which was actually a front for a huge spam operation, was brought to light as a result of the work of Washington Post reporter Brian Krebs to track down the source of spam.

While bringing down the McColo operation resulted in an immediate drop in the amount of spam clogging the Internet's byways, other operations picked up the slack to fill the void in spammy substances. ISS X-Force reports that China emerged as the number one spam provider immediately following McColo's demise, but that Brazil claimed the top prize by the end of the year. Another BRIC country, Russia, was also a top spam generator for 2008 (India, where are you?), as was Turkey.

The complete 106-page ISS X-Force report can be downloaded at www-935.ibm.com/services/us/iss/xforce/trendreports.


RELATED STORIES

Surf's Up for Web-Based Organized Crime, IBM X-Force Says

In Search Of a More Secure Internet

IBM X-Force Says For-Profit Cyber Attacks to Increase in 2007



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
VAULT400

Never Lose Your Data

 

VAULT400's online service automatically backs up
your systems--using the highest level of encryption--to a
secure offsite data center. Should you lose a file for any reason,
it can be recovered with a few keystrokes.

 

                                                   Our online backup makes it easy:
                                                        · Automate backups offsite
                                                        · Secure backups with end-to-end encryption
                                                        · Recover data immediately
                                                        · Lower costs
                                                        · Reduce backup times
                                                        · Test disaster recovery process
                                                        · Meet government compliance regulations

 

Discover how online backup delivers
a better way to protect business-critical data.

 

www.vault400.com


Editor: Timothy Prickett Morgan
Contributing Editors: Dan Burger, Joe Hertvik, Brian Kelly, Shannon O'Donnell,
Mary Lou Roberts, Victor Rozek, Kevin Vandever, Hesh Wiener, Alex Woodie
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

ARCAD Software:  FREE Webinar, How ALM Can Save You Money, February 19
COMMON:  Join us at the 2009 annual meeting and expo, April 26-30, Reno, Nevada
Bytware:  Protect your systems by taking the fight to the viruses where they hide

 

 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
Four Hundred Stuff
i OS Vendors Take Different Approaches to Poor Economy

RPG Gets Mixed Up in EGL Jam

Vault400 Debuts Tiered DR and Managed HA Services

Zend's PHP to be Preloaded Onto IBM i OS

Bring Your IT Ideas to Life, mrc Says

Four Hundred Guru
A Bevy of BIFs: Look Up to %LookUp

Treasury Of New DB2 6.1 Features, Part 1: Query Enhancements

Admin Alert: Time Gobbling Tasks for a System Upgrade

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
January 31, 2009: Volume 11, Number 5

January 24, 2009: Volume 11, Number 4

January 17, 2009: Volume 11, Number 3

January 10, 2009: Volume 11, Number 2

January 3, 2009: Volume 11, Number 1

December 27, 2008: Volume 10, Number 52

TPM at The Register
NEC confirms European PC biz shutdown

US sheds 598,000 jobs in January

Ubuntu shops believe in Ubuntu

Chipzilla sits on its Tukwila

IT questions Obama's IT stimulus

Sun christens once and future Supernovas

Citrix boosts seat count for XenDesktop

Hitachi takes losses, chops jobs

Uncle Sam buys 20 petaflops BlueGene super

Dell pairs with Xsigo on virtual I/O

Sun taps ex-Merrill, ex-Fannie Mae exec for board

Intel to spill Nehalem secrets

Novell cuts 1000 100 workers

Ex-IntelCrayAkamai startup rejiggers virtualization

THIS ISSUE SPONSORED BY:

Databorough
Maximum Availability
Profound Logic Software
Safedata
VAULT400


Printer Friendly Version


TABLE OF CONTENTS
Database Server/400, Anyone?

Who's the Fool When it Comes to Training?

Google's Love Affair with IBM's Offspring

As I See It: If I Were Wise Enough, I Might Say. . .

Web Site Vulnerabilities Continue Unabated, IBM X-Force Says

But Wait, There's More:

Deconstructing and Rebuilding IBM's Q4 Server Sales . . . Avnet Hit By Economic Downturn in Fiscal Q2 . . . SAP Launches Business Suite 7, Reports 2008 Financials, and Cuts Jobs . . . Demand for BI is High Says, HiT Software . . . IBM Cuts Price of BladeCenter S SAS Module in Half . . .

The Four Hundred

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2009 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement