Feeds

Admins slow to tackle SSL security risks

SSL servers last in line for Apache fix - Netcraft

  • alert
  • submit to reddit

Choosing a cloud hosting partner with confidence

Web admins are faster at fixing flaws to conventional Web servers than SSL servers, figures from Netcraft latest Web site survey suggest.

The study, released this Tuesday, found almost half of the 22 million Apache HTTP sites scrutinised are running Apache/1.3.26, whilst only around a quarter of the Apache SSL sites are running this version, which fixes a well publicised chunked encoding vulnerability.

This flaw, which opens the door to potential DoS attacks or remote exploits on vulnerable servers, together with recent remote vulnerabilities in Microsoft Commerce Server and Microsoft-IIS, leaves a great many ecommerce sites vulnerable to direct attack over the internet, Netcraft gloomily notes.

And that's before factoring in four remotely exploitable buffer overflows in OpenSSL or the effects of a recently demonstrated vulnerability in IE and KDE which potentially allows Web sites certified by Verisign to assume the identity of other sites, including widely used ecommerce sites.

More than just events of this month alone, 2002 is shaping up to be an annus horribilis for Web security. ®

Related Stories

MS soft-pedals SSL hole
KDE fixes SSL hole as MS dithers
Trio of bugs bite MS Content Management Server
OpenSSH trojaned!

Beginner's guide to SSL certificates

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.