Feeds

Web vulns top security threat index

On the up-and-up

Securing Web Applications Made Simple and Scalable

Analysis Less rigor in web programming, an increasing variety of software, and restrictions on web security testing have combined to make flaws in web software the most reported security issues this year to date, according to the latest data from the Common Vulnerabilities and Exposures (CVE) project.

A draft report on the latest numbers from the vulnerability database found that 4,375 security issues had so far been cataloged in the first nine months of 2006, just shy of the 4,538 issues documented last year. The data shows that web flaws have continued their meteoric rise since 2005, capturing the top-three spots on the list of most common vulnerabilities. Buffer overflows, a perennial favorite, fell to the No. 4 slot.

"The takeaway is that researchers are paying a lot more attention to web vulnerabilities, and if companies don't want to get caught up in that, then they need to pay attention to those flaws," said Steven Christey, the security researcher that authored the draft report and the CVE Editor for The MITRE Corp., a nonprofit government contractor.

The jump in web-based vulnerabilities is fueled by the simplicity of exploiting many of the most common web vulnerabilities, the enormous number of web applications freely available, and the difficulty in eradicating cross-site scripting flaws. Moreover, while many of the vulnerabilities are easy to test for and find, independent security researchers are less likely to probe another group's website to find the flaws, because doing so violates computer intrusion statutes. The case of Eric McCarty illustrates the danger: The network administrator found a database vulnerability in the online application site for the University of Southern California but was prosecuted for his unauthorized access of the server and last week agreed to plead guilty.

Easy-to-use web programming languages are also to blame, because they attract people who have not programmed before and can be more easily audited for flaws, Christey said.

"The existence of these web-friendly languages, like PHP, lowers the bar for someone to create a useful application but also lowers the bar for someone to find vulnerabilities in that application," he said.

In the CVE Project's latest numbers, flaws that use a technique for injecting code from one website into another, known as cross-site scripting or XSS, accounted for 21.5 per cent of the vulnerabilities reported so far in 2006.

Cross-site scripting is considered by many security researchers to be a less-than-hackerly technique used by script kiddies, phishers and spammers to fool trusting users. The technique is a key method for injecting malicious code into a victim's web session. Cross-site scripting allows a malicious website to inject code into the context of another website; a user that believes they are interacting with a popular social networking site, for example, might instead be loading a script in from some other malicious site.

Mobile application security vulnerability report

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
British data cops: We need greater powers and more money
You want data butt kicking, we need bigger boots - ICO
Crooks fling banking Trojan at Japanese smut site fans
Wait - they're doing online banking with an unpatched Windows PC?
NIST told to grow a pair and kick NSA to the curb
Lrn2crypto, oversight panel tells US govt's algorithm bods
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.