Feeds

Web vulns top security threat index

On the up-and-up

Internet Security Threat Report 2014

Analysis Less rigor in web programming, an increasing variety of software, and restrictions on web security testing have combined to make flaws in web software the most reported security issues this year to date, according to the latest data from the Common Vulnerabilities and Exposures (CVE) project.

A draft report on the latest numbers from the vulnerability database found that 4,375 security issues had so far been cataloged in the first nine months of 2006, just shy of the 4,538 issues documented last year. The data shows that web flaws have continued their meteoric rise since 2005, capturing the top-three spots on the list of most common vulnerabilities. Buffer overflows, a perennial favorite, fell to the No. 4 slot.

"The takeaway is that researchers are paying a lot more attention to web vulnerabilities, and if companies don't want to get caught up in that, then they need to pay attention to those flaws," said Steven Christey, the security researcher that authored the draft report and the CVE Editor for The MITRE Corp., a nonprofit government contractor.

The jump in web-based vulnerabilities is fueled by the simplicity of exploiting many of the most common web vulnerabilities, the enormous number of web applications freely available, and the difficulty in eradicating cross-site scripting flaws. Moreover, while many of the vulnerabilities are easy to test for and find, independent security researchers are less likely to probe another group's website to find the flaws, because doing so violates computer intrusion statutes. The case of Eric McCarty illustrates the danger: The network administrator found a database vulnerability in the online application site for the University of Southern California but was prosecuted for his unauthorized access of the server and last week agreed to plead guilty.

Easy-to-use web programming languages are also to blame, because they attract people who have not programmed before and can be more easily audited for flaws, Christey said.

"The existence of these web-friendly languages, like PHP, lowers the bar for someone to create a useful application but also lowers the bar for someone to find vulnerabilities in that application," he said.

In the CVE Project's latest numbers, flaws that use a technique for injecting code from one website into another, known as cross-site scripting or XSS, accounted for 21.5 per cent of the vulnerabilities reported so far in 2006.

Cross-site scripting is considered by many security researchers to be a less-than-hackerly technique used by script kiddies, phishers and spammers to fool trusting users. The technique is a key method for injecting malicious code into a victim's web session. Cross-site scripting allows a malicious website to inject code into the context of another website; a user that believes they are interacting with a popular social networking site, for example, might instead be loading a script in from some other malicious site.

Beginner's guide to SSL certificates

More from The Register

next story
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Internet Security Threat Report 2014
An overview and analysis of the year in global threat activity: identify, analyze, and provide commentary on emerging trends in the dynamic threat landscape.