Feeds

Patch often: Cyber-crim toolkits love stinky old gaping holes

Updating software is better than relying on AV - shock finding

Protecting against web application threats using SSL

More than two in three exploits kits that attempt to inject malware into web surfers' computers were developed in Russia - and at least one in two exploit rather old vulnerabilities.

Blackhole 2.0 is the most often used hacking toolkit - installed on websites to attack and take over visitors' computers - but it targets fewer software security holes than rival cybercrime kits. That's according to a fresh report by managed security biz Solutionary.

Contrary to hype that exploit kits target unpatched flaws in products, Solutionary found the majority (58 per cent) of exploited vulnerabilities were more than two years old.

The company reviewed 26 commonly used kits and discovered code abusing security bugs dating as far back as 2004, evidence that old vulnerabilities continue to be mined for profit for cybercrooks. Criminal hackers typically compromise otherwise legitimate websites to plant hacking toolkits and distribute fake antivirus software, banking Trojans and other nasties.

Researchers at the security firm concluded that antivirus products cannot detect 67 per cent of malware being distributed, a finding that is likely to be controversial. The practical upshot is that surfers would be wise to regularly update applications - especially Adobe Flash, web browsers and the Java runtime - rather than rely on security scanners to block any attacks that come their way.

"Exploit kits largely focus on targeting end-user applications,” said Rob Kraus, a director of security research at Solutionary. “As a result, it is vital that organisations pay close attention to patch management and endpoint security controls in order to significantly decrease the likelihood of compromise."

A complete copy of Solutionary's Q4 2012 threat report can be found here (registration required). ®

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Early result from Scots indyref vote? NAW, Jimmy - it's a SCAM
Anyone claiming to know before tomorrow is telling porkies
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.