Browser flaws biggest software security risk

By Tom Espiner, ZDNet UK
Monday, September 18, 2006 12:17 PM

The most common software flaws are now cross-site scripting (XSS) vulnerabilities, according to Mitre, a U.S. Government organization.

XSS flaws have accounted for 21.5 percent of the vulnerabilities found in 2006 so far according to Mitre statistics.

XSS vulnerabilities potentially allow attackers to access sensitive data from a Web site by bypassing security in browsers using JavaScript.

SQL injection flaws, which can occur in database-backed Web applications, accounted for 14 percent of vulnerabilities seen.

PHP remote file vulnerabilities accounted for 9.5 percent of the 20,000 flaws collated by Mitre, said DarkReading.com.

PHP, a Web scripting language, can be vulnerable to attack if applications created using it are not carefully written. PHP implementations are often considered notoriously poorly coded, according to security vendor Sophos.

Buffer overflow vulnerabilities slipped from being the most prevalent in 2003 to accounting for 7.9 percent of holes in 2006.

However, Sophos said that it hadn't seen any noticeable shift in terms of attacks on these flaws, including buffer overflow holes. Sophos questioned how the statistics had been collated and the potential severity of the flaws, due to the limited number of people who use smaller Web servers.

"There is a danger that these folks are comparing apples with oranges," said Graham Cluley, senior technology consultant with Sophos. "After all, you could find lots and lots of vulnerabilities in Fred's Internet Utility, but that wouldn't be something we would consider to be a bigger problem than just one vulnerability in a widespread technology like [Microsoft's] Internet Information Services."

Cluley said that XSS attacks are very common on less popular Web servers and applications, but that the more widely used packages are less likely to have such flaws.

According to Cluley, the Mitre statistics do not indicate a shift in the type of software that attackers are targeting, merely that the proliferation of flawed applications with few users is skewing the statistics.

"The fact is that there are more small .Net, Java and PHP implementations of blogging and Web hosting than there are Internet side C-based software platforms," said Cluley.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web