All the latest UK technology news, reviews and analysis

Well-known security flaws go ignored

by Robert Jaques

20 Jan 2003

Be the first to comment

  • Tweet this

Failure to implement effective security policies is leaving the majority of companies open to surprisingly common vulnerabilities, and is even threatening the security of the "entire internet", analysts warned last week.

According to the Open Web Application Security Project (OWASP), which has published a list of the most dangerous internet application security problems, the greatest threat comes from ignoring exploits that are well understood and well documented.

Many of the problems on the OWASP's list can be executed by inexperienced 'script kiddies' using automated cracking tools.

The Washington-based open source project was surprised to find that firms were not deploying countermeasures against well known threats.

"The security issues raised here are not new. In fact, some have been well understood for decades," he said.

"Yet for some reason, major software development projects are still making these mistakes and jeopardising not only their customers' security, but the security of the entire internet."

This view was endorsed by Dr Charles Pflegger, master security architect at Cable and Wireless.

"Flaws continue to be found in applications, even after nearly 50 years of programming experience," he explained. "Worse, the same kinds of flaws appear over and over again.

"This failure to learn from our mistakes and those of our parents' generation, creates far too many vulnerabilities for potential attack. It is no wonder that attacks against applications are on the rise."

The OWASP highlighted the danger of web applications which are not configured to recognise malicious code encapsulated in HTTP requests that can "sail past firewalls, filters, platform hardening, Secure Socket Layer and intrusion detection systems without notice".

While welcoming the report as an attempt to raise awareness of IT security issues, Quocirca strategy analyst Clive Longbottom pointed out that highlighting technical problems could fight only half the battle.

"Just raising a list of problems in isolation will only provide a recipe for fear, uncertainty and dread," he warned.

"Over 95 per cent of UK companies are not large enough to employ dedicated IT security professionals. As a result most will not understand the difference between a command injection flaw and a cross-site scripting exploit.

"In order to better serve this majority of companies the security market needs to stop the techno-babble of stringing acronyms together to describe vulnerabilities.

"They must move away from the technology for its own sake and start offering understandable products and services to deal effectively with these common vulnerabilities."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

.Net Principal Development Engineer Lead- London

Principal Development Engineer Lead- London - Smart TV...

.Net Development Engineer - HTML, XHTML, CSS, DOM

Development Engineer - London - Smart TV, Gaming, Tablets...

Principal Development Engineer - .Net ,C# or Java -

Principal Development Engineer - London - Smart TV, Gaming...

Test Engineer -London - Smart TV, Gaming, Tablets, PC& Mac

Test Engineer -London - Smart TV, Gaming, Tablets, PC...

To send to more than one email address, simply separate each address with a comma.