All the latest UK technology news, reviews and analysis

Security report attacks backup software

by Ken Young

26 Jul 2005

Be the first to comment

  • Tweet this

The Sans Institute has identified 422 new internet security vulnerabilities in its most recent quarterly report, up nearly 11 per cent on the first quarter of the year. 

The report highlighted weaknesses in popular backup software, including programs from Veritas (now part of Symantec) and Computer Associates, both of which made the Sans Institute's list of top 20 new vulnerabilities. 

"Because backup programs grant access to virtually all of a company's data they are particularly attractive to attackers. And since updating these applications with patches is often overlooked, they represent a real vulnerability," said Alan Paller, director of research at the Sans Institute.

"These are weaknesses that people can actually exploit to cause damage. I advise firms to use the patches available on the Institute's list."

Sans also reported new vulnerabilities in popular music download programs from Apple and RealNetworks. Both iTunes and RealPlayer contain flaws that allow for playlists or music files to be downloaded that contain malware, according to Paller.

Also on the list are Internet Explorer, Firefox and Mozilla, which contain vulnerabilities allowing PCs to become infected simply by visiting a website.

Matt Peachey, managing director of email security vendor Ironport Systems., said: "The security holes highlighted by the Sans report are a huge problem, primarily because there is an increase in the number of hackers who are eager to exploit these holes.

"The findings highlight the importance of the often neglected area of pre-patch management and the need for a proactive, rather than a reactive, approach.

"What is needed is a filter which proactively controls and quarantines traffic from suspicious or unknown senders."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

36%

0%

10%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Android Developer (Android and .NET) - West Midlands - up to £40k

Android Developer (Android and .NET) - West Midlands...

Regional Architect

Responsibilities: - Delivering End-to-End solutions...

SQL, Marketing Data Manager, West London - to £45K + Bens

SQL, Marketing Data Manager, West London - to £45K...

Software Developer

One of Aston Carters longest standing clients has an...

To send to more than one email address, simply separate each address with a comma.