All the latest UK technology news, reviews and analysis

Weak security found in many web servers

by John Leyden

07 Sep 2000

Be the first to comment

  • Tweet this

One in three supposedly secure ebusiness servers are using software with known security weaknesses, and European sites are the worst offenders, according to a survey.

Eric Murray, a consulting security architect based in the US, found that in a random sample of more than 8000 web servers running the SSL protocol, 32 per cent were "dangerously weak".

Murray explained that these weak servers either support only the flawed SSLv2 protocol, use weak encryption, or have expired or self-signed digital certificates.

"These weaknesses make the transactions that are protected by these servers easy to attack with modern key-cracking and/or hacking attacks," said Murray, who added that there is no good reason for sites not to address the problems he has highlighted.

There is no technical or legal reason to limit secure servers to using only SSLv2, since SSLv3, which corrects known weaknesses, is available. Since US export regulations were relaxed in January to allow the export of 128bit cryptographic products, there is also no reason to support only 40bit cipher suites or 512bit RSA keys.

The survey revealed that security of European servers is particularly weak, because many still used web servers obtained before the export restriction were relaxed. This was found to be particularly the case for sites running Microsoft's Internet Information Server rather than those running Apache.

The fact that many sites are vulnerable for no good reason is, according to Murray, explained by a tendency for businesses not to update their security software until websites become breached.

"Many sites don't bother to update or patch software, even when it is readily available, until they're forced to do so because someone has broken in. Until then, they are still open to well-known vulnerabilities," said Murray.

Matt Tomlinson, business development director at IT security consultancy MIS Corporate Defence, said the survey is one of the most comprehensive he had come across, and said the figure of a third of so-called secure websites actually being insecure matched the experience of MIS in the UK.

"Even if a web server is secure that is not the end of the issue. There is also the possibility of backdoors into a network, and hackers will not always go to the obvious point when they launch attacks," said Tomlinson.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

34%

1%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Credit Risk Modeller, SAS, London, £50,000

Credit Risk Modeller, SAS, London, £50,000 Title- Credit...

Global Project/Programme Manager-with recruitment deployment experienc

My London client is looking for an experienced Programme...

PHP Developers (All Levels)

My leading client is looking for a number of excellent...

Group Services Manager - Telecoms

My client, a leading international name in Manufacturing...

To send to more than one email address, simply separate each address with a comma.