01 Feb 2005
A three-year research project by security firm NTA Monitor has concluded that nine out of 10 virtual private networks have exploitable vulnerabilities.
Most of the companies that had their VPNs tested as part of the project thought that they were invulnerable to hackers, but researchers found the same types of flaw repeated across the whole product range.
The report stated that, in some cases, VPNs were actually the weakest security link in an organisation.
"VPNs are not the invulnerable systems that they are often believed to be," said Roy Hills, technical director at NTA Monitor and author of the report.
"They can actually be the weak link in a secure system. Some of these problems are new discoveries, while others are known limitations of the protocols which are exposed due to poor configuration."
The most widespread flaw involved the hacking of user names. Many VPNs give away useful information to someone guessing user names and, although NTA Monitor has warned these companies of this weakness, many have yet to fix the problem.
Other vulnerabilities centre around password cracking. The survey found that a text-based password could be broken in 16 minutes using a brute force attack, while a password containing a mixture of words and letters took two days.
VPNs are also a very tempting target for hackers. As they are considered to be secure, the most valuable data is often found by cracking such security measures.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Hands on with the highly anticipated Android 4.0 Ice Cream Sandwich hybrid tablet
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
Project Manager (BI) 6 Months Contract – to...
Desktop Support Manager 3 month contract - to start...
/ Programme Manager / 45k / Significant benefits / London...
Automation Test Manager Selenium London 75k Automation...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?