Well-known security flaws go ignored

'Entire internet' could be at risk, warns analyst

Robert Jaques

Failure to implement effective security policies is leaving the majority of companies open to surprisingly common vulnerabilities, and is even threatening the security of the "entire internet", analysts warned last week.

According to the Open Web Application Security Project (OWASP), which has published a list of the most dangerous internet application security problems, the greatest threat comes from ignoring exploits that are well understood and well documented.

Advertisement

Many of the problems on the OWASP's list can be executed by inexperienced 'script kiddies' using automated cracking tools.

The Washington-based open source project was surprised to find that firms were not deploying countermeasures against well known threats.

"The security issues raised here are not new. In fact, some have been well understood for decades," he said.

"Yet for some reason, major software development projects are still making these mistakes and jeopardising not only their customers' security, but the security of the entire internet."

This view was endorsed by Dr Charles Pflegger, master security architect at Cable and Wireless.

"Flaws continue to be found in applications, even after nearly 50 years of programming experience," he explained. "Worse, the same kinds of flaws appear over and over again.

"This failure to learn from our mistakes and those of our parents' generation, creates far too many vulnerabilities for potential attack. It is no wonder that attacks against applications are on the rise."

The OWASP highlighted the danger of web applications which are not configured to recognise malicious code encapsulated in HTTP requests that can "sail past firewalls, filters, platform hardening, Secure Socket Layer and intrusion detection systems without notice".

While welcoming the report as an attempt to raise awareness of IT security issues, Quocirca strategy analyst Clive Longbottom pointed out that highlighting technical problems could fight only half the battle.

"Just raising a list of problems in isolation will only provide a recipe for fear, uncertainty and dread," he warned.

"Over 95 per cent of UK companies are not large enough to employ dedicated IT security professionals. As a result most will not understand the difference between a command injection flaw and a cross-site scripting exploit.

"In order to better serve this majority of companies the security market needs to stop the techno-babble of stringing acronyms together to describe vulnerabilities.

"They must move away from the technology for its own sake and start offering understandable products and services to deal effectively with these common vulnerabilities."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Related whitepapers

Related jobs

Most watched

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation