« ABC Internet TV Beta Trial | Main | How copyright produces crap »

March 23, 2008

Cenzic - Top 10 Vulnerabilities Q4 2007

This for obvious reasons caught my eye this morning in my RSS reader via Dave Northey so I jumped over to look at the entire Cenzic - Top 10 Vulnerabilities of Q4, 2007 (PDF) report . The details contained in the report show that  web browsers only made up 5% of the total for web technology vulnerabilities with web servers and web applications making up the balance at 10% & 85% respectively and the report does state 'Unlike previous quarters, less vulnerabilities were reported in Internet Explorer than in Opera, Firefox or Safari'.


Cenzic - Application Security Trends Report Q4 2007

The overall 'Q4 2007 Top 10 Vulnerabilities'.

  1. OpenSSL (Execute Arbitrary Code)
  2. Java (Remote Read/Write File Access)
  3. Adobe Acrobat (Execute Arbitrary Code)
  4. IBM Lotus Notes (Execute Arbitrary Code)
  5. RealPlayer (Execute Arbitrary Code)
  6. IBM WebSphere (Cross-Site Scripting)
  7. IBM WebSphere  (Script Injection)
  8. PHP (Elevated Privileges)
  9. Apache (Cross-Site Scripting)
  10. Adobe Flash (Cross-Site Scripting)

The 'Top 5 Vulnerability Trends for 2007'

  1. Javascript Trickery: Hiding, Anti-Pinning and Mutating
  2. Universal Cross-Site Scripting in Adobe Acrobat Reader
  3. Mass-SQL Injection Worm
  4. Google Gadgets and Gmail Hacks
  5. Google Orkut Cross-Site Scripting Worm

With 67% of attacks reported 'for the purpose of financial gain' the days are long gone when people just did it for '15 minutes of fame'. These days it is big business and you can even pick up some extra cash 'Breaking Google Capchas' and you need to ensure that you don't become complacent with your online privacy either.

Whatever operating system and software combinations you use ensure that you regularly check that you have the latest security updates and  patches and take care when giving out personal data.

Posted by Stephen at March 23, 2008 01:54 PM

Trackback Pings

TrackBack URL for this entry:
http://bleedingedge.com.au/cgi-bin/mt/mt-tb.cgi/1442

Comments

Post a comment




Remember Me?



(you may use HTML tags for style)