Advertisement
Promo

Online business Toolkit

Survey says e-commerce servers still vulnerable

Matthew Broersma ZDNet.co.uk

Published: 20 Aug 2002 15:24 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Virus activity may have declined so far this year, but a new study has found that Internet servers are being left worryingly vulnerable to a series of newly discovered bugs.

According to a survey by UK research firm Netcraft, published on Tuesday, system administrators have been upgrading their Web servers to fix new vulnerabilities, but have been slower about servers used for e-commerce and encryption.

The survey found that almost half of the 22 million monitored sites using Apache software for serving Web pages had been upgraded to version 1.3.26, which fixes a recently publicised vulnerability. But only one quarter of Apache sites using Secure Socket Layer (SSL), which creates the encrypted communications channel typically used for e-commerce, have been updated to this version.

The situation should cause concern, Netcraft said, in light of the discovery of several vulnerabilities in OpenSSL, which can allow an attacker to execute code on a server. "Most sites using Apache for encrypted transactions and e-commerce will be vulnerable to the attack," said Netcraft director Mike Prettejohn in a statement.

Last month, a series of bugs in Microsoft Internet Information Server, Microsoft Commerce Server and Apache led Prettejohn to remark that the Web was more open to attack than ever before. While he called the situation more an incident than a trend, sluggishness to patch the affected servers along with new bugs has kept the window of danger open, Prettejohn said.

Among the most recent security alerts is an easily exploitable flaw in some versions of Apache that could allow attackers to discover where scripts are located on the server, and to execute code on the server.

The survey found that market share for Microsoft servers had declined by 6.48 percent, matched by a 5.89 percent rise in Apache's market share. However, this was accounted for by a periodic platform switch by Register.com, a registrar which controls a large number of domain names.

Netcraft noted that some companies appear to be making good business out of server hosting, identifying six providers that had achieved greater than 30 percent growth since the beginning of this year. The top companies include Rackshack.com, with 88 percent growth, Cybercon.com with 44 percent and Crystaltech.com with 43 percent.

Worryingly for Sun, however, few of these hosting companies now use servers from Cobalt, which were a de facto industry standard before Sun bought the company. In recent months the hosting companies have shifted to IBM, Compaq or generic boxes, Netcraft said. Rackshack placed the largest-ever order for Cobalt servers in December, but dropped the platform at the beginning of this year, Netcraft reported.


For everything Internet-related, from the latest legal and policy-related news, to domain name updates, see ZDNet UK's Internet News Section.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
56 out of 120 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters