ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

NISSC warns over MIME flaws

Dan Ilet ZDNet.co.uk

Published: 14 Sep 2004 10:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The National Infrastructure Security Coordination Centre (NISCC) has released details of hundreds of serious flaws in security products that use the MIME protocol.

Security consultancy firm Corsaire found more than 800 vulnerabilities in what it described as "the top 10" gateway protection products. MIME encodes email attachments and Internet file transfers on HTTP.

"[Vendors] say that the world is wonderful and that they'll protect you from everything," said Martin O'Neil, technical director for Corsaire. "But there have been a number of viruses and worms that get around the MIME protocol."

The firm warned NISCC of 190 attack vectors from 14 core issues with the Multi-Purpose Internet Mail Extensions protocol.

If exploited, the vulnerabilities could allow hackers to bypass content checking and antivirus tools Before going public with the research today, NISCC warned firms last year of the problem, and as a result, many vendors have already prepared patches.

"NISCC has done a really good job of communicating this to vendors. If people have been patching properly, they'll be OK," said Martin O'Neil, technical director for Corsaire.

Corsaire said there were around 100 gateway security products including antivirus, mail content checkers and Web filtering.

The vulnerabilities were found between June and August 2003.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
42 out of 116 people found this useful


Full Talkback thread

0 comments


Related Jobs

NHS - Director - Contract - Healthcare - East Midlands - Apply!

An NHS organisation is looking for a: Highly motivated individual who can aid them with their; 1) Strategic Planning 2) Service Modernisation 3) ...

Assistant Director - NHS

Assistant Director (Adults and Older People) needed for an initial 4 month interim role in the East Midlands. The ideal candidate will have extensive ...

Sussex CRO seek Director of QA (Quality Assurance)

Sussex CRO seek Director of QA (Quality Assurance) Quality Director: My client is a Clinical Research Organisation working across Europe and the US, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment