Advertisement
Promo

Security threats Toolkit

Browser flaws biggest software security risk

Tom Espiner ZDNet.co.uk

Published: 15 Sep 2006 18:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The most common software flaws are now cross-site scripting (XSS) vulnerabilities, according to US Government organisation Mitre.

XSS flaws have accounted for 21.5 percent of the vulnerabilities found in 2006 so far according to Mitre statistics.

XSS vulnerabilities potentially allow attackers to access sensitive data from a web site by bypassing security in browsers using JavaScript.

SQL injection flaws, which can occur in database-backed web applications, accounted for 14 percent of vulnerabilities seen.

PHP remote file vulnerabilities accounted for 9.5 percent of the 20,000 flaws collated by Mitre, said DarkReading.com.

PHP, a web scripting language, can be vulnerable to attack if applications created using it are not carefully written. PHP implementations are often considered notoriously poorly coded, according to security vendor Sophos.

Buffer overflow vulnerabilities slipped from being the most prevalent in 2003 to accounting for 7.9 percent of holes in 2006.

However, Sophos said that it hadn't seen any noticeable shift in terms of attacks on these flaws, including buffer overflow holes. Sophos questioned how the statistics had been collated and the potential severity of the flaws, due to the limited number of people who use smaller web servers.

"There is a danger that these folks are comparing apples with oranges," said Graham Cluley, senior technology consultant with Sophos. "After all, you could find lots and lots of vulnerabilities in Fred's Internet Utility, but that wouldn't be something we would consider to be a bigger problem than just one vulnerability in a widespread technology like [Microsoft's] Internet Information Services."

Cluley said that XSS attacks are very common on less popular web servers and applications, but that the more widely used packages are less likely to have such flaws.

According to Cluley, the Mitre statistics do not indicate a shift in the type of software that attackers are targeting, merely that the proliferation of flawed applications with few users is skewing the statistics.

"The fact is that there are more small .Net, Java and PHP implementations of blogging and webhosting than there are Internet side C-based software platforms," said Cluley.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
211 out of 351 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

3 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters