ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Infosecurity Europe 2008

Businesses face new breed of security threats

Tim Ferguson silicon.com

Published: 10 Apr 2008 09:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

"Pass the hash" and "metasploit" are two of a breed of emerging security threats facing corporate IT departments.

The key security threats facing businesses range from mutations of established phenomena — such as malware or phishing — to less well-known ones, such as metasploit releases and pass-the-hash attacks.

The most dangerous new security threats were revealed by experts at the RSA security conference in San Francisco this week.

Ed Skoudis, a hacking expert at the Sans Institute, said most security threats stem from the fact that so many applications are now linked to the internet.

He said: "We've web-ified all applications."

Among the less familiar new threats are metasploit releases, which target networks by simultaneously attacking a number of vulnerabilities (up to 200) on different platforms, including Windows, Linux and the iPhone.

Pass-the-hash attacks, which use stolen password hashes to access other systems in a targeted network — avoiding more time-consuming password-cracking — were also singled out.

Although this approach has been around for some time, it is only now that it's becoming prevalent. Skoudis said: "These attacks have been around for years but now the tools are out there."

Read this

Feature
Corporate espionage: Not if, but when

When it comes to business-to-business theft of information, experts agree — it's best to assume it will happen to your company

Read more +

Website attacks, which plant browser exploits to compromise users, are also becoming more of a problem, as they are able to target well-known, high-traffic sites.

A major threat is browser scripting attacks, which use web browsers to get through corporate firewalls, allowing access to confidential information.

While not a new threat, the development of botnets remains a big security concern because the "fast flux" approach used by attackers to protect their robotic networks is making the life of botnet investigators difficult.

The security experts also warned about the threat of malware being spread through the use of embedded devices, such as memory sticks — now one of the main ways harmful code is brought into businesses.

Credit: Security threats revealed: Beware the metasploit from silicon.com

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

0 comments


More in this Special Report

Blog: Social networking and portability

Blog: Social networking and portability

One of the more interesting speakers at Infosec's "Locking Down Social Networking Vulnerabilities" event today was Giles Hogben of the European Network and Information Security Agency (ENISA) more

ICO: Data-protection spot checks due this year

ICO: Data-protection spot checks due this year

The information commissioner has confirmed that his office will be getting new powers to carry out spot checks on any company in the UK holding data on individuals more

Infosecurity Europe 2008: Preview

Infosecurity Europe 2008: Preview

Over 11,000 delegates and 320 exhibitors will attend one of Europe's largest IT security shows on Tuesday at London's Olympia conference centre more

Security breaches down, says IT security report

Security breaches down, says IT security report

The latest Information Security Breaches Survey has reported that while the number of security breaches has fallen in the past two years, the average spend on defences has increased more

Facebook admits to increased attacks by spammers

Facebook admits to increased attacks by spammers

The social-networking site has come under increased attack by spammers and phishers this year, according to its head of security more

Security industry gears up for biggest UK event

Security industry gears up for biggest UK event

Infosecurity Europe 2008 is underway in London and will include keynotes and product demos from the some of the leading organisations in IT security more

Vendors urged to take responsibility for security

Vendors urged to take responsibility for security

When it comes to the security of hardware and software, suppliers should be put on the spot, argue experts at Infosecurity Europe 2008 more

Media lobbying 'watered down' data-misuse laws

Media lobbying 'watered down' data-misuse laws

As a result of media lobbying, the information commissioner says another serious data breach will need to occur before prison sentences for data misuse are imposed more

HMRC data loss blamed on targets

HMRC data loss blamed on targets

Merlin, Lord Erroll, believes targets and budgets rather than individuals should be blamed for the loss of 25 million UK citizens' confidential records last year more

Former White House adviser talks mobile threats

Former White House adviser talks mobile threats

Security strategist Howard A Schmidt discusses whether mobile attacks are overhyped and what new risks have been introduced by virtualisation more

Security expert voices virtualisation concerns

Security expert voices virtualisation concerns

Mikko Hyppönen, chief research officer for security specialist F-Secure, claims virtualisation technology will have its own specific security threats more

Lord: No proof any data was lost from HMRC

Lord: No proof any data was lost from HMRC

Security expert Merlin, The Earl of Erroll, claims no evidence has come to light to prove data was actually lost in last year's HMRC missing-disc incident more

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Accenture Siebel Consultants-00037335

Successful candidates should possess strong team working, self-management, communication, issue resolution and client facing skills suitable to a ...

Surrey-based Quality Assurance (QA) Manager

The role involves providing GMP compliance solutions to internal and external customers, hands-on management of the Quality department, including ...

Performance Engineering Consultant / Manager-00038060

You will be assigned to client facing roles across a variety of industry sectors including financial services, high-technology and communications, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment