Showing posts with label Vulnerability. Show all posts
Showing posts with label Vulnerability. Show all posts

Saturday, November 1, 2008

IRS finds unauthorized Web servers connected to its networks

The Internal Revenue Service found more than 1,000 unauthorized Web servers connected to its networks, leaving the agency's systems open to hackers, according to a report released on Thursday by the IRS inspector general.

In September 2007, the IRS Computer Security Incident Response Center scanned the agency's Web servers and identified 2,093 that had at least one security vulnerability. When the center matched those servers to the IRS database of registered Web sites and servers, an inventory of systems that the agency uses to perform security maintenance and apply patches, it found 1,811, or 87 percent, were not listed in the database.

Of the unregistered servers, the IRS identified 661 that were used for legitimate agency business, leaving 1,150 servers being used for potentially unauthorized activity, according to the report. .. More ..

Saturday, March 1, 2008

Half of 2006 vulnerabilities still unpatched

It is important that when vendors send patch updates, these are implemented to prevent weaknesses from being exploited and depending on the system set up, can cause major interruptions to infrastructure. Despite its importance organisations still lack the diligence to keep up in updating the patches.

More than 3600 vulnerabilities discovered last year remain unpatched, according to a study.

The IBM Internet Security Systems (ISS) X-Force report for 2007 found of the 6437 vulnerabilities discovered, 20 percent of those targeting Microsoft, Apple, Oracle, IBM and Cisco were still in the wild up to 12 months later.

More than 50 percent of remaining 6200 flaws targeting other solutions remain currently unpatched. >> More....

Friday, December 28, 2007

Top Ten Information Security Risks of 2008

This list which in fact covers Threats, Vulnerabilities, Impacts, Risks and Controls assembled by the CISSP Forum and the ISO 27K Implementers' Forum. The list of course includes threats and risks to Critical Information Infrastructure.

Those who are still confused with the definition and differences of Threat, Vulnerabilityu, Impact, Risk and Control, this article does list and discuss the brief definitions and the actual lists of the above will illustrate the definition further.

This is a must read for all involved in security. >> More...

Monday, November 19, 2007

2006 OS Vulnerability Summary

This report analyses and discuss about the OS Vulnerabilities. >> More..

Monday, October 15, 2007

Hole Found in Protocol Handling Vital National Infrastructure

Researchers on March 21 announced that the systems which control dams, oil refineries, railroads and nuclear power plants have a vulnerability that could be used to cause a denial of service or a system takeover.

The flaw, reported by Neutralbit , is the first remotely exploitable SCADA security vulnerability, according to the security services provider.

Neutralbit identified the vulnerability in NETxAutomation NETxEIB OPC (OLE for Process Control) Server. OPC is a Microsoft Windows standard for easily writing GUI applications for SCADA. It's used for interconnecting process control applications running on Microsoft platforms. OPC servers are often used in control systems to consolidate field and network device information. >> More ..

Those who want more technical details on the vulnerabilities can find them here.

Friday, October 12, 2007

OWASP Preps Framework for Website Security Certification

The Open Web Application Security Project (OWASP) is working on a potential framework for evaluating and certifying Websites as secure, including the criteria that would entail. The project is still in progress and not quite ready for prime time, but the goal is to provide a framework for certifying the security of a site's apps, which entails much more than just the usual vulnerability scan.


"A black box scan doesn't mean a site is secure," says Dinis Cruz, OWASP's technology evangelist and project coordinator for the so-called Web Security Application Certification Framework Project.


Several commercial certifications already exist, including ScanAlert's Hacker Safe, and ControlScan, which indicate that a site has been vulnerability-scanned. And the Extended Validation SSL (EV SSL) moniker, championed by digital certificate vendors such as VeriSign and Cybertrust, helps verify that a site is legitimate. (See Are 'Sealed' Websites Any Safer?).


But security experts say today's Good Housekeeping-style seal-of-approvals aren't enough. "The fact is that in this day and age, the VeriSign logo and the lock icon in your browser just don't cut it," says Caleb Sima, CTO of SPI Dynamics. >> More ..

Sunday, October 7, 2007

Hackers Step Up SCADA Attacks

This 2004 article says that "A majority of cyber attacks on industrial control systems now come from the outside, reversing earlier assumptions, according to research at the British Columbia Institute of Technology."

The full article can be found here.

Control Systems, Instrumentation Systems and Automation Security

A number of articles relating to Control Systems, Instrumentation Systems and Automation security can be found from the Instrumentation Systems and Automation site here.

Amongst the relavant articles are:
1. Making Cyber Security Work in the Refinery
2. Uncovering Cyber Flaws
3. SP99 Counterattacks
4. Securing the Power Grid . This article also has a good chronological chart on the 2003 power blackout in OHIO that crippled a part of the nation.
5. ISA99, Manufacturing and Control Systems Security ISA99 is a new standard for Manufacturing and Control Systems Security. The current edition covers only security technologies and their strengths/weaknesses in the manufacturing environment. Eventually this would be expanded to include traditional strengths and weaknesses of the different types of control systems (DCS, PLC, SCADA, HMI, etc). The end of the article contain a list of materials in the development of ISA99 by the ISA SP-99 Committee.

America's Hackable Backbone

This article is a MUST READ article. It highlights the vulnerability of SCADA systems.

SCADA systems are used around the country to control infrastructure like water filtration and
distribution, trains and subways, natural gas and oil pipelines, and practically every kind of industrial manufacturing. And as some security professionals are pointing out, those weaknesses are increasingly connected to the Internet, leaving large parts of America's critical infrastructure exposed to anyone with moderate information technology training and a laptop.

The full article can be found here.

However those who want a pictorial rundown of the story can find it here. The pictorial story covers incidents and potential vulnerabilities of SCADA systems controlling power plants, oil and gas pipelines, transportation, dams, manufacturing, water distribution.

Malicious Code Affects Chinese Security Site

Even security organizations are not spared from cyber attacks!!

The Web site of one of China's Internet security organizations has been laced with malicious code.

At least three pages on the Chinese Internet Security Response Team's (CISRT) Web site are rigged with a malicious "iframe," a hidden window on a Web page that can allow code such as JavaScript to run on a visitor's PC.

See here for the full news.

Water Utility Computer System Susceptible to Cyber Attack

In a 2005 article, it was reported that computer-based monitoring and control systems installed by water utilities "may be susceptible to attacks" by cyberterrorists.

See here for the full article.