The Network Security. Org

RSS Feed

Top three web server vulnerabilities

August 9th, 2006 · No Comments


A few weeks back, I wrote about old worms and attacks that were still propagating around the webserver.jpgNet. I received feedback from folks who said that only in the last six months or so have they seen the death of the Nimda and Code Red worms for the most part. I did some checking and most of my systems now only get a Code Red hit about once a week or less, while Nimda hits have all but disappeared on most of my monitored network segments. These days, the web server top three seems to be ASN.1 exploits, scans for PHP applications and ongoing scans for the Horde application framework. These are almost continual, with ASN.1 hitting about the same rate as scans on our honeypot systems for open spam relays. I’m surprised by this fact because I have a hard time believing that there are web servers out there that still have not been patched and cleaned up from the ASN.1 debacle.

For those organizations using PHP on Internet exposed systems, I expect they feel the true brunt of the ongoing attacks. So much attacker attention is being paid to PHP that it must feel like a never-ending game of patch and counter patch. PHP has its place, and it is a powerful language, but it leaves something to be desired in terms of a history of secure development. security.itworld.com - Top three web server vulnerabilities

From around the Web

  • Advertisments