A few weeks back, I wrote about old worms and attacks that were still propagating around the
Net. I received feedback from folks who said that only in the last six months or so have they seen the death of the Nimda and Code Red worms for the most part. I did some checking and most of my systems now only get a Code Red hit about once a week or less, while Nimda hits have all but disappeared on most of my monitored network segments. These days, the web server top three seems to be ASN.1 exploits, scans for PHP applications and ongoing scans for the Horde application framework. These are almost continual, with ASN.1 hitting about the same rate as scans on our honeypot systems for open spam relays. I’m surprised by this fact because I have a hard time believing that there are web servers out there that still have not been patched and cleaned up from the ASN.1 debacle.
For those organizations using PHP on Internet exposed systems, I expect they feel the true brunt of the ongoing attacks. So much attacker attention is being paid to PHP that it must feel like a never-ending game of patch and counter patch. PHP has its place, and it is a powerful language, but it leaves something to be desired in terms of a history of secure development. security.itworld.com - Top three web server vulnerabilities
From around the Web
- Windows Vista Service Pack 2 Latest Release Schedule
- Vista SP2: What is inside?
- NetWitness releases free version of security software
- Three Reasons Why Users Won’t Buy Into Security
- Automated security testing & its limitations
- Google Wants to Preinstall Chrome Browser on PCs
- Mozilla warns of Firefox China add on
- Firefox No Longer an Automatic Defense Against Browser Drive Bys
- Google patches Chrome file stealing bug
- Apple plays catch up, adds anti fraud safeguard to Safari
- Researchers find vulnerability in Windows Vista
- How to Use Network Behavior Analysis Tools
- The insider security threat in IT and financial services
- Windows 7 security: An overall improvement?
- Windows 7 UAC could be less of a nag