![]() |
![]() |
|
May 02, 2005Hackers aren't just picking on MicrosoftAccording to some research completed by SANS, online criminals turned their attention to antivirus software and media players like Apple's iTunes in the first three months of 2005 as they sought new ways to take control of users' computers. On a news article I read on Yahoo, they had some interesting quotes I thought some of you may be interested in:
Anti-virus products from Symantec, F-Secure, TrendMicro and McAfee, proved vulnerable as well, a prospect Paller found particularly discouraging. Amen. But this is an industry wide problem. Here is a poster I think I need to make for our office: SECURITY PRODUCTS != SECURE PRODUCTS Secure software programming is a discipline that all software vendors need to embrace. Not just operating system and security software vendors. And the issues of vulnerabilities in all software will continue to grow as hackers move on to easier and easier targets in popular applications that most people are using. So none of us are immune. We need to be on our guard and write safe code. We need to follow the principles of secure coding and ensure our clients are not only safe, but secure in their business workflow with the tools they use built by us. And this has to have buy in from all stakeholders in the ISV, from the CEO all the way down to the junior programmer that is just starting up. Posted by SilverStr at May 2, 2005 08:22 AM | TrackBackComments
Yes, but do you think that they are going to try to exploit itunes on a mac, or itunes on a windows system? I'm going to guess at the latter, and though I don't know a lot about exploits, I'm going to guess that they are going to be exploiting a flaw in itunes so that they can get through and exploit a flaw in the windows core software. If they were exploiting flaws in safari or rhythmbox, or some other one OS only software I'd agree with the 'not targetting microsoft' statement, but just using other not securely written software to take control of windows systems isn't going to convince me the tide has turned. That said, lets hope realplayer/itunes/etc beefs up their code :) Posted by: Arcterex at May 2, 2005 03:24 PM |
![]() ![]()
My 5 Favorite Books
Writing Secure Code
Secure Programming Cookbook Security Engineering Secure Coding Principles & Practice Inside the Security Mind ![]()
My 5 Favorite Papers
Smashing the Stack
Penetration Studies Covert Channel Analysis of Trusted Systems DoD Trusted Computer System Evaluation Criteria NSA Security Recommendation Guides ![]()
Archives
December 2005
November 2005 October 2005 September 2005 August 2005 July 2005 June 2005 May 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004 August 2004 July 2004 June 2004 May 2004 April 2004 March 2004 February 2004 January 2004 December 2003 November 2003 October 2003 September 2003 August 2003 July 2003 June 2003 May 2003 April 2003 March 2003 February 2003 January 2003 December 2002 November 2002 October 2002 September 2002 August 2002 July 2002 ![]() |
|