Recent Articles

Educational Changes in the Field of Information Technology
As the information technology industry has grown, so have the related educational opportunities.

IT Specialists: Are Non-Profits a Viable Market?
Yes, non-profits are viable. But there are certainly more financially rewarding sectors for IT specialists.

Microsoft Offers U2 Licensing
Hardware licenses for technologies developed by Microsoft provide third-party firms the opportunity to build devices based on those innovations.

Google Analytics Slowing Down Websites
Google recently updated some of the Javascript fetched every time a page using Google Analytics is loaded. The new code is slowing down all matter of websites...

Adoption Strategy for Social Software in the Enterprise
Perhaps the greatest competency Socialtext has gained over the past three years is fostering adoption of social software.

Vista Gets Throttling
Liked Netflix's throttling, where customers who order lots of movies get screwed by an algorithm that pushes them down the queue? Well, Windows Vista...

Questionable Influence of Industry Research Firms
InformationWeek has an interesting, albeit exhaustive feature today on the influence that tech vendors wield over IT research firms:

Search Engines: Release DOJ Data
After all, as Cory Doctorow et al at BoingBoing point out, if there is no personally identifiable information in the data, there is no reason to keep it from being posted for review.



05.02.06


Mac Security Reputation 'is In Tatters'

By David A. Utter

The SANS Institute released its spring update of the top 20 Internet security vulnerabilities, and the increased adoption of Mac OS X and the Firefox browser have made them more tempting to malicious hackers.

SANS provided an update to its top 20 vulnerabilities list, to ensure the newest and most important ones are brought to the attention of security professionals everywhere.

Long regarded as much more secure than Windows, Apple's Mac OS X has slowly become a more attractive target for attacks. "OS/X still remains safer than Windows, but its reputation for offering a bullet-proof alternative to Windows is in tatters," SANS said.

Microsoft still figures prominently in several places on the list, thanks to the "continuing discovery of multiple zero-day vulnerabilities in Internet Explorer." SANS also noted a "substantial decline" in critical vulnerabilities in Windows Services, which unfortunately has been offset by the client-side problems in Windows and Internet Explorer.

Firefox and the Mozilla Foundation have found the price of fame includes a following from fans it does not want. SANS said there has been "rapid growth in critical Firefox and Mozilla vulnerabilities," as attackers continue to probe those products for arbitrary code execution weaknesses.

Managed Hosting Solutions Powered By Rackspace
Click here for more information

SANS also observed a couple of disturbing trends. One concerns zero-day attacks, which they claim are used to "infiltrate systems for profit motives." Adware figures in this trend, they noted:

One possible explanation is that cyber crime has become so lucrative - reaching at least $10 billion per year -- that huge sums of money are being spent to sponsor research to find more vulnerabilities faster. Many vulnerabilities being found make their way into zero-day attacks meant to collect zombies to be infected with lucrative adware downloads.

The other vulnerability can't be blamed on software, but "gullible users" instead. SANS cited a three-year series of disciplined attacks emanating from hostile countries against US, Canadian, and British government interests has escalated to a higher pitch.

Defense and nuclear sites have been specifically targeted, but SANS did not discuss which sites, or which countries have been the sources of the attacks. Spear-phishing attacks aimed at users at those sites try to entice users to download a piece of software for security needs.

They end up downloading a Trojan file that steals information, sends it back to its distributor, and opens a back door for future intrusions.


About the Author:
David Utter is a business and technology writer with WebProNews.

About ITProNews
News and updates for the IT professional

ITProNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
PerlProNews.com SQLProNews.com
SysAdminNews DevWebPro.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITCertificationNews.com


-- ITProNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
©2006 iEntry, Inc. All Rights Reserved Privacy Policy Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article




ITProNews News Archives About Us Feedback ITProNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact