Click here to receive your FREE subscription to Campus Technology
5/13/2008
Organizations still aren't doing enough to protect their data from Web application vulnerabilities, according to a study released Tuesday by security firm Cenzic. The study, Application Security Trends Report, Q1 2008, identified "1,409 unique published vulnerabilities for the first quarter of 2008, with Web technology vulnerabilities comprising 70 percent of the vulnerability volume and 65 percent of the total vulnerabilities classified as easily exploitable," according to Cenzic.
According to the report, the most prevalent vulnerabilities were in the areas of information exposures/leaks, cross-site scripting, and "session management." Other highlights included:
"We're seeing many patterns over time, and our results remain consistent with the Symantec Internet Security Threat Report for the second half of 2007--that organizations are still not taking the proper initiatives to secure their Web applications," said Mandeep Khera, vice president of marketing at Cenzic, in a statement released to coincide with the report. "With organizations required to become compliant with PCI requirement 6.6 by June 30, they need to act aggressively. Many of these vulnerabilities are being discovered in the most commonly used commercial applications. However, most proprietary applications have even more vulnerabilities that are never fixed. PCI Compliance is important, however it's even more important to protect customer information by getting security vulnerabilities fixed in applications."
The vulnerabilities affected a wide range of technologies, from home-grown applications to commercial or publicly available technologies from Adobe, IBM, Microsoft, Sun, and others. The percentage of overall vulnerabilities stemming from Web applications remained consistent with reports dating back to early 2007, with each quarter hovering within two points of 70 percent.
Of these Web application vulnerabilities, 82 percent stemmed from the application itself; 12 percent were the fault of the Web server; 3 percent were attributable to Web browsers; and another 3 percent fell at the doorstep of media players.
The breakdown in vulnerabilities went something like this:
The complete study, with breakdowns of the top-10 specific vulnerabilities, is available for download from Cenzic's site in PDF format here.
About the author: Dave Nagel is the executive editor for 1105 Media's educational technology online publications and electronic newsletters. He can be reached at dnagel@1105media.com.
Have any additional questions? Want to share your story? Want to pass along a news tip? Contact Dave Nagel, executive editor, at dnagel@1105media.com.
copy text (above) for proper citation
The Foundation for California Community Colleges (FCCC) has awarded a statewide emergency alert notification contract to Waterfall Mobile. The contract establishes Waterfall's AlertU as an approved technology through the official non-profit foundation for the California Community College (CCC) system office. Through this partnership, individual colleges may directly implement emergency communication services, eliminating lengthy technology evaluation and RFP processes.
King's College and Arizona State University have switched to Omnilert's e2Campus for emergency notification. Omnilert also has introduced a new program called the ENS Conversion Service that allows schools to bulk upload data from their previous emergency notification system into e2Campus at no charge.
Saint Joseph's University has begun deploying a Meru Networks wireless local area network across its Philadelphia campus as part of a multi-year effort to bring wireless coverage to every building on campus.
Organizations may have been slow to adopt Microsoft Windows Vista, but expect that to change by late 2008 to 2009, according to a Forrester Research report by Benjamin Gray et al., published last week.
Talisma Corp. announced version 8.0 of its constituent relationship management (CRM) application for higher education. The new release includes application management, a revamped user interface, two-way text messaging, personalized Web portals, and an ADA-compliant Web client, among other enhancements.
Two Pennsylvania teaching colleagues with an interest in music and technology are bringing remote experts into classrooms at almost no cost, using Skype's free videoconferencing technology.