Calgarypuck Forums - The Unofficial Calgary Flames Fan Community
Old 11-03-2012, 11:25 AM   #1
Mike F
Franchise Player
 
Mike F's Avatar
 
Join Date: Jul 2003
Location: Djibouti
Exp:
Default Top IT Security Vulnerabilities

Admittedly this is barely thread worthy, but I did find the new report by Kaspersky of the Top 10 Security Vulnerabilities very surprising for who was on and who was absent:
  1. Oracle Java Multiple Vulnerabilities: DoS-attack (Gain access to a system and execute arbitrary code with local user privileges) and Cross-Site Scripting (Gain access to sensitive data). Highly Critical
  2. Oracle Java Three Vulnerabilities: Gain access to a system and execute arbitrary code with local user privileges. Extremely Critical
  3. Adobe Flash Player Multiple Vulnerabilities: Gain access to a system and execute arbitrary code with local user privileges. Gain access to sensitive data. Highly Critical.
  4. Adobe Flash Player Multiple Vulnerabilities: Gain access to a system and execute arbitrary code with local user privileges. Bypass security systems. Highly Critical.
  5. Adobe Reader/Acrobat Multiple Vulnerabilities: Gain access to a system and execute arbitrary code with local user privileges. Extremely Critical.
  6. Apple QuickTime Multiple Vulnerabilities: Gain access to a system and execute arbitrary code with local user privileges. Highly Critical.
  7. Apple iTunes Multiple Vulnerabilities: Gain access to a system and execute arbitrary code with local user privileges. Highly Critical.
  8. Winamp AVI / IT File Processing Vulnerabilities: Gain access to a system and execute arbitrary code with local user privileges. Highly Critical.
  9. Adobe Shockwave Player Multiple Vulnerabilities: Gain access to a system and execute arbitrary code with local user privileges. Highly Critical.
  10. Adobe Flash Player Multiple Vulnerabilities: Gain access to a system and execute arbitrary code with local user privileges. Bypass security systems. Gain access to sensitive data. Extremely Critical.

I had no idea Adobe products were so vulnerable, and was surprised to see 2 Apple products and no Microsoft products on the list given the common conception about the two companies.
Mike F is offline   Reply With Quote
Old 11-03-2012, 11:48 AM   #2
sclitheroe
#1 Goaltender
 
Join Date: Sep 2005
Exp:
Default

Quote:
Originally Posted by Mike F View Post
I had no idea Adobe products were so vulnerable
#1 risk vector today, especially in business. Flash in the browser and Reader handling PDF's is a security minefield.

Now Adobe has tried to fix some of this by introducing an auto-update mechanism to their products (Flash in particular), not unlike Windows Update - however, I am deeply concerned it will get compromised and allow a mass deployment of a trojan'ed version of Flash. They have already had one security breach along these lines allowing Flash applications to be signed with their private key - the only thing that didn't happen was it getting published to their auto-update server.

The same concern exists for other update mechanisms (Microsoft Update and Apple's App Store update process are the big ones of course), but Adobe is especially "special" when it comes to security in my opinion.
__________________
-Scott
sclitheroe is offline   Reply With Quote
The Following User Says Thank You to sclitheroe For This Useful Post:
Old 11-03-2012, 01:23 PM   #3
Flash Walken
Lifetime Suspension
 
Flash Walken's Avatar
 
Join Date: Sep 2005
Location: The Void between Darkness and Light
Exp:
Default

So what's the deal with java?

Is it safe? Is it Superaids? Is it sometimes superaids if you go to eastern european porn sites or chinese warez links?
Flash Walken is offline   Reply With Quote
Old 11-03-2012, 07:57 PM   #4
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Not really surprised by any of the culprits, but QuickTime. Adobe and Java easily are the single largest time sinks in my desktop hardening regime.

I have been severely tempted to remove Flash and Java from all of our machines and see how long I can stomach the fallout.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 12:08 AM.

Calgary Flames
2023-24




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright Calgarypuck 2021