Saturday | 20 March, 2010
CSO
Web Site Damage A Growing Concern
Siobhan Chapman 03/10/2002 11:20:43

Web site defacement is on the rise and IT departments are finding their resources stretched in dealing with the issue, according to security experts.

IT security monitor Zone-H (www.zone-h.org) reported around 88 Australian Web sites which were newly defaced in one day alone, IT security expert Arjen de Landgraaf told Computerworld Today.

"This is only what Zone-H has recorded last week, and by no means the full number of Australian sites that have been compromised over time," Landgraaf, founder and technical director of IT Security alert service E-Secure-IT, said.

"If it is already that easy to go in, it may be simple to dig further, go into the actual intranet, move through to the customer databases, pick up credit card info, or whatever," Landgraaf said, adding most of these defacements could have been avoided.

According to E-Secure IT, in 27.6 per cent of cases, the perpetrators took advantage of a known vulnerability on an unpatched system. Almost 17 per cent used a brute force attack and 16.4 per cent exposed a configuration or an administration mistake.

Landgraaf said a lack of a centralised IT security resources for IT administrators trying to secure systems is to blame. He claims free IT security databases such as E-Secure-DB can provide a knowledge source for IT professionals to determine which of their system components may be vulnerable.

"If only the IT administrators had known what vulnerabilities were a threat, (they) would have been in a position to act. Knowing what to defend is half the battle," Landgraaf said.

"Besides 2,000 fractured, disparate information sources such as security e-mail lists and Web sites, there is no (single) centralised source where the 'Joe Bloggs' of the IT industry can get that information," he said. "Overworked IT administrators do not have the luxury of time or resources to sit behind their PC half the day tracking possible vulnerabilities on obscure e-mail and IRC chat lists."

Grant Bayley, who heads up hacker advocate group 2600 Australia, said, "The window of time between a vulnerability becoming widely known and it being exploited by large numbers of people is dropping fast. It would have been measured in days or weeks several years ago, but it's now measured in hours."

However, Bayley says the number of defacements over the past two years has "gone down pretty dramatically", as mass defacement is in decline. Yet there are some notable exceptions. While the mass defacement problem "largely went away" when operators closed down defacement mirror sites, realising they were "were little more than advertisements for teen criminals showing off their work", Bayley says companies can still make themselves a target for attack. Companies that have disgruntled ex-employees, are embroiled in social or political issues, or fail to follow the most rudimentary IT security procedures can be targets.

"It comes down to a few simple things. Be vigilant, patch machines, use nonstandard configurations, and disable features not being used. If this doesn't apply because you don't host servers internally, get binding guarantees from your service providers," he said.

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the CSO Online comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

Making the move to Ethernet | A DECISION GUIDE

While enterprises today need higher bandwidth, there is increasing demand for solutions that can provide scalability, performance, simplicity and control at lower costs. Get the best of both worlds - read about Ethernet adoption today.

Sponsored Links