Your Daily Source for Apache News and Information  
Breaking News Preferences Contribute Triggers Link Us Search About
Apache Today [Your Apache News Source] To internet.com

The Premier Event for Grid Computing Products/Services

Apache HTTPD Links
Apache Module Registry
Apache-Perl Integration Project
PHP Server Side Scripting
Apache Project
The Apache Software Foundation
The Java Apache Project
The Apache FAQ
Apache XML Project
Apache-Related Projects
ApacheCon
The Jakarta Project
The Linux Channel at internet.com
Linux Planet
Linux Central
Linux Today
Linux Apps
Just Linux
Linux Start
Linux Programming
Apache Today
All Linux Devices
Linuxnewbie.org
BSD Central
BSD Today
Enterprise Linux Today
PHPBuilder
SITE DESCRIPTIONS
VNU Net: Weak Security Found in Many Web Servers
Sep 7, 2000, 17 :40 UTC (2 Talkback[s]) (1653 reads) (Other stories by John Leyden)

By John Leyden, VNU Net

One in three supposedly secure ebusiness servers are using software with known security weaknesses, and European sites are the worst offenders, according to a survey.

Eric Murray, a consulting security architect based in the US, found that in a random sample of more than 8000 web servers running the SSL protocol, 32 per cent were "dangerously weak."

Murray explained that these weak servers either support only the flawed SSLv2 protocol, use weak encryption, or have expired or self-signed digital certificates.

"These weaknesses make the transactions that are protected by these servers easy to attack with modern key-cracking and/or hacking attacks," said Murray, who added that there is no good reason for sites not to address the problems he has highlighted.

There is no technical or legal reason to limit secure servers to using only SSLv2, since SSLv3, which corrects known weaknesses, is available. Since US export regulations were relaxed in January to allow the export of 128bit cryptographic products, there is also no reason to support only 40bit cipher suites or 512bit RSA keys.

The survey revealed that security of European servers is particularly weak, because many still used web servers obtained before the export restriction were relaxed. This was found to be particularly the case for sites running Microsoft's Internet Information Server rather than those running Apache.

The fact that many sites are vulnerable for no good reason is, according to Murray, explained by a tendency for businesses not to update their security software until websites become breached.

"Many sites don't bother to update or patch software, even when it is readily available, until they're forced to do so because someone has broken in. Until then, they are still open to well-known vulnerabilities," said Murray.

Matt Tomlinson, business development director at IT security consultancy MIS Corporate Defence, said the survey is one of the most comprehensive he had come across, and said the figure of a third of so-called secure websites actually being insecure matched the experience of MIS in the UK.

"Even if a web server is secure that is not the end of the issue. There is also the possibility of backdoors into a network, and hackers will not always go to the obvious point when they launch attacks," said Tomlinson.

Want to discuss security and Apache with other Apache Today readers? Then check out the discussions at Apache Today Discussions.

  Current Newswire:
Another mod_xslt added to the Apache Module Registry database

Netcraft Web Server Survey for December is available

O'Reilly: Apache Web-Serving with Mac OS X: Part 1

WDVL: Perl for Web Site Management: Part 3

Retro web application framework V1.1.0 release

Leveraging open standards such as Java, JSP, XML,J2EE, Expresso and Struts.

Netcraft Web Server Survey for November is available

FoxServ 2.0 Released

Ace's Hardware: Building a Better Webserver in the 21st Century

Web Techniques: Customer Number One

 Talkback(s) Name  Date
>Murray explained that these weak servers either support only the flawed SSLv2 > ...   Self signed.   
  Sep 7, 2000, 18:13:12
It has been my experience that with SSL v3 enabled many older browsers,noteable ...   SSL V3 and old browsers   
  Sep 8, 2000, 09:35:04
Enter your comments below.
Your Name: Your Email Address:


Subject: CC: [will also send this talkback to an E-Mail address]
Comments:

See our talkback-policy for or guidelines on talkback content.

About Triggers Media Kit Security Triggers Login


All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux 2.4, Apache 1.3, and PHP 4
Copyright INT Media Group, Incorporated All Rights Reserved.
Legal Notices,  Licensing, Reprints, & Permissions,  Privacy Policy.
http://www.internet.com/