, SecurityFocus 2006-09-15
Less rigor in Web programming, an increasing variety of software, and restrictions on Web security testing have combined to make flaws in Web software the most reported security issues this year to date, according to the latest data from the Common Vulnerabilities and Exposures (CVE) project.
A draft report on the latest numbers from the vulnerability database found that 4,375 security issues had so far been cataloged in the first nine months of 2006, just shy of the 4,538 issues documented last year. The data shows that Web flaws have continued their meteoric rise since 2005, capturing the top-three spots on the list of most common vulnerabilities. Buffer overflows, a perennial favorite, fell to the No. 4 slot.
"The takeaway is that researchers are paying a lot more attention to Web vulnerabilities, and if companies don't want to get caught up in that, then they need to pay attention to those flaws," said Steven Christey, the security researcher that authored the draft report and the CVE Editor for The MITRE Corp., a nonprofit government contractor.
The jump in Web-based vulnerabilities is fueled by the simplicity of exploiting many of the most common Web vulnerabilities, the enormous number of Web applications freely available, and the difficulty in eradicating cross-site scripting flaws. Moreover, while many of the vulnerabilities are easy to test for and find, independent security researchers are less likely to probe another group's Web site to find the flaws, because doing so violates computer intrusion statutes. The case of Eric McCarty illustrates the danger: The network administrator found a database vulnerability in the online application site for the University of Southern California but was prosecuted for his unauthorized access of the server and last week agreed to plead guilty.
Easy-to-use Web programming languages are also to blame, because they attract people who have not programmed before and can be more easily audited for flaws, Christey said.
"The existence of these web-friendly languages, like PHP, lowers the bar for someone to create a useful application but also lowers the bar for someone to find vulnerabilities in that application," he said.
In the CVE Project's latest numbers, flaws that use a technique for injecting code from one Web site into another, known as cross-site scripting or XSS, accounted for 21.5 percent of the vulnerabilities reported so far in 2006.
Cross-site scripting is considered by many security researchers to be a less-than-hackerly technique used by script kiddies, phishers and spammers to fool trusting users. The technique is a key method for injecting malicious code into a victim's Web session. Cross-site scripting allows a malicious Web site to inject code into the context of another Web site; a user that believes they are interacting with a popular social networking site, for example, might instead be loading a script in from some other malicious site.