Home > Security News > Metasploit creator promises browser flaws galore
Security News:
EMAIL THIS
COLUMN

Metasploit creator promises browser flaws galore

By Bill Brenner
07 Jul 2006 | SearchSecurity.com


Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Security Blog Log
Looking for a blog that outlines the latest security holes in the most popular Web browsers? If so, Metasploit Framework creator H.D. Moore has just the thing: a new vulnerability listing site called the Browser Fun blog.

Moore -- whose Metasploit Framework is used for penetration testing, IDS signature development and exploit research -- has declared July the "Month of Browser Bugs." In a message posted to the official Metasploit blog, he promised new browser-flaw details each day this month.

"The vendors have been notified and the time has come to start publishing the results," Moore said. "This information is being published to create awareness about the types of bugs that plague modern browsers and to demonstrate the techniques I used to discover them."

In the Browser Fun blog, Moore is quick to point out that the details will be displayed with care. "The hacks we publish are carefully chosen to demonstrate a concept without disclosing a direct path to remote code execution," he said.

About Security Blog Log

Senior News Writer Bill Brenner peruses security blogs each day to see what's got the information security community buzzing. In this column he lists the weekly highlights. If you'd like to comment on the column or bring new security blogs to his attention, contact him at bbrenner@techtarget.com.

Recent articles:
Would Blue Pill create a matrix for PCs?

Microsoft and the peril of predatory pricing

Doing good with exploit code

Here's what was posted as of Thursday morning:

  • July 2: Three Internet Explorer flaws.

  • July 3: One flaw in Mozilla Firefox 1.5.0.2 running on Gentoo Linux, which was fixed in Firefox 1.5.0.3.

  • July 4: One flaw in Safari, tested on a fully patched Mac OS X machine.

  • July 5: One flaw in Internet Explorer, tested on a fully patched Windows XP SP2 machine.

    Reaction so far seems to be that of detached amusement, sprinkled with some hope that vendors will put the intelligence to good use.

    "It is interesting to see how horribly buggy browsers can be," computer security specialist Dominic White wrote in his blog. "I am most interested in seeing which browser gets broken the most and if we can take any defense-in-depth lessons from this."

    Hopefully, he said, vendors will take all the details and release one patch for all of the bugs affecting their browser, "because nobody has the resources to run about patching user's browsers several times a month."

    Taking a swipe at Microsoft, one respondent to Moore's posting on the Metasploit blog wrote, "Why not release one bug on the second Tuesday of each month? Then the bugs would last at least two and a half years."

    To that Moore responded, "We could probably release one a day for the next two and a half years without running out of bugs."

    McAfee laments a malware milestone
    Santa Clara, Calif.-based antivirus vendor McAfee Inc. used its Avert Labs blog this week to mark a grim milestone: the 200,000th entry into its VirusScan malware detection database.

    Since it took 18 years to log the first 100,000 pieces of malware in the database, McAfee said it's alarming that it took barely two years to double the number.

    "Looking ahead, our researchers expect yet another doubling in a similar timeframe," McAfee's Jimmy Kuo wrote. "So, 100,000 new threats in the past two years, 200,000 new threats to come in the next two years!"

    Kuo noted that the last two years marked a significant spike in downloaders and bots: malware designed to sit silently on machines and extract information that could be used for financial gain.

    "In early 2004, a number of viruses like Netsky, Bagle, and Mydoom would infect multiple millions of machines with each release of a new variant," he said.

    But over time, malware distribution has changed dramatically. "In the first half of 2004, 31 virus outbreaks were rated medium and above. The second half of 2004 saw 17 more. That number fell to 12 for the whole of 2005. And in 2006, there have been no outbreaks of similar severity!"

    Instead of huge virus events, he said, "the preferred method of malware distribution now involves the creation of many minor variants sent through controlled spam efforts. Good family detection becomes crucial for a less worrisome experience on the Internet."

    Tags: Security Testing and Ethical HackingWeb Browser SecurityVIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Security Testing and Ethical Hacking
    H.D. Moore speaks about Metasploit Project deal, Release 3.3
    Could Metasploit popularity erode?
    Metasploit Project acquired by vulnerability management firm Rapid7
    Should management processes change based on a patch release schedule?
    Does an EULA make it truly illegal to decompile software?
    Screencast: BackTrack 4 offers an arsenal of penetration testing tools
    Security testing firm uncovers XML vulnerabilities
    Screencast: Samurai offers pen-testing nirvana
    The requirements needed to make an external penetration test legal
    McAfee to acquire Solidcore Systems for whitelisting

    Web Browser Security
    Exploit code targets Internet Explorer zero-day display flaw
    InZero Systems launches hardware-based security gateway
    Web security firm ranks Firefox, Safari browsers as flaw prone
    Microsoft fixes security update that breaks Internet Explorer
    Mozilla update repairs Firefox buffer overflow vulnerabilities
    Kaspersky system analyzes malicious URLs on Twitter for malware
    Silon malware intercepts Internet Explorer sessions, steals credentials
    Do Facebook URL security concerns justify blocking social networks?
    Phishing attacks to remain a major problem, say security experts
    Adrian Perrig: Improve SSL/TLS Security Through Education and Technology
    Web Browser Security Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Cyber Storm  (SearchSecurity.com)
    ethical hacker  (SearchSecurity.com)
    ethical worm  (SearchSecurity.com)
    gray hat  (SearchSecurity.com)
    honey pot  (SearchSecurity.com)
    honeynet  (SearchSecurity.com)
    war dialer  (SearchSecurity.com)
    white hat  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



  • More Tips to Secure Your Network
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts