Wednesday, July 30, 2008

Open source software fired into IBM top-10 vulnerability list

Large news websites also hosting malicious code

Open source software has emerged for the first time in a top ten list of products to face major vulnerabilities.

Open source software names such as Joomla!, Drupal, WordPress and Linux are now alongside large proprietary software firms including IBM, Microsoft, Apple, Sun, Cisco, and Oracle in the IBM Internet Security Systems ‘Midyear Trend Statistics’ report.

It is the first time that community-developed open source software such as the Drupal and Joomla! content-management software packages for the web also showed up on the list. Tom Cross, X-Force researcher at IBM ISS, said Drupal and Joomla! are open source packages that "have both been vulnerable to SQL injection attacks".

The report tracked 3,534 disclosed vulnerabilities in software for the first half of the year, a 5 percent increase from the first half of 2007.

According to another report, Websense’s ‘State of Internet Security Q1-Q2’, the situation regarding compromised websites is becoming dire.

Stephan Chenette, manager of the Websense Security Labs, said: "Sixty percent of the 100 most-popular websites have been hosting malicious code or inadvertently distributing it.” He added: "75 percent of malicious websites in general are actually legitimate websites that are compromised."

Read More Article...

No comments: