PC District
Software News
| |
Search in
PC District » News Articles Reviews » Security » Latest Hacks and Attacks Report Shows Web Vulnerability

Latest Hacks and Attacks Report Shows Web Vulnerability

Category: Security
Published: 11/07/2007, 17:22
Editor: Badragan Ciprian

    Breach Security, Inc., the web application security, will be presenting 'Latest Hacks and Attacks' from the Web Application Security Consortium's Distributed Open Proxy Honeypot Project at next week's Open Web Application Security Project & WASC AppSec 2007 Conference, in San Jose, CA. The Distributed Open Proxy Honeypot Project initially began in January 2007 and is led by WASC officer Ryan C. Barnett, director of Application Security Training for Breach Security, Inc.

    By deploying multiple open proxy server honeypots, WASC is able to take a granular look at the types of malicious traffic
that are utilizing these systems. The open proxy honeypots are specially configured vmware hosts used as a medium for gathering attack data. Much of the traffic passing through the open proxies is from hackers or spammers looking to cover their tracks. When the project initially began in January, analysts collected data from seven open proxy servers in countries around the world including Germany, Greece, Russia and the United States.

    The MMA provides security analysts with a single interface for monitoring the security of their web applications.
The global net of honeypots run Breach Security's open source ModSecurity core rules to identify and block attacks and provide research data. The Honeypot Project is also using Breach Security's commercial ModSecurity Management Appliance, a network-based tool designed to collect logs and alerts from remote ModSecurity sensors in real-time.

    Utilizing globally located open proxy servers and sensors, the Honeypot Project captures live attack data to provide specific examples
of targeted web application attacks. Barnett will discuss the new findings on Wednesday, November 14th during the first day of the AppSec conference. The project has broadened over the past year, with the number of participating sensors doubling in number to 14. New open proxy servers are now located in Romania, Argentina, and Belgium. The ModSecurity open source web application firewall is the most widely deployed with 10,000 users worldwide. This highly flexible web application firewall can be used for a wide range of functions including web application monitoring, web intrusion detection and prevention, as well as "just in time" virtual patching of known vulnerabilities.

    While the Distributed Open Proxy Honeypot Project started in January 2007,
the data presented below was collected solely in October 2007 - all data is compared to the four month cycle of the phase one of the project, which was collected from January 15th through April 30th 2007.

    "This research project differs from conventional web attack statistics as we have wide visibility of attack traffic,
whereas most organizations only see data destined for their specific sites," said Barnett. "We present this project to the security and business community to build awareness by offering fresh insight into the multiple forms of web application attacks that are occurring."



Bookmark this article to:
Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Del.icio.us Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to digg Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to FURL Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to reddit Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Technorati Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Yahoo My Web Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Stumble Upon Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Google Bookmarks Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to RawSugar Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Squidoo Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Spurl Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Netvouz Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Rojo Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Bloglines Add 'Latest Hacks and Attacks Report Shows Web Vulnerability' to Tailrank
Add comment  
PC District is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the PC District.
User comments (0):

There is no comment for this review.

 
Related Articles:
 

External HDD Presents Vulnerability To Data Loss
 Consumers using external hard drives often assume the valuable data on their PC is protected, but an external hard drive can leave them vulnerable to catastrophic data loss. Carbonite’s online backup service allows users to store an unlimited amount of data for $49.95 per year. The service works automatically to provide continuous backup whenever the user’s computer is connected to the Internet.
Read More >
10/25/2007, 14:11
 

xPost for Instant Content Creation of Niche Digital Signage Launched by CAYIN
 To create rich contents for digital signage in different vertical markets, the professional supplier of digital signage solutions, CAYIN Technology, releases the web-based application software, xPost, which offer a powerful suite of content editing software: wayfinderPost, meetingPost, and lobbyPost.
Read More >
07/31/2008, 16:38
 

VOXCOM Security Systems and iControl Networks To Deliver Home Security Solution
 VOXCOM Security Systems  announced that it has partnered with iControl Networks, pioneer of mass-market, web-based 'Home Security 2.0' solutions, to produce an offering that allows customers to remotely monitor and control their homes. VOXCOM's Active Response Monitoring solution, an innovative monitoring, notification and video services platform, will be integrated with iControl's iHub technology: a home security router that plugs into the home network and connects wirelessly to security panels, IP cameras, sensors, and Z-Wave-based home automation devices.

Read More >
02/12/2008, 23:19
 

Networking Equipment Upgrade from EstDomains, Inc
 A US-based domain registrar, EstDomains, Inc (http://estdomains.com) offers a wide spectrum of domain name relating services, including domain forwarding, domain name registration, mail forwarding and managed DNS.
Read More >
04/24/2008, 14:41
 

McAfee Forecasts The Year 2008 Security Issues
 McAfee, Inc. released its top ten predictions for security threats in 2008. Researchers at McAfee Avert Labs expect an increase in Web dangers and threats targeting Microsoft Corp.'s Windows Vista operating system, among other new or increased threats. At the same time ad-serving software known as adware is expected to continue to decrease. Compromises and malware at Salesforce.com, Monster.com and MySpace, among others, represent a new trend in attacking online applications and social networking sites.
Read More >
11/19/2007, 15:11

 My PCDistrict Login
News - Articles - Reviews
Software
Sponsored