Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

November 24, 2006 12:00 AM

Carelessness Runs Amuck With Zero Day Vulnerabilities

Windows IT Pro
InstantDoc ID #94351
Rating: (0)

It's no secret that some hackers, predominantly wearing either black or grey hats, discover vulnerabilities and then proceed to sit on those vulnerabilities for some variable amount of time. The motives for not informing the affected vendors appear to vary from entirely self-centered reasons to the need for leverage against a given vendor who might claim to be improving security, but just not fast enough for the satisfaction of some people. Sometimes the latter explanation turns out to be more of a ruse than fact.

In recent months the Internet community has become exposed to "A Month of Browser Bugs," where every day for a month a new bug in a Web browser was published openly to a public Web site. A follow-up to that series, "A Month of Kernel Bugs," is currently underway and so far has exposed serious vulnerabilities in Linux, Windows, BSD, and related subsystems. One bug related to wireless drivers is severe and the effects are far-reaching given that the core problem stemmed from a vendor who restributes their code to other vendors, who in turn modify that code to match their own hardware specifications. The end result with particular wireless vulnerability is that numerous vendors must each produce a unique patch and some get that patch out to users of their products. Meanwhile countless users remain at extreme risk.

The "month of bugs" trend is apparently catching hold with others. On November 20 a person who goes by the name of "Caesar" posted a message to the Bugtraq mailing list announcing "A Week of Oracle Database Bugs" slated to begin on some unspecified day in December. Caesar gave a link to the Argeniss company Web site, which apparently is behind the series. He wrote that the motive is to demonstrate that Oracle's security is insufficient, and that the company "isn't getting any better at securing it's products." He added that people "already know the history: two years or more to fix a bug, not fixing bugs, failing to fix bugs, lying about security efforts, etc." While the allegations of lying are unproven, security administrators already do know about Oracle's lag time for producing security fixes. It's no big secret, so it seems rather transparent and relatively unbelieveable for Argeniss to claim that as a motive.

It's sometimes understandable to use leverage against vendors' security-related claims, particularly when they're placing the Internet community at high risk. However, in the process of embarassing vendors some self-proclaimed "researchers" invariably harm innocent users of the affected vendors' products.

Even more troubling in the case of Argeniss is that the company claims it could do "The Year of Oracle Database Bugs" but stops short of that by saying "[We] think a week is enough to show how flawed Oracle software is." Argeniss goes on to claim that it is in possession of "zero days" for "all database software vendors" then proceeds to allege that Oracle doesn't care about security. The latter statement seems rather twisted, given the amount of carelessness required to publish zero-day vulnerabilities.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.