On GameSpot: The Sith return to The Old Republic
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Vamosi
Posted on ZDNet News: Mar 21, 2005 5:31:00 PM

Commentary--Like cockroaches that you stop at a hole in the wall only to have them reappear under the door, criminal hackers are finding new and better ways to compromise your computer and electronic devices. So concludes a new Internet Security Threat report out today, based on data collected at Symantec's Security Response facilities worldwide. The report is one company's snapshot of malicious Internet activity during the last six months of 2004.

I asked David Cole, director of product management for Symantec Security Response, to use the information uncovered in the report (more than 70 pages long) to talk about what he's already seeing in 2005. In our conversation, he covered trends such as the discovery and exploitation of flaws in non-Internet Explorer browsers and non-Windows operating systems and the recent reach by criminal hackers (crackers) into nondesktop computer systems such as handhelds and smart phone devices.

Overall, the news is mixed
The good news, says Cole, is that today, companies are much better at defending our network perimeters than they were a few years ago. Traditional Internet attacks are down. Unfortunately, attackers are opportunistic and are now going after end users--employees who log in from home or while on the road. Since companies are doing a good job protecting their e-mail systems--either at the gateway with corporate defenses or on desktops with antivirus apps--virus writers are frequently frustrated and have begun targeting instant-messaging apps, Internet Relay Chat (IRC), and peer-to-peer networks (P2P) in addition to e-mail. Symantec reported threats related to P2P, IM, IRC, and CIFS make up 50 percent of its top 50 threat submissions, up from 32 percent covering the same period one year earlier.

Browsers beware
But viruses and worms aren't the only Internet threats. Phishing scams, spyware, and now pharming attacks are becoming more common. By now, most of us know that Microsoft Internet Explorer harbors many security vulnerabilities. So as people move away from IE (now below 90 percent usage), attackers are turning their attention to Mozilla and other Internet browsers, according to Symantec.

An example might be what crackers have done with the vulnerability found in Internationalized Domain Names (IDN) that affects most non-IE browsers. IDN renders specialized character sets such as non-English domain names in a standardized way using Unicode characters, a standard that attempts to assign a unique computer number for every computer character, no matter the platform or the language set used. The IDN standard allows foreign companies to register domain names in different languages; however, criminal hackers have discovered that they can use this loophole to fool end users onto their phishing sites by substituting specific letters from alternative character sets.

Oddly, IE does not support IDN (although rumors suggest the upcoming Windows XP-only IE 7 will support IDN). Mozilla and Firefox have since patched their IDN flaw.

But if you thought that IE would be a safer browser as a result of recent attention to non-IE browsers, you'd be wrong. Cole said that while there were a greater number of vulnerabilities reported in Mozilla during the last half of 2004, Symantec found that the most severe vulnerabilities still reside within Internet Explorer. Of the 13 Internet Explorer vulnerabilities rated by Symantec from June to December 2004, 9 were considered high.

Other OSs under attack
The Symantec report also predicts that crackers will become more interested in Macs during 2005, specifically mentioning sales of low-priced mini Macs. As more casual, less tech-savvy users adopt Macs, expect to hear more about vulnerabilities exposed within the Mac OS, which is based on the Unix system. Other security companies are seeing an uptick in Mac flaws. For example, security company Secunia also saw an increase in reported Mac OS flaws during 2004.

Other electronic devices under attack
As more people leave their desktops and start accessing the Internet via mobile devices, so too do the crackers. Last summer, someone released the Cabir worm, designed to infect Symbian OS-equipped Nokia series 60 smart phones. These phones are popular in Europe, but have only recently started selling here in the United States. Since the first of this year, however, the Cabir worm has been reported in nearly two dozen countries, including the United States. Cole says these attacks will continue to grow as Bluetooth and smart phone adoption sets in. In fact, crackers recently launched CommWarrior, a smart phone-enabled virus that is able to infect either Bluetooth systems or those using Multimedia Messaging Service. Expect hybrid or multiplatform worms to remain the norm with mobile technology devices.

All is not lost
What's fueling the spread of Internet threats to other platforms? Money. As I wrote during the Sobig virus attacks in 2003, spammers and perhaps organized crime are now paying virus writers to push the limits and infect as many systems as they can. But that's good. We've moved from a strictly ego-fueled virus culture to one where the tools of law enforcement work best. Instead of finding a random, rogue programmer, law enforcement officials are following the money, and they're making some major busts against cybercrime.

As you adopt new technology, stop and think about the possible security pros and cons. Just because someone hasn't written a devastating worm to hit the Mac OS platform doesn't mean it won't happen. Same with your Nokia smart phone. Proceed with caution. If we've been successful in frustrating crackers by having antivirus and firewall solutions on our desktops, I think there's a chance we'll also prevail in these other areas as well.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 75 Talkback(s)
Re: I just don't trust Symantec
quote: But anyway, can you point out to me a specific hack that has been exploited, like Sasser and Blaster for Windows?.. unquote

Still waiting 3 months later.

Didn't someone put a Mac on the net with no firewall and a prize to anyone who could compromise it?... (Read the rest)
Posted by: timpin1@... Posted on: 06/17/05 You are currently: a Guest | | Terms of Use
Would still rather just 5 people coming to break into my house..  Jeff Spicoli | 03/21/05
Jeff talking about speaking for yourself?  vdraken | 03/21/05
Hold yer horsies, Victor  Jeff Spicoli | 03/21/05
That seems a little immature...  RayeKinezono | 03/22/05
hmm...  jdahs@... | 03/21/05
I use firefox myself, but...  Sotek | 03/21/05
"and there are and will always be"  rkadowns | 03/21/05
Sadly, yes...  RayeKinezono | 03/22/05
Here you go...  htotten | 03/21/05
I just don't trust Symantec  Jeff Spicoli | 03/21/05
Re: I just don't trust Symantec  timpin1@... | 06/17/05
Ouch!  NonZealot | 03/21/05
he dug arouynd real hard..on the very same site!  Jeff Spicoli | 03/21/05
Wake up and Smell Reality  Cayble | 03/25/05
this is MY reality...  piercedtiger | 03/29/05
Windows security is a joke !  matrixdomain | 03/21/05
minus..  d_jedi | 03/21/05
It's for your protection  Chad_z | 03/21/05
Uh, SELinux backdoors???  fmcgowan | 03/21/05
It makes for fun convresation, but  Hugh Jass | 03/21/05
REALLY secure  Spacebug | 03/21/05
Impossible!  NonZealot | 03/21/05
wow  Jeff Spicoli | 03/21/05
Left out my favourite bit  Richard Flude | 03/21/05
Nope  NonZealot | 03/21/05
Boomph! BAAAAHH!!  Jeff Spicoli | 03/22/05
But But But  lengua99 | 04/06/05
Article is not accurate...  Mike Cox | 03/21/05
Are you sure your Windows network is secure?  matrixdomain | 03/21/05
ROFL  Kamikaze_Ohka | 03/21/05
Ah...I see now  slingzenarrowzuvowtrayjissforchin | 03/21/05
Mike is back  Yagotta B. Kidding | 03/21/05
Mike, know your executives.  Anton Philidor | 03/21/05
CIOs like me ...  tdconserv | 03/21/05
Intellectual Horsepucky  SysAdmin101 | 03/21/05
You must be new here. (NT)  John E Wahd | 03/23/05
Maybe?  Fitzhugh | 03/21/05
Windows User: The weak link...  ramjet@... | 03/21/05
7.0  Real World | 03/22/05
I knew it...  jdahs@... | 03/21/05
Time to bubble burst compadre  Linux User 147560 | 03/21/05
I never said it wasnt  jdahs@... | 03/21/05
Realistic World  wmrich | 03/21/05
Nothing Has Really Changed  LynneDoucette | 03/21/05
Hackers reach beyond Windows IE  polrbear@... | 03/21/05
Exceptionally improbable.  Sotek | 03/21/05
I agree with you 100%  LynneDoucette | 03/21/05
You are entitled to your opinion  LynneDoucette | 03/21/05
Our World is not changing  KingOfHeaven | 03/22/05
Why?  sceeble | 03/22/05
Curiosity, of course ...  David A. Pimentel | 03/22/05
Try the daily Xword puzzle  sceeble | 03/23/05
I said that I was (past tense) a hacker  LynneDoucette | 03/25/05
Hackers reach beyond Windows IE  polrbear@... | 03/21/05
Hackers reach beyond Windows IE  polrbear@... | 03/21/05
tay  taycha | 03/21/05
Symantec's sel serving prophesizing  checkdesk | 03/21/05
Yes, they are creating an artificial market  Hugh Jass | 03/21/05
Only as secure ...  Henaway | 03/21/05
You got it!  Hugh Jass | 03/21/05
Add Microsoft to that list of users.  agottschald | 03/22/05
Club Shepherd 2005 v1.00  Bridge_SMASH | 03/21/05
Symantec's sel serving prophesizing  dmh1000dan@... | 03/21/05
You...  KOS-MOS | 03/21/05
The great criminal hacker challenge  FilledOut | 03/21/05
Better jobs  rkadowns | 03/21/05
Antivirus programs  irishpv | 03/21/05
How to get a TROJAN with WINDOWS XP  3nigma | 03/21/05
Tell you what.....  s_gamgee | 03/22/05
Get a hardware firewall  rpmyers1 | 03/22/05
Interesting choice of words, Macs are Flawed?  TxFrog1999 | 03/22/05
I think some people are missing the point...  RayeKinezono | 03/22/05
sadly...  jdahs@... | 03/23/05
Indeed...  RayeKinezono | 03/23/05
Hackers  cheshirecaaat | 04/07/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Meet Doc

advertisement
Click Here