You are here: silicon.com > Software > Security Strategy

Security Strategy

Security threats revealed: Beware the metasploit

"Web-ified" apps put corporate IT at risk…

Tags: browser, rsa, phishing, botnet

By Tim Ferguson

Published: 9 April 2008 11:14 GMT

'Pass the hash' and metasploit are two of a new breed of emerging security threats facing corporate IT departments.

The key security threats facing businesses range from mutations of established methods - such as malware or phishing - to less well-known ones, such as metasploit releases and 'pass the hash' attacks.

The most dangerous new security threats were revealed by experts at the RSA security conference in San Francisco this week.

Security A to Z

From antivirus to zero-day, click here for silicon.com's alphabetical guide to security.

Hacking expert at the Sans Institute, Ed Skoudis, said most security threats stem from the fact so many applications are now linked to the internet.

He said: "We've web-ified all applications."

Among the less familiar new threats are metasploit releases, which target networks by simultaneously attacking a number of vulnerabilities (up to 200) on a different platforms including Windows, Linux and the iPhone.

'Pass the hash' attacks, which use stolen password hashes to access other systems in a targeted network - avoiding more time-consuming password cracking - were also singled out.

Although this approach has been around for some time, it is only now that it's becoming prevalent. Skoudis said: "These attacks have been around for years but now the tools are out there."

Website attacks, which plant browser exploits to compromise users, are also becoming more a problem as they are able to target well known, high-traffic sites.

A major threat is browser scripting attacks, which use web browsers to get through corporate firewalls, allowing access to confidential information.

While not new, the development of botnets remains a big security concern because the "fast flux" approach used by attackers to protect their robotic networks is making the life of botnet investigators difficult.

The security experts also warned about the threat from malware being spread through embedded devices, such as memory sticks, which is now one of the main ways harmful code is brought into businesses.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Security Consultant (Symantec SEP, SEE, SAV)

Salary: GBP35,000-GBP41,000 Dependant on experience Benefits: 20 days holiday + Bank Holidays + 3 extra days performance related ROLE: Primarily the ...

Senior Software Engineer

CompanyMcAfee creates best-of-breed computer security solutions that span large enterprises, governments, small- & medium-sized businesses, & ...

Infrastructure Manager

As the Infrastructure Manager you will be leading a team of six highly skilled individuals in the UK and India and liaising with the different R&D ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: