Welcome | Sign In
ECommerceTimes.com
News

E-Commerce Security Advisories Go Unheeded

Print Version
E-Mail Article
Reprints
E-Commerce Security Advisories Go Unheeded


Learn How You Can Protect Your Virtual Datacenter
With Trend Micro™ Enterprise Security, powered by the Trend Micro Smart Protection Network™ infrastructure, you can mitigate risk and maximize the benefits of virtualization. Get the free eBook to learn how.

In an environment charged with a major China espionage scandal, and electronic attacks on the official Web sites of the White House, the Senate, and the FBI, the issue of online security remains a critical one.

E-commerce sites aren't being spared from recent waves of security breaches, though they could be doing more to immunize themselves, according to some security experts.

Whether staying vigilant about the latest software updates -- and the occasional patch -- or taking the time to read security advisories, experts believe that solutions do exist -- if IT departments are willing to invest the time and effort to seek them out.

Cold Fusion Compromise

L0pht, an independent online security site, recently disclosed that a full month after it had posted an advisory regarding a security problem with the Allaire Cold Fusion Server, sites are still being attacked.

For example, the official Web site of the State of Vermont was the victim of a hack attack that changed site. The resulting damage featured the phrase, "so how does it feel to be owned?" -- along with some other unpleasant messages left by the perpetrator(s) "Hackfactor X." The damage is still available for viewing at attrition.org.

The Power of Full Disclosure

Originally disclosed in the December 25, 1998 issue of Phrack Magazine, the problem involves the online documentation, which is installed by default. According to Phrack, the vulnerability allows web users to not only view files anywhere on the server, but delete other data and upload potentially executable files.

L0pht, in the process of conducting merely "a cursory survey," found that "many large corporate and e-commerce sites using Cold Fusion" were vulnerable. Allaire has posted a fix on their Web site, and users can access detailed fix information online through L0pht as well.

Another recent and more widely reported security problem announced by L0pht involves Microsoft's (Nasdaq: MSFT) Internet Information Server (IIS) 4.0. According to the group's advisory, transaction logs and other customer Learn how SugarCRM will improve your business. Free Trial. Click here. information such as credit card numbers, shipping addresses and purchase information in text files stored on servers could be compromised.

Administrators will need to change security settings in order to fix the problem. L0pht feels that its policy of "full disclosure" has been effective, as in the case with Microsoft, to force companies to publicly disclose vulnerabilities.

Entrust No One?

Entrust Technologies, Inc. (Nasdaq: ENTU), in an apparent move to challenge VeriSign (Nasdaq: VRSN), Inc. (Nasdaq: VRSN), recently announced the establishment of Entrust.Net, a new company that will offer secure e-commerce transaction management.

Entrust, known for its business-to-business Internet security software, hopes to become a leader in providing secure Web Site solutions.


Print Version E-Mail Article Reprints More by Matthew Beale


See Related Stories
Lloyds of London Offers Anti-Hacker Insurance
E-Commerce Sites Now Open to Hackers?
VeriSign Announces New E-Commerce Services
Netscape Chooses VeriSign for E-Commerce Security
Viewpoint: I Saw the (Veri)Sign
Certificate Authorities: A Matter of Trust

More by Matthew Beale

One Year Ago: Red Hat Finds E-Commerce At Hell's Kitchen
January 04, 2001
According to analysts, Red Hat co-founder Robert F. Young can look forward to a rapidly growing Linux marketplace in year 2000.
Linux Grows Up
June 07, 2000
Technology Spotlight: Mission Critical Linux
May 30, 2000
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Free eBook: Secure Your Datacenter
Click here to download today.
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network