Approve the Cookies
This website uses cookies to improve your user experience. By using this site, you agree to our use of cookies and our Privacy Policy.
OK
Forums  •   • New posts  •   • RTAT  •   • 'Best of'  •   • Gallery  •   • Gear
Guest
Forums  •   • New posts  •   • RTAT  •   • 'Best of'  •   • Gallery  •   • Gear
Register to forums    Log in

 
FORUMS General Gear Talk Computers 
Thread started 18 Feb 2009 (Wednesday) 11:47
Search threadPrev/next
sponsored links (only for non-logged)

X-Force Security report

 
Faolan
Goldmember
Avatar
1,204 posts
Gallery: 1 photo
Likes: 137
Joined Jun 2006
Location: Scotland
     
Feb 18, 2009 11:47 |  #1

This will probably bore a lot of you however this makes for interesting reading, not because OS X desktop and server leads the report for insecurity but for the general overview of the Malware situation:

X-Force Trend reports (external link) - Warning PDF file.

Before I start this is the actual quote from the report:

"Vulnerability – any computer-related vulnerability, exposure, or configuration
setting that may result in a weakening or breakdown of the confidentiality,
integrity, or accessibility of the computing system.
"

The X-Force is part of IBM so their can be no claim of partisanship here. Over the last few years their has been a steady and growing awareness that OS X varients and Linux are generally insecure. This is proves the old adage that any OS system operated by a user is insecure by nature. It also proves that Microsoft's steady progress in locking down the OS is proving to be worthwhile. Of course the big issue with M$ and it's user model is that much of the software on Windows was (and still is) can't be run on anything less than Administrator mode. A recent report showed that removing the Admin rights would stop 92% of attacks dead. Source:

Secure Computing. (external link)

Remember this report is based upon publically declared security flaws, so M$ should be heavily penalised but it's not even with XP leading the pack for security flags. Another aspect to consider is Apple's own history of being secretive about security and what they do (and how long it can take for them to patch) to resolve the flaw which could be if taken in this context that OS X situation could be far worse. This said the two top spots in for OS X could involve a certain amount of duplication as like M$ they often share the same codebase for their server products (or vice versa).

Also note that web flaws are now accounting for a large amount of red flags and so is Phishing scams which is OS agnostic in nature. In regards to disclosures a number of Web 2 companies have started to appear alongside the traditional companies, in the top 10 you have Drupal, Joomla! and Typo3 appearing in the list. To put this in context though the OS systems account for nearly 75% of all disclosures in 2008.

Overall the take away from this report is that no one should be bandying around saying they have a secure OS. If Apple was in a more dominant position (or even Linux) then they will be getting their shirts stolen off their back.

Overall this is a very informative and readable report with good visual diagrams and descriptions of the various vectors.


Some call me the Heilan' Laddie, but others call me Rob.
Flickr (external link) - Lighting set ups using Canon Flash/Elinchrom plus some general work.
Celtic Shadows Design (external link) - Photography and WordPress Development.

  
  LOG IN TO REPLY
Karl ­ Johnston
Cream of the Crop
9,334 posts
Likes: 5
Joined Jul 2008
     
Feb 26, 2009 00:46 |  #2
bannedPermanent ban

So....does this mean that Joomla is unsecure?


Adventurous Photographer, Writer (external link) & Wedding Photographer (external link)

  
  LOG IN TO REPLY
Faolan
THREAD ­ STARTER
Goldmember
Avatar
1,204 posts
Gallery: 1 photo
Likes: 137
Joined Jun 2006
Location: Scotland
     
Feb 26, 2009 01:21 |  #3

No it means you need to make sure if you're using templates and extensions that you need to keep on top of any patching. It's just like running any software on a computer.

Of course if there is no patches or updates then you're at the mercy of both the developers and the hackers.


Some call me the Heilan' Laddie, but others call me Rob.
Flickr (external link) - Lighting set ups using Canon Flash/Elinchrom plus some general work.
Celtic Shadows Design (external link) - Photography and WordPress Development.

  
  LOG IN TO REPLY
Karl ­ Johnston
Cream of the Crop
9,334 posts
Likes: 5
Joined Jul 2008
     
Feb 26, 2009 01:48 |  #4
bannedPermanent ban

I've really got to get computer literate.


Adventurous Photographer, Writer (external link) & Wedding Photographer (external link)

  
  LOG IN TO REPLY
sponsored links (only for non-logged)

1,014 views & 0 likes for this thread, 2 members have posted to it.
X-Force Security report
FORUMS General Gear Talk Computers 
AAA
x 1600
y 1600

Jump to forum...   •  Rules   •  Forums   •  New posts   •  RTAT   •  'Best of'   •  Gallery   •  Gear   •  Reviews   •  Member list   •  Polls   •  Image rules   •  Search   •  Password reset   •  Home

Not a member yet?
Register to forums
Registered members may log in to forums and access all the features: full search, image upload, follow forums, own gear list and ratings, likes, more forums, private messaging, thread follow, notifications, own gallery, all settings, view hosted photos, own reviews, see more and do more... and all is free. Don't be a stranger - register now and start posting!


COOKIES DISCLAIMER: This website uses cookies to improve your user experience. By using this site, you agree to our use of cookies and to our privacy policy.
Privacy policy and cookie usage info.


POWERED BY AMASS forum software 2.58forum software
version 2.58 /
code and design
by Pekka Saarinen ©
for photography-on-the.net

Latest registered member is Marcsaa
513 guests, 119 members online
Simultaneous users record so far is 15,144, that happened on Nov 22, 2018

Photography-on-the.net Digital Photography Forums is the website for photographers and all who love great photos, camera and post processing techniques, gear talk, discussion and sharing. Professionals, hobbyists, newbies and those who don't even own a camera -- all are welcome regardless of skill, favourite brand, gear, gender or age. Registering and usage is free.