Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Computer Security News
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Computer Security News The Latest Computer Security News

Reply
 
LinkBack Thread Tools
Old 05-09-2009, 01:30 AM   #1 (permalink)
Analyst, Security Team
 
sjb007's Avatar
 
Join Date: Dec 2007
Location: Lincoln UK
Posts: 2,255
OS: Windows 7 Premium x64

My System

McAfee website visited by plague of security locusts

McAfee's website has been has been hit by at least three nasty bugs that left its customers susceptible to phishing and other types of scams. At least one remained unfixed at time of writing, more than 24 hours after it was first disclosed.

The most serious vulnerability, ironically enough, affected McAfee Secure, a service that certifies the security of sites that conduct ecommerce and other sensitive transactions. Mike Bailey of the Skeptikal.org blog found the site suffered from a CSRF, or cross-site request forgery, that could have allowed attackers to take control of customer accounts.
Click here to find out more!

McAfee has already fixed the bug, but during the five weeks that Bailey monitored it, the site continued to bear the McAfee Security logo, raising questions about just how valuable such a mark is. McAfee Secure, after all, is designed to pinpoint precisely these types of vulnerabilities.

It also shines a bright light on the processes McAfee takes to ensure its websites are free of such hazards. According to Bailey, the vulnerable application was not designed with the benefit of an SDL, or secure development lifecycle, which builds products from scratch to make sure they follow security best practices. He also said that prior to the bug being reported, McAfee "had never performed a full code review for web vulnerabilities."

McAfee spokesman Joris Evers said he didn't know whether the application followed an SDL, but in any event, he said the company follows strict practices to make sure its sites are safe.

"Obviously, we have processes in place that check our websites for vulnerabilities, and unfortunately, it appears a couple slipped through. We will look at the processes we have to make sure that if they're broken, they get fixed."

Bailey's report coincided with the discovery of a separate vulnerability on a part of McAfee's website that handles customer rebates. Lance James, co-founder of Secure Science Corporation and author of Phishing Exposed, created a proof-of-concept link that showed how phishers could use the vulnerability to create authentic-looking spoof pages that bear McAfee's domain name and secure sockets layer certificate while directing visitors to pages that try to steal their personal information.

The vulnerability was publicly disclosed on Monday, but at time of writing, more than 24 hours later, the hole remained unpatched.

Evers, the McAfee spokesman, said the company was "very close" to squashing the bug.

A separate batch of bugs in McAfee's website were reported late last week by an independent security group that goes by the name Team Elite.

Of course, no website or software is free of security bugs, but the issue here goes beyond that. First, consider the sheer number and then remember that McAfee is a security company, so the bar for the company is higher. Second, it's time McAfee adopted comprehensive SDLs for its products. That would go a lot farther than a logo in ensuring its considerable base of customers is secure. ®

Update

On late Tuesday, McAfee took the unfixed part of its website offline while the vulnerability was being repaired.

http://www.theregister.co.uk/2009/05...fee_site_bugs/
__________________
If we have helped you then please consider donating

Proud Member of ASAP & UNITE Since 2007
sjb007 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 12:40 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85