Showing posts with label McAfee. Show all posts
Showing posts with label McAfee. Show all posts

Secunia: popular security suites failing to block exploits

Secunia Comparative Review Internet Security SuitesIn a recently conducted comparative review, Danish security company Secunia, tested the detection rate of 12 different Internet Security Suites against 300 exploits (144 malicious files and 156 malicious web pages) affecting popular end user applications, to find that even the top performer in the test is in fact performing poorly in general. Their conclusion :

“These results clearly show that the major security vendors do not focus on vulnerabilities. Instead, they have a much more traditional approach, which leaves their customers exposed to new malware exploiting vulnerabilities.

While we did expect a fairly poor performance in this field, we were quite surprised to learn that this area is more or less completely ignored by most security vendors. Some of the vendors have taken other measures to try to combat this problem. One is Kaspersky who has implemented a feature very similar to the Secunia PSI, which can scan a computer for installed programs and notify the user about missing security updates. BitDefender also offers a similar system, albeit this is more limited in scope than the one offered by Kaspersky and Secunia. We do, however, still consider it to be the responsibility of the security vendors to be able to identify threats exploiting vulnerabilities, since this is the only way the end user can learn about where, when, and how they are attacked when surfing the Internet.”

And while it’s boring to scroll through the empty tables of the study, is Secunia’s report a frontal attack against the security software vendors’ inability to block exploits, or are they trying to emphasize on the fact that the end user should make better informed purchasing decisions when relying on All-in-One Security products?

In 2007, Secunia released data indicating that 28% of all installed apps are insecure, and despite that the vulnerabilities has been already addressed, the end users were still living in the reactive response world. Cybercriminals on the other hand, took notice, and following either common sense or publicly obtainable data indicating that end users remain susceptible to already patched vulnerabilities, started integrating outdated exploits into what’s to become one of the main growth factors for web malware in the face of today’s ubiqutous web malware exploitation kits.

Live Exploit Kit SampleA year later, another study confirmed this fact and pointed out that one of most effective vehicle for the success of web malware — the insecure web browser — remains largely ignored by millions of Google users. So, theoretically, the more traffic the malicious attackers acquire and redirect to their exploit serving domains, the higher the probability for a successful infection with an undetected by standard signatures based scanning piece of malware - which is exactly what they’ve been doing the entire 2007 and 2008.

What is more important, to detect the latest malware binary behind the exploit serving file, or prevent the latest malware binary from reaching the end user/company by blocking the relatively static exploit serving file? It’s all a matter of perspective.

Naturally, the reactions to the comparative review, and the methodology used are already receiving criticism from the vendors. Sunbelt Software’s Alex Eckelberry comments on the report, and also includes AV-Test.org’s Andreas Marx opinion emphasizing on why it’s important to prioritize :

“In most cases, it is simply not practical to scan all data files for possible exploits, as it would slow-down the scan speed dramatically. Instead of this, most companies focus on some widely used file-based exploits (like the ANI exploits) and some companies also remove the detection of such exploits after some time has passed by (as most users should have patched their systems in the meantime and in order to avoid more slow-downs). There are a lot more practical solutions built-in to security suites, like the URL filter (which checks and blocks known URLs which are hosting malware or phishing websites) and the exploit filter in the browser (which would also block access to many “bad” websites). Some tools also have virtualization and buffer/stack/heap overflow protection mechanisms included, too.

Then we have the traditional “scanner” — and even if some exploit code gets executed, a HIPS, IDS or personal firewall system might be able to block the attack. For example, some security suites are knowing that Word, Excel or WinAmp won’t write EXE files to disk — so potentially dropped malware cannot get executed and the system is left in a “good” state.”

Emphasizing on defense-in-depth, and prioritizing in the case of blocking the most popular exploits used is a very good point since it has the potential to protect as many customers as possible from the default set of exploits used in the majority of malware attacks. For instance, the massive SQL injections attacks that took place during the last couple of months, were all relying on relatively static javascript file, whose generic detection is a good example of prioritizing. Moreover, due to the evident template-ization of malware serving sites, and the commoditization of web malware exploitation kits, the impact of ensuring that your customers are protected from the default sets of exploits included within these kits, means that your customers will be protected from a huge percentage of web based malware attacks.

No Internet Security Suite can protect you from yourself, so do yourself and the Internet a favor - patch all your insecure applications - it’s free.

[Source: zdnet]

McAfee buys CipherTr– err, Secure Computing

ike every other red-blooded American I take a quick peak at my collapsing retirement and savings portfolios in the morning just to give me that extra kick to head into the office. So I pull up Google Finance to see Secure Computing (SCUR) is, up some 23%, one of the big movers for the day. There are very few things that could cause a tech company to jump so much in such a short period of time.

Apparently McAfee has decided to acquire the shop. This will help McAfee in not only the enterprise and edge space, they also will get an anti-spam offering in the 2 year old CipherTrust acquisition, which was then valued at around $275MM, or 58% of the current purchase price.

On a more personal note, I take this as a sign that I must finally throw away my SideWinder t-shirt.

[Source: zdnet]

McAfee S.P.A.M. experiment and more ridiculous HackerSafe failures

Stay with me here readers, I’m stringing two stories about McAfee together here, a little out of the ordinary, so I hope it makes sense. If you aren’t interested in the tech details (of which there are very little), please do read for a good laugh.

Network World reported that McAfee conducted an experiment into what would happen if computer users really did respond to all those spam emails and click all those free virus scan popups. The experiment, called S.P.A.M. (Spam Persistently All Month) took 50 volunteers, both male and female, from numerous countries and tried to determine what would really happen. Of course, the end result will be exactly what you’d expect, but hey, I’m game for an experiment, and the volunteers get free computers, so let’s read on!

The article states:

By the time it was all over, after every bank-account phishing scam, Nigerian bank scheme, and offer for medication, adult content and just plain free stuff had been pursued. “I was horrified,” says Mooney, a realtor by profession. “It’s all snake oil. I’m amazed at what true junk is out there when you’re clicking through on e-mail.”

Holy crap… so, what this article is telling me is that McAfee is actually pointing out snake oil to end users? Whoa, this goes against all their marketing campaigns for HackerSafe certifications and their PCI solutions, but hey, that’s cool I guess. Oh wait, sorry, they’re not pointing out their OWN snake oil.

[Author’s Note: Sorry guys and gals, this was like a slow-pitch Softball… I couldn’t help myself]

The article goes on:

McAfee is releasing the results Tuesday of its free-wheeling month-long S.P.A.M. experiment, done largely to illustrate — if you didn’t know already — how spam is connected to malware and criminal activity, not to mention some of the slimiest marketing ever devised.

Holy haberdashery, Batman! Can you believe it? Spam, popups, phishing, etc. actually lead to malware and criminal activity? Not to mention some of the slimiest marketing ever devised?

Yeah, so about that slimy marketing… HackerSafe is popping up on my news radar again, as once again fearless friends of the people Russ McRee and Rafal Los have posted some very interesting comments on HackerSafe issues. From McRee’s newest blog entry, entitled “XSS Comedy at McAfee Secure’s Expense“:

In celebration of the deadline for PCI Requirement 6.6 compliance as of June 30, 2008, I thought I’d share a little web app sec comedy at McAfee Secure’s expense. As well you should know by know, the existence of XSS vulnerabilities in a site that is required to meet PCI DSS standards means that the site IS NOT PCI COMPLIANT. Very simple, right?

Let’s consider the McAfee Secure/Hacker Safe-branded site for Organize-It.
A seemingly handy site, perfect for your HGTV types, likely with healthy credit card limits. Uh-oh, here it comes. Oh yes, Organize-It handles credit cards and is thus beholden to PCI DSS. Organize-It is also proudly displaying a current McAfee Secure badge, indicating that it’s tested daily. Given the focus of many a recent discussion it shouldn’t shock you that Organize-It is vulnerable to XSS.

By the way, Russ as always has included video evidence, but yeah, it would seem that the McAfee Secure badge has failed us again. It sort of reminds me of when children play peek-a-boo and hide behind their hands and actually believe that you can’t see them… except that, yeah, they’re children, so you can’t blame them. Oh and about that slimy marketing that they do? Yeah, just check out that blog posting by Russ.

I will continue to say, you’re better off with the cheaper “Nate McFeters Secure” certification, and I mean, come on, who doesn’t want this picture proudly displayed on their site:


Source: zdnet]