Click to Play

Is Your Website Effective?
In this interview with Mike McDonald at the 25th Annual ACCM, Larry Becker of the Rimm-Kaufman Group defines website effectiveness as a website meeting...

Top Security News

Enterprise 2.0: A Security Nightmare
Steve Lohr posts Enterprise 2.0: A Security Nightmare on the NY Times Bits blog. Its the kind of fear sells story that is inevitable. There are apps happenging outside your firewall. P2P, unauthorized-by-the-enterprise proxies, YouTube and Google Apps.

Our Broken Information Security Business
4.2 million accounts were exposed in a supermarket data hack. This will probably go down as the biggest breach in this quarter, but unlikely to go down as the biggest data breach for 2008. What is interesting through is that the data breach actually occurred in...

G-Archiver Pulls Their Software From Distribution
G-Archiver, the software that was previously caught by coding horror and blogged about here has pulled the version of the software that captures user credentials and e-mails them to Google. From the time it was discovered by Coding Horror on the 7th through to...

Enterprise CMS Fall Short On Security Demands
CMS Watch released research that finds Enterprise Content Management (ECM) products ill-equipped to meet the security requirements of Service Oriented Architectures (SOA). In its most recent research, CMS Watch looked at 30 leading ECM vendors around...

Flash Vulnerabilities Discovered By Google Researchers
The Register reports that Google Researchers have documented serious vulnerabilities in Adobe Flash content which leave tens of thousands of websites susceptible to attacks that steal the personal details of visitors. The security bugs are in the Flash SWFs...

Hackers Bypassing Registration With PyCurl
Interesting hacking attack going on at a social networking site that I am working on today. Seems that the hacker is using PyCurl to bypass the registration page and dump user's right into the system.



05.21.08

HackerSafe Program Not So Safe

By Dan Morrill

And with cause, if XSS is not a security issue, then there are at least 62 doomed sites carrying the HackerSafe/McAfee logo that could seriously damage someone's day.

More than three months after security bugs were documented in more than 60 ecommerce sites certified by McAfee as "Hacker Safe," a security researcher has unveiled a fresh batch of vulnerable websites. Russ McRee, a security consultant for HolisticInfoSec.org, documented cross-site scripting (XSS) errors in five sites that prominently carry a logo declaring them to be Hacker Safe. As McRee documented in a blog post and accompanying video, the bugs make it possible for attackers to steal authentication credentials and redirect visitors to malicious websites. Source: Register

But this story gets stranger, ala Hans Reiser, computer geek gone bad, seems that the VP in charge of the HackerSafe program is also under indictment for a few things, like security fraud.

Get Listed on Google, Yahoo, and Other
Search Engines in 48 Hours Guaranteed

The real issue though is not that Brett M. Oliphant is not clean (this is a classic issue of trusted person in a security position), but that the program that he ran, HackerSafe is now coming out as fundamentally flawed.

A McAfee spokeswoman said the company rates XSS vulnerabilities less severe than SQL injections and other types of security bugs. "Currently, the presence of an XSS vulnerability does not cause a web site to fail HackerSafe certification," she said. "When McAfee identifies XSS, it notifies its customers and educates them about XSS vulnerabilities." Source: ZDNet

For anyone in the computer security business that gets XSS and the follow on fun things that can happen when someone truly exploits and XSS error in a system (see this article here) you pretty much so know that the spokes person's comment was one that is going to keep people up at night. While they do report back to the company running the program, a sever XSS flaw can seriously ruin a customers day, let alone their identity, computer, and anything else associated with that.

Here is a video on that exact subject, will make you wonder when you realize just how bad this can be.



The idea here that you can not be certified as anything if you have a glaring hole in your web site that a hacker can drive a bus through. It is an issue, and not a trivial issue either. Brushing off an attack, telling someone it is ok, this is just bad bushiness. It also provides a false sense of security for people, people who trust the companies that carry the HackerSafe logo.

Comments


About the Author:
Dan Morrill is CEO and co-founder of Socialtext, an emerging provider of Enterprise Social Software that dramatically increases group productivity and develops a group memory.

He also writes Dan Morrill's Weblog which focuses on markets, technology and musings.
About EnterpriseSecurityNews
Security news and updates for your enterprise





EnterpriseSecurityNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITmanagementNews.com






-- EnterpriseSecurityNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2008 iEntry, Inc. All Rights Reserved Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


Enterprise Security News News Archives About Us Feedback EnterpriseSecurityNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact