Fox lets chickens guard the henhouse | eWEEK Labs | eWeek

Fox lets chickens guard the henhouse

Jul 25, 2007
2 minute read
eWeek Le contenu et les recommandations de produits sont indépendants de la rédaction. Nous pouvons gagner de l'argent lorsque vous cliquez sur des liens vers nos partenaires. En savoir plus

As reported by Lisa Vaas at eWEEK, “Fox News’ Web site over the weekend exposed a password that granted inappropriate access to images from its news stories and to a headline feed from its content syndication partner and eWEEK publisher, Ziff Davis Media.” Ziff Davis Media is also the publisher of Permit/Deny.

Hacker Webzine is now reporting SQL injection and ColdFusion vulnerabilities in publicly facing applications at Fox sites.

The next step for Fox and Ziff Davis is to run a vulnerability assessment battery against their externally facing IT resources.

Then the companies need to hire a different company (to avoid conflict of interest and inferior test results) to run penetration tests against the sites to ensure that as many weaknesses as possible are found.

Then a third company should be hired to help the current IT staffs at both companies remediate the remaining problems. Finally, the vulnerability assessment and penetration tests should be run again to ensure that the newly remediated Web sites and any exposed systems (such as servers sitting in a DMZ) are fully patched and ready to face the hostile world.

I think it’s important to separate vulnerability assessment, penetration testing and remediation into three distinct segments of the same overall project to ensure the best results.

If the same company performs all three operations, then Fox and Ziff Davis will likely be protected against the faults that the single vendor knows best. Dividing the tasks almost certainly adds time and complexity to the ultimate security solution. However, with three sets of independent security consultants checking on each other, the problems likely to be found by motivated hackers from the outside will greatly reduced in number. Further, the most serious and obvious problems, such as those experienced by Fox, will almost certainly be eliminated.

IT managers should use public examples to motivate plans to secure their infrastructure. The vulnerability assessment/pen testing/remediation cycle that I’ve outlined won’t be the cheapest solution for correcting security problems. However, these external tests are more effective than occasional internal audits.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Propriété de TechnologyAdvice. © 2026 TechnologyAdvice. Tous droits réservés

Divulgation publicitaire : Certains des produits qui apparaissent sur ce site proviennent d'entreprises dont TechnologyAdvice reçoit une compensation. Cette compensation peut influencer la façon dont les produits apparaissent sur ce site, notamment l'ordre dans lequel ils apparaissent. TechnologyAdvice n'inclut pas toutes les entreprises ou tous les types de produits disponibles sur le marché.