Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Whos Watching Whom?

    Written by

    Dennis Fisher
    Published July 8, 2002
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The long-running dispute over when to release vulnerability information escalated last month into a bitter turf war among several security companies, all of which claimed to have their customers best interests at heart. And while it might have started by coincidence, this latest dispute illustrates the need for a formal, documented method for reporting security vulnerabilities, according to industry experts.

      The flap began June 17 when news of a serious vulnerability in the popular Apache open-source Web server software hit security mailing lists. First to report the flaw was security vendor Internet Security Systems Inc., which released an advisory the day it discovered the problem. The ISS advisory included a piece of code that the companys X-Force research team said would close the security hole. At the time, no formal patch was available.

      The Apache Software Foundation, in Forest Hill, Md., which maintains the Apache software, released its own advisory later the same day, which not only criticized ISS for releasing its advisory before a patch was ready but also claimed that Atlanta-based ISS patch didnt fix the vulnerability.

      The CERT Coordination Center, in Pittsburgh, which acts as a kind of clearinghouse for vulnerability data and often coordinates its efforts with security researchers and vendors, published a bulletin that afternoon as well.

      The notification barrage, which left users with a mix of contradictory information about an operating system on which many businesses rely, apparently occurred because several security researchers found the Apache flaw virtually simultaneously.

      While ISS was preparing its bulletin, Next Generation Security Software Ltd., which had also discovered the problem, contacted CERT and The Apache Software Foundation, alerting them to the problem. Apache developers said they wanted to coordinate the release of the bulletin with CERT, to which NGSS agreed, according to a note posted to the Bugtraq mailing list by David Litchfield, a well-known security researcher and co-founder of NGSS, in Surrey, England.

      “Of course, with a premature release from ISS many are now left vulnerable without a patch,” Litchfield wrote.

      Marc Maiffret, chief hacking officer of eEye Digital Security Inc., in Aliso Viejo, Calif., also joined the fray, saying that the early release of the vulnerability data will inevitably lead to active exploitation of the flaw by crackers.

      “Since there has actually been many chunked encoding vulnerabilities released lately, and exploits [for Win32], it only makes sense that it will take no time for someone to develop an exploit for this Apache Win32 chunked overflow and then start using that to break into systems,” Maiffret wrote in a reply to Litchfields message.

      ISS officials said they saw no need to keep the vulnerability secret for a long period because it had developed a patch for the flaw. “ISS was not aware of other researchers discovering this vulnerability nor aware of it in the wild at the time of the advisory,” ISS Chief Technology Officer Chris Klaus wrote in a note on Bugtraq. “We do not view this as a race to beat other researchers to releasing an advisory but a race to protect our customers in a timely manner.”

      But this did little to assuage the anger of Apache administrators, who saw ISS actions as indefensible.

      “The belief that you can just issue a patch and consider the problem solved shows a complete lack of understanding for the software development process. Review, testing and [quality assurance] are all part of that process—a third-party patch is no substitute for those,” wrote one respondent to Klaus note.

      The Apache “chunking” problem is a prime example of the kind of situation vulnerability-reporting reformers have been trying to address. In March, Chris Wysopal, director of research and development at @Stake Inc., in Cambridge, Mass., and Steve Christey, lead information security engineer at The Mitre Corp., in Bedford, Mass., drafted a “Responsible Disclosure Process” document and submitted it to the Internet Engineering Task Force for consideration as an Internet standard. But the IETFs security section decided it didnt fit with the bodys main mission of developing technical standards for Internet operations.

      Wysopal and Christey, who are both well-known in the security community, said they hoped that the document would be an important step toward a uniform disclosure policy. The pair are still considering their options for the document and have talked about creating an independent organization if no existing body shows interest.

      Related Stories:

      • Exploit Code Released for Apache Flaw
      • Apache 2.0 Beats IIS at Its Own Game
      • Commentary: A Bad, Bad Situation for Apache Sites
      • More Security Coverage
      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×