Research fingers ActiveX, QuickTime as buggiest browser plug-ins
ActiveX controls accounted for 79% of plug-in bugs; Firefox extensions, just 0.4%
Active Comments
The Security Zone
With the mobility of employees and the ease with which external devices can be brought in and out of a network, continuing to build your security plan for network servers and clients is a must. Fortunately, there is much that organizations can do to protect themselves from attacks - internal and external. Having the right policies, procedures and server configurations is critical... Learn more in The Security Zone See All Zones
|
April 11, 2008 (Computerworld) ActiveX controls accounted for an overwhelming majority of all browser plug-in vulnerabilities in the second half of 2007, Symantec Corp. said this week in its semiannual Web security report.
Microsoft Corp.'s technology, which is used to create add-ins for Internet Explorer, accounted for 79% of the 239 plug-in bugs discovered between July and December of 2007, Symantec said. The plug-in with the next-highest number of flaws was Apple Inc.'s QuickTime, which had just 8% of the six-month's total.
Only one vulnerability in a plug-in for Mozilla Corp.'s Firefox browser was detected in the same period, meaning Firefox's extensions -- the moniker Mozilla Corp. uses for plug-ins -- accounted for only 0.4% of all flaws found.
Symantec argued that ActiveX's poor showing could stem from several factors, including the availability of "fuzzing" tools that hackers can use to sniff out input vulnerabilities in the controls. But it also fingered several traits inherent to the add-on technology.
"ActiveX is also an attractive target because many users may not be aware that they have installed vulnerable controls and because of the relative difficulty of removing or patching ActiveX controls once they have been installed," said Symantec in its "Internet Security Threat Report Volume XIII" (download PDF). Hackers also root out ActiveX bugs, Symantec continued, because they are used exclusively on Internet Explorer (IE), which still holds nearly 75% of the browser user market.
The 2006 launch of IE7, which Microsoft touted as being much more secure than its predecessors, hasn't had a measurable impact on the number of ActiveX vulnerabilities, Symantec's report said, even though the newer browser introduced several security features designed to stymie plug-in abuse. In the second half of 2007, Symantec detected 190 ActiveX vulnerabilities, down about 10% from the 210 found in the first six months of that year.
"This may be a measure of the effectiveness of these security enhancements, or it may indicate that many at-risk users have not upgraded to Internet Explorer 7," Symantec speculated.
In the case of enterprises, the latter may be the cause, according to other research. By the end of 2007, Forrester Research Inc. said recently, only about 30% of the 50,000 corporate computer users it surveyed said they were using IE7; the bulk of the remainder reported using IE6.
The upshot, said Symantec, is that ActiveX remains a major problem. "While Microsoft has gone a long way to improve the security of Microsoft Windows and its applications, ActiveX is still a critical security exposure on the Microsoft Windows platform," the report said.
ActiveX's problems haven't improved in 2008. In February, for example, a wave of vulnerabilities in several high-profile ActiveX controls prompted the U. S. Computer Emergency Readiness Team (US-CERT) to recommend that users disable all IE plug-ins.
Today's Top Stories
Resource Alerts
Webcasts
Web Threats Don't Discriminate
The Secure Web Gateway. Mission Critical For Business
Dynamic Data Center and Virtualization Drives Operational Excellence at Emory Healthcare
Editor's Picks
Clues point to Jan. 13 release of Windows 7 beta
Microsoft releases Vista SP2 beta
Obama's DHS pick may find support for raising H-1B cap at confirmation hearing
IBM wants info from Apple execs in Papermaster case
License server glitch exposes SonicWall users to e-mail security threats
Report: Former AOL chief exec tries to raise funds to buy Yahoo
Fired up about IT? Join Sharkbait and share your true tales of IT. SharkBait is the place for you to sound off about everything IT the good, the bad, and the rest of the weird stuff you deal with every day.New baits |
|
![]() |
|
Patrick Thibodeau: Satellite images of U.S military bases Which is more important? Helping terrorists or protecting military bases? Answer: protecting Web 2.0 ... [more] |
| White Papers Read up on the latest ideas and technologies from companies that sell hardware, software and services. | ||||||
|




Subscribe to
Computerworld 







Read up on the latest ideas and technologies from companies that sell hardware, software and services. 

