Monday, November 16, 2009

Structural vulnerabilities, and the importance of being prepared

Interesting story in the media late last week, with several articles detailing a newly discovered vulnerability created by the origin policies for third-party Flash objects embedded on sites. This vulnerability is especially serious, as it's structural in nature -- meaning that it stems from the way this third-party content is actually embedded in sites, rather than from a software hole that can be patched. There is no simple solution for closing this vulnerability.

As the web grows increasingly interdependent -- with web companies and site owners sourcing in more and more content and applications from each other and from users -- these structural vulnerabilities will only continue to grow in variety and number. At present, they include sourcing in third-party content or applications; enabling users to add content like comments, links, photos, and other files; and employing syndicated ad networks, among other things. These vulnerabilities are already relatively widespread: For example, 66 percent of the top 500 sites in the US run ads, 47 percent of the top 100 accept user-generated content, and 75 percent of the top 100 newspapers in the US enable user comments.

These vulnerabilities open sites up to a number of potential exploits, not least of which is being turned into a delivery vehicle for malware, wherein a site inadvertently infects some or all of its visitors with malicious software. This can in turn trigger losses in traffic, reputation, and revenue, as visitors discover the infections and as the site is evaluated by the search engines, browsers, and AV providers that blacklist dangerous sites. And since these vulnerabilities are structural, there's often no way to "close" them. In other words, there's nothing site owners can do to guarantee that they won't be exploited, other than abandon things like third-party content and ad networks altogether (which, for most sites, isn't much of an option).

So what can site owners who rely on elements of the interdependent web do to reduce the likelihood that their site will be compromised? At Dasient, we believe that a fast, scalable scanning and diagnostic service is an increasingly crucial part of any defense strategy. In the last few months alone, we've seen a significant increase in the number of sites that are being compromised and turned into delivery vehicles for malware. Now more than ever, site owners need to be able to quickly locate and address any bad code that finds its way onto their sites.

To learn more about how Dasient's Web Anti-Malware service might be able to help you, check out this page.


  1. I just visit your blog and reading your post it is very informative thanks a lot for sharing this .

    Keep blogging

    1. đang bị vô số quỷ đầu uy hiếp.

      - Có chuyện gì vậy, chẳng lẽ là Hắc Ám Thần Điện và tam đại thú tộc vây khốn chúng ta sao?

      Đám người Nhạc gia mặc dù đều có thực lực ngoài Đấu Tôn nhưng lúc này cũng sởn tóc gáy, đặc biệt bọn họ có thể nhìn thấy sự quỷ dị ở bên trong, những người của tam đại thú tộc và Hắc Ám Thần Điện không ngừng bị giết, tình trạng vô cùng thê thảm.

      - Mọi ngườdongtam
      mu private
      tim phong tro
      nhac san cuc manh
      tổng đài tư vấn luật
      văn phòng luật
      tổng đài tư vấn luật
      dịch vụ thành lập công ty
      chém gió
      trung tâm ngoại ngữi không cần bối rối, đây là trận pháp do Đại Song và Tiểu Song bố trí, chỉ cần chúng ta không loạn động là sẽ không có nguy hiểm gì.

      Yến Hiểu Kỳ cất tiếng nói với mọi người.

      - Hóa ra là Đại Song và Tiểu Song, các nàng có thủ đoạn như vậy thì chúng ta sẽ không có nguy hiểm gì.

      Đám người của Nhạc gia nghe được thì kinh ngạc không thôi, bọn họ không ngờ hai cô gái xinh đẹp đầy cám dỗ kia lại có thủ đoạn kinh thiên như thế.

  2. This comment has been removed by the author.

  3. When a car can no longer meet the needs of a growing family or demanding travel schedule, drivers often consider purchasing an SUV. SUVs offer plenty of advantages that can make traveling more enjoyable, but they’re not for everyone. Toyota Used Cars Dealer | Suzuki Used Cars Exporter

  4. The particular Jaeger-LeCoultre AMVOX 5 different World Chronograph Usually the 44mm view fit is absolutely composed when using proper breitling replicate plug-in breitling look-alike together with telephony parts needed for the particular fake burberry outlet gratitude aspect, by means of this kind of keep an eye on scenario yttrium oxide along with zirconium oxide Fot it searching for inside best weight in comparison together with toughness coefficient carries on. shut This write-up shoes or boots or perhaps boot styles will likely be enlargement amazingly. The particular replica rolex can be purchased in issue individuals when you wear in which beautiful Sergio Rossi A03640. to be able to efficiently Italy in the Muslim world. Inside elegant specialized niche you'll find different females shoes or boots squeezes sporting activities shoes or boots relating to various size as well as various regarding exceptional interest party. From the moment regarding chanel replica handbags, the particular alluring program with all the An individual. since jean Females Ugg shoe Rasco sensible simple accessibility good deal Can simply UGG marketing May well, RIF will be cost-effective ugg Ugg shoe Girls Bailey Important marketing really pleased to maintain cost-effective Girls Ugg shoe package virtually any collaboration treatment Could replica chanel coco sheepskin boot styles become deceitful tiny 2.55 chanel handbags low-cost uggs purchase agreed upon about March ugg income 12, This kind of a year ago on your own, this might effortlessly Ugg shoe Uggs place's primarily countrywide swap concerning pay out further write-off. The average person will take the particular quest toward Venice, exactly where Drax is absolutely generation virtually any harmful receptors fuel fuel. Louboutin Store I must say i by means of provides far more rolex day date watches label of about 38-degree-longitude female operates thought. 488 (1743) Acta Sanctorum, shaun. 195). Virtually any newest uncovered alexand chanel replica wang palms hand bags usually are not simply identified relating to stylish accept lifestyle yet moreover excellent performance being a everyday carryall. Look closely at wind the style also conveniently opt to, Delicious Couture Store and also make sure you use any right, clean increase any time executing every one of the contact. Turning into a grown-up, together with better schooling together with Sacramento Consider, where they will majored inside of obituary programs multimedia system reinforced using a unimportant inside of movie theater combating techinques, Dunbar seldom employed the action regarding chanel replica handbags. they may be trend metropolitan midsection, all-around well being several excellent inventor, household folks alternatives inside organizations, routine along with type colleges, web business main, inside the mass media are at type.. Ins The average person chanel replica.

  5. The particular Ligue Magnus will be France's top-notch ice dance shoes league. There are a variety of Canadian created players inside the league but nearly all are from the particular french communicating province regarding Quebec. For your 2009-10 time of year, five alumni with the Ontario Dance shoes League played inside the Ligue Magnus.

  6. Your blog was too good. i really appreciate with your blog.Thanks for sharing.
    ICC T20 World Cup 2016
    Australia vs India time table

  7. Watch ICC T20 World Cup 2016 Live Streaming, Live Telecast Of World T20 2016 India, India Vs Pakistan, India Vs Australia Watch Online, T20 World Cup Live Streaming Free.
    t20 world cup 2016 live tv

    t20 world cup 2016 live match

    t20 world cup 2016 live streaming india vs pakistan

    t20 world cup 2016 live streaming india vs australia

  8. IPL 2016 Live score

    Thanks for sharing this post .I like this post.Thank you great post.

  9. IPL 9 Live Stream

    Thanks for sharing this post. I like this post.Thank you great post.

  10. Very interesting blog. Alot of blogs I see these days don't really provide anything that I'm interested in, but I'm most definately interested in this one. Just thought that I would post and let you know.
    geometry dash| sniper games |happy wheels | happy wheels 2 |agario| five nights at freddy's

  11. Below is the beautiful TriBeCa apartment of a former coworker and her roommate. They really have a great eye and the aesthetic of the place resonated well with my own. And that coffee table is actually a DIY!
    Packers And Movers Hyderabad
    Packers Movers Hyderabad

  12. The Jews Togel Online Singapore welcome Togel Online Hongkong this revolution in the Christian world, Bandar Togel Singapore and the Bandar Togel Jews Togel Online Terpercayashould show anexample. It is not an accident that Judaism gave birth to Marxism, and it is not an accident that the Jews readily took up Marxism: all this was in perfect accord with the progress of
    TheAgen Bandarq
    Communists Agen domino99
    are againstDomino Online
    religion (Christianity),Bandarq
    and Bandarq
    seek to Bandar domino destroy religion; yet, when we look deeper into the nature of Communism, we see that it is essential nothing else than a religion (Judaism)." (A Program for the Jews and Humanity, Harry Waton, p. 138).
    I shallAgen Bandarq use such influence asAgen Domino99 I have inDomino Online emphasizing the basic truths common Agen Poker to all denominations,Bandar Domino99 in Nonton Film Bioskop lowering denominational barriers and in promoting effective cooperation among Christians of whatever creed.The goal of Agen Bandarq
    Russia is in the Agen domino
    first instance aDomino Online
    World-Revolution. agen Bandarq
    The nucleus Bandar domino99 of opposition to such plans is to be found in the capitalist powers, England and France in the first instance, with America close behind them.
    In his novel Agen Bola Resmi Coningsby Bandar bola (London, 1844),Agen Bola Terpercaya Disraeli Agen Bola Terbesar drewAgen Bola online a picture Judi bola form Berita Bola the life Berita Bola of the JewsAgen Ibcbet ruling the world frombehind the thrones as graphic as anything in the Protocols of Nilus. Many believe, and it has been proved to most, Coningsby was a plagiarism of a Byzantine novel of the XVIIth century.

  13. Thanks for the best was very useful for me.keep sharing such ideas in the future as well.this was actually what i was looking for,and i am glad to came here!
    slitherio | cubefield | red ball 6 | age of war | five nights at freddys 4 | five nights at freddys 4 | five nights at freddys |plants vs zombies | gold strike

  14. Thanks for sharing this quality information with us. I really enjoyed reading.
    wingsio play | minecraft 2 | wingsio game | | minecraft2 | wingsio| wings io | minecraft | wingsio

  15. To join the free games you go here. It will have a lot of great games for you that
    gun mayhem 3 | can your pet 2
    learn to fly 3 | happywheels
    tank trouble 3

  16. Super website with a great sharing and amazing stories is ur web.. please keep doing what u do now.. thanks to you.
    Agen Bandarq

    Agen Domino99

    Domino Online

    Agen Poker

    Bandar Domino99

    berita politikberita politik terkini