Options upgrades low latency route between Cartere... » New York: Options has announced that it has upgraded the route between the firm’s data center facili... Cloud World Forum examines security, privacy and r... » London: As the adoption of cloud computing continues to grow across the world, security, privacy and... U.S. Air Force selects Cubic for Moroccan P5 Air C... » Cubic Defense Systems, a subsidiary of Cubic Corporation has been awarded a contract valued at more ... Tokenless two-factor authentication defies “Heartb... » London: The existence of Heartbleed, a vulnerability in the OpenSSL open source software, was recent... Advanced application security now standard on Barr... » Basingstoke:  Barracuda Networks, Inc. has announced that it will offer advanced application securit... Check Point provides multiple protections against ... » Check Point has announced that its network security products offer multiple protections against the ... Tyco UAE and CNL Software partner for major UAE pr... » CNL Software has partnered for an iconic security management project with Tyco Fire & Security UAE, ... Cubic unveils new corporate branding » SAN DIEGO, Calif.: Cubic Corporation has introduced its new corporate brand identity. The name Cubic... Taxware acquires VAT Resource...enhances value add... » Wilmington, MA.: axware, a global provider of sales, use and value added tax (VAT) compliance softwa... Courion expands international footprint with two n... » London, UK: Courion has announced two new hires in the UK and the Middle East to help boost its stra...

CLICK HERE TO

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

MANCHESTER, UNITED KINGDOM: Commenting on the active hacker exploitation of the latest Java zero-day vulnerability - which has already been included in the BlackHole and Cool Exploit kits - Avecto says this is an IT security disaster in progress, as there is currently no patch available for the problem.

 

According to Andrew Avanessian, VP of Global Professional Services with the Windows privilege management specialist, the vulnerability has also been added to the Nuclear Pack and Redkit exploit kits, strengthening the argument that Java should be carefully controlled on most endpoint systems.

"Whether or not Java is allowed to free reign on employee PCs, however, is actually secondary to the removal of admin rights from user accounts, as with standard user rights it is a relatively easy task to mitigate the effects of Java vulnerabilities on the Windows platform," he said.

"Put simply, without admin rights, it is difficult for cybercriminals to deploy malware capable of installing a root kit - or embedding itself in the operating system. The worst case scenario is where the malware runs in the user's profile - a problem that can be solved by removing the profile, rather than re-installing the operating system, with all the hassle this entails," he added.

Avecto’s VP of Professional Services went on to say that, once the admin rights have been removed, there is still a relatively small attack surface to deal with - and this issue can be remediated using a whitelisting security approach.

This, he says, is where the IT system only allows trusted `digitally signed' applications to run.

The good news, he adds, is that this approach also reduces the potential mis-configuration of endpoints by the user, which helps to strengthen the security model of the business IT platform in question.

Companies, says Avanessian, frequently underestimate the increases in security that can be derived through the removal of admin rights and whitelisting, despite the fact that processes can be easy to set up.

“Our observations suggest that many IT managers perceive these processes as being too hard to achieve, so they either avoid or simply don’t bother considering them. The reality is that, with the correct admin rights audit and allied requirements capture sessions in place, the right balance between security and flexibility is relatively easy to achieve,” he explained.

Avanessian says that adding a privilege management system to the security mix offers additional levels of flexibility and a positive user experience, especially against a backdrop of continuing security issues with Java, which appears to be caused by vulnerabilities in the platform.

“Simply removing Java from a computer system is not, sadly, the solution, owing to the wide variety of legacy applications that require its presence. The good news, however, is that with finer grained control over the code environment, IT professionals can mitigate most of the problems,” he said.

“One area worth noting is the issue of standard application installs and portable apps. There are several vendors developing applications, which do not need privileged accounts to run or install and, as a result, the endpoint build can become cluttered with unauthorised and unlicensed software. Application whitelisting goes a long way towards mitigating against this issue,” he added