Protect and survive [software security]
Ed Dickson · Information Professional · 2004
When the Morris worm surfaced in 1988 and infected many servers on the Internet, it revealed a serious flaw in several pieces of software including the sendmail email software. The curious thing is that exploits used by the worm's creator to help it burrow into the host system are still being used today against software that has too many security flaws. The result is that applications developers are now having to think like hackers to ensure that the software they write is not vulnerable to attack as companies try to combat the speed with which new exploits are being found. There are many forms of attack but, according to market analyst group Gartner, 75% of the hacker attacks today are at the application level. And 97% of more than 300 Websites audited were found vulnerable to Web application attack. Because the applications represent the weak link in the chain in terms of technical security-the vulnerabilities presented by users inadvertently installing Trojans and disclosing their passwords to fake login pages are another thing altogether-firewalls and secure sockets layer encryption do not help a great deal when dealing with a determined hacker. The vast majority of security holes in software results from design or programming errors that allow an attacker to direct a program's execution to an arbitrary memory location.