Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

8/11/2010
05:21 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Post Patch Tuesday. Don't Stop There

While you may be well underway testing and deploying this month's hefty batch of patches from Redmond, it's never too soon to ask: how secure do the rest of your applications and servers look?

While you may be well underway testing and deploying this month's hefty batch of patches from Redmond, it's never too soon to ask: how secure do the rest of your applications and servers look?There's no reason to go through all of this trouble month after month deploying all of these Microsoft patches only to leave the rest of your servers and applications porous and open to anyone who has read a beginner's book about Web application hacking. Unfortunately, that's what many medium-sized enterprises tend to do. And there's really no reason for it, beyond not taking the time to cover the security basics.

Here a few steps that can be taken to get your organization headed in the right direction:

Harden Servers. Review your vendor guidance on how to keep the servers secured and establish an acceptable configuration. Test that configuration before deployment into production: turn off unnecessary services, make sure patches are up to date, change manufacture passwords. NIST maintains its 800 series documents, of interest to those responsible for IT security. Check out SP800-123, Guide to General Server Security. Next: make sure they stay hard.

Vulnerability Assessments. Outsource or do-it-yourself: run vulnerability assessments across your infrastructure to: make certain you're aware of all networked devices that are active and to identify and prioritize vulnerabilities that need remediation on those systems. One of the keys to a successful vulnerability management program is repetition: identify vulnerabilities, prioritize, remediate, validate remediation - and repeat.

Review Your Code. In addition to network scans, it's vital to have your application code evaluated for flaws (either by someone trained in-house, or by a consultant familiar with web application security.). The most effective way to build secure applications is to build applications with security as part of the process throughout. That includes from application design through development. With additional careful security testing before moving to production and then throughout maintenance: one wants to build security into the Software Development Life-cycle (SDLC). Microsoft has provided guidance on getting started with what it calls the Secure Development Lifecycle. And the Open Web Application Security Project (OWASP) has plenty of resources on the subject as well.

So while you labor through the pain of patching your systems with these 34 patches, save some energy to test your other applications and to make sure your servers are snug. Otherwise, you're really just wasting your time.

For my security and technology observations throughout the day, find me on Twitter.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
What the FedEx Logo Taught Me About Cybersecurity
Matt Shea, Head of Federal @ MixMode,  6/4/2021
Edge-DRsplash-10-edge-articles
A View From Inside a Deception
Sara Peters, Senior Editor at Dark Reading,  6/2/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23394
PUBLISHED: 2021-06-13
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
CVE-2021-34682
PUBLISHED: 2021-06-12
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
CVE-2021-31811
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-31812
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-32552
PUBLISHED: 2021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.