On MovieTome: The 10 worst movies of 2009 so far!
BNET Business Network:
BNET
TechRepublic
ZDNet

October 11th, 2007

Fortify calls Apache tools insecure

Posted by Dana Blankenhorn @ 8:37 am

Categories: Applications, Development, General, Infrastructure, Internet, Security, support

Tags: Criminal, Apache Software Foundation, Tool, Open Source, Security, Dana Blankenhorn

Brian Chess from Berenger.orgFortify Software chief scientist Brian Chess and his team have published a white paper demonstrating how cross-build injection attacks could let criminals take control of programs as they are being written.

In particular the paper says three Apache projects — Ant, Maven, and Ivy (the latter is now in an Apache incubator) could make developers, and their employers, vulnerable.

All three projects are “external dependencies” which are loaded during a build process, Fortify wrote. A criminal could thus hijack the build and enable trojans or other programs future access.

While the vulnerability at this point is theoretical — the main fix so far is an update to security coding rulepacks —  the alert highlights just how sophisticated criminal gangs are becoming in their efforts to hijack PCs for use by botnets, which are now the major security threat on the Internet. Once broken into smaller botnets to escape detection, they can be rented out to other criminals for as little as $1,000 per hour.

Botnets are not just being used for distributing spam or viruses anymore. They’re also being used to blackmail sites with threats of DNS attacks. Some alarmists even see them determining the next President as politicians use them for dirty tricks campaigns.

Given all that the idea of someone hijacking your little corporate build by getting between your development team and its tools is not that far-fetched. And it’s useful to know what is theoretically possible before you find out about vulnerabilities the hard way.

Dana BlankenhornDana Blankenhorn has been a business journalist for 30 years, a tech freelancer since 1983. You can follow Dana on Twitter. See his full profile and disclosure of his industry affiliations.

Email Dana Blankenhorn

Subscribe to Linux and Open Source via Email alerts or RSS.

  • Talkback
  • Most Recent of 12 Talkback(s)
You've hit Nail on the Button!
I'm glad someone is sensible enough to see thru all the subterfuge coming from these guys.

Ulterior motives are almost always wolves in sheep clothing.

Fortify may think releasing questi... (Read the rest)
Posted by: thx-1138_@... Posted on: 10/11/07 You are currently: a Guest | | Terms of Use
It's true, but not Apache centric  TripleII | 10/11/07
Why Apache  DanaBlankenhornZDNet Moderator | 10/11/07
I don't disagree, per se  TripleII | 10/11/07
Vulnerability Reporting Solves This Problem  Melisa@... | 10/11/07
RE: Fortify calls Apache tools insecure  devils_advocate | 10/11/07
This is WAY far fetched.  bjbrock | 10/11/07
Not necessarily  DanaBlankenhornZDNet Moderator | 10/11/07
If they get into your systems far enough to affect..  mrOSX | 10/11/07
I was thinking the same thing...  Linux User 147560 | 10/11/07
Someone tell me how this is different...  Rokstar83 | 10/11/07
I have to Agree  rjacksix | 10/11/07
You've hit Nail on the Button!  thx-1138_@... | 10/11/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More