On BNET: Vote: How will Apple blow it?
BNET Business Network:
BNET
TechRepublic
ZDNet

June 25th, 2009

Secunia: Average insecure program per PC rate remains high

Posted by Dancho Danchev @ 11:21 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Exploit code, Firefox, Hackers, Malware, Microsoft, Mozilla, Passwords, Patch Watch, Pen testing, Vulnerability research, Windows Vista, Zero-day attacks

Tags: PC, Secunia, Desktops, Viruses And Worms, Security, Hardware, Dancho Danchev

With the time frame for an exploit to become an inseparable part of a web malware exploitation kit shrinking, and with the average Internet user’s over-confidence in an antivirus scanner’s ability to detect and block exploits (Secunia: popular security suites failing to block exploits) it shouldn’t come as a surprise that Secunia’s recently released WorldMap shows a relatively high rate for insecure programs found on a single PC.

The WorldMap of patched and unpatched PCs is released prior to an updated version of Secunia’s Personal Software Inspector, with the latest version finally filling a niche left open potentially undermining the usefulness of the handy tool in general - measuring the exploitability of cross-browser plugins such as Adobe Flash Player, QuickTime, or Sun’s Java.

Let’s take a look at some of their stats.

North America is led by Cuba with 15 insecure programs on average, and with 4 insecure programs on average, Canada and Mexico lead the U.S which has 3 insecure applications installed per PC. However, Secunia’s emphasis on the big picture points out that there are at least 2.7 billion vulnerable programs installed in the U.S alone.

Mikkel Winther comments:

The fact that US based PC users have more than 2.7 billion vulnerable programs installed are shocking! And quite frankly I am very surprised, we had an idea it would be bad, but couldn’t imagine the enormous scope of this problem. And to make things even worse, the picture formed in the US is the same all over the world. PC users need to patch! They need to patch all their vulnerable programs and they need to do so as fast as possible after the patch has been issued from the vendor. Failing to do so is playing Russian Roulette with your IT security – it is only a question about time – and luck – when your system will be compromised.

South America is led by Guadeloupe with 12 insecure programs in average, San Marino with its 11 insecure programs on average leads Europe, and Yemen with 12 insecure programs on average tops Asia’s chart. These results should be considered as very conservative, with the real data itself much more disturbing if only all the Internet users in these countries were running the PSI.

Despite the fact that according to Secunia’s WorldMap there are countries like Burkina Faso with 20 insecure programs per PC, or Cuba with 15, it only takes a single unpatched application or a browser plugin in order for the cybercriminal to successfully exploit the host on-the-fly through a mix of popular exploits (Cybercriminals release Christmas themed web malware exploitation kit) embedded within a particular kit.

Prior to the official announcement of PSI 1.5, Secunia stated thatpatching is more important than having an Anti-Virus program and a personal firewall.

What do you think? Talkback.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 19 Talkback(s)
Hardening = moat, Unpatched 3rd party app = open draw bridge
Your hardened OS is going down if you don't secure the applications that run on top of it. (Read the rest)
Posted by: ejhonda Posted on: 08/13/09 You are currently: a Guest | | Terms of Use
Generalizations are always bad wink  mechBgon | 06/25/09
Low-rights user accounts will not work  Lerianis2 | 06/25/09
Low-rights accounts worked well for me  mechBgon | 06/25/09
This is where Linux wins big time  NonZealot | 06/25/09
You can control *when* patching occurs  Dietrich T. Schmitz | 06/25/09
That just gives me a 'warm and comfy' feeling about Windows...  Dietrich T. Schmitz | 06/25/09
Look up Vista security features...  jamesrayg | 06/25/09
And if Ubuntu actually became a SERIOUS OS...  kaninelupus | 06/27/09
Ubuntu is already a serious contender  dougan_w@... | 06/27/09
Anyone see the major flaw in this survey ?  Alan Smithie | 06/25/09
Ecosystem Improvement  johnfenjackson@... | 06/26/09
Hardening a system is more important than patching & AV  s_southern | 06/26/09
Hardening = moat, Unpatched 3rd party app = open draw bridge  ejhonda | 08/13/09
Secunia makes a great product: OSI & PSI  ejhonda | 06/26/09
Guadeloupe in South America?  goyta | 06/26/09
RE: Secunia: Average insecure program per PC rate remains high  phatkat | 06/26/09
RE: Secunia: Average insecure program per PC rate remains high  30bob1 | 06/26/09
Why it Matters, What You can Do!  eiverson@... | 06/29/09
Some insecure programs may not put your computer at risk  aa3805@... | 07/07/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline