[an error occurred while processing this directive]
BBC News
watch One-Minute World News
Last Updated: Thursday, 5 May, 2005, 07:36 GMT 08:36 UK
Biggest security holes revealed
Volume indicator, BBC
Media players are being exploited by malicious hackers
Media players and anti-virus programs have been named in a list of the most pressing security problems.

Drawn up by non-profit security group Sans, the Top 20 names the software most in need of fixing to avoid attack by malicious hackers.

Programs make it on to the list if they are widely used, the bugs widely known, and are being actively exploited.

Vulnerabilities are being exploited so fast that Sans is issuing its Top 20 four times as often.

Faster threats

The Sans Top 20 used to be issued in October but the organisation has upped the pace of warnings in response to the accelerating speed of attacks from malicious hackers.

"The number of vulnerabilities is fairly solid," said Gerhard Eschelbeck, chief technology officer at security firm Qualys and contributor to the Sans list. "What's changing is the fact that these vulnerabilities are being exploited faster."

When Sans started producing its Top 20, he said, it took nine months to a year for exploit code to appear.

"Now code is circulating within weeks of the appearance of the vulnerability," he said.

If exploit code keeps appearing faster, Sans might have to issue alerts even more quickly, said Mr Eschelbeck.

"I think the truth lies somewhere between monthly and quarterly updates," he said, "because firms need to put resources behind it to schedule patches and so on."

As well as issuing reports more often, Sans has for the first time started including applications found to be vulnerable to attack. Previously the list has concentrated on operating systems such as Windows and Unix.

The list of at risk programs includes Microsoft's media player, iTunes, RealPlayer, WinAmp as well as anti-virus software from Symantec, F-Secure, Trend Micro and McAfee.

"These programs are out there being used and being exploited as well," said Mr Eschelbeck.

The ease with which media players let people share playlists was putting people at risk, he explained.

The good news was that there were patches available for all the vulnerabilities identified in the Sans Top 20, said Mr Eschelbeck.




SEE ALSO:
Web shops face tighter security
18 Apr 05 |  Technology
Ex-hacker warns on computer security
08 Apr 05 |  Click Online
Net security bug prompts warnings
13 Apr 05 |  Technology
Online music lovers 'frustrated'
25 Apr 05 |  Technology
Top 20 computer threats unveiled
09 Oct 04 |  Technology
Helpful users face virus danger
20 Apr 05 |  Technology


RELATED INTERNET LINKS:
The BBC is not responsible for the content of external internet sites


PRODUCTS AND SERVICES

News Front Page | Africa | Americas | Asia-Pacific | Europe | Middle East | South Asia
UK | Business | Entertainment | Science/Nature | Technology | Health
Have Your Say | In Pictures | Week at a Glance | Country Profiles | In Depth | Programmes
Americas Africa Europe Middle East South Asia Asia Pacific