Warning: Trying to access array offset on value of type bool in /home/sites/3b/7/74de28c56e/public_html/wp-content/plugins/related-posts-thumbnails/related-posts-thumbnails.php on line 846
 

Blacklisting - If your company is not blacklisting then it could be a sitting duck! - InstaHost Solutions

28th January 2018by Andy Mc

2016 has been a busy year for cyber criminals,with indications that there have been over 500 data breaches and more than 500 million records exposed up to today. This includes the disclosure of 500 million Yahoo accounts,  68 million Dropbox User records and 117 million user emails and password details at LinkedIn.

Businesses have moral and legal responsibilities

to keep their clients and customers data secure, Hackers seeking to access such data is now a persistant risk and Advanced Persistent Threats (APT’s) are on the rise, while “ransomware” and the use of targeted phishing attacks are being used for financial blackmail and to gain access or leak sensitive, confidential information. .

There has been a a tendency for small business owners to assume that hackers would not bother with SME’s / small businesses however to put things in perspective, 75 percent of small businesses were a target of a cyber-attack and because cyber security defenses are typically lacking, steps must be taken to protect data and reduce the risk of an attack.

SME Systems pose an easy target for attackers because they often run legacy operating systems, applications and may not apply security updates due to the potential for subsquent issues. Security compliance and complexity of the systems make security a larger task and therefore typically has been lower in priority. Companies continue to be vulnerable to cyber-attacks and data disclosures until they implement more secure measures to protect, detect and respond against these threats.

A major concern is the ever growing and increasing complexity of patching systems and applications. The importance of “patch management” is huge since it can mitigate more than 80 percent of cyber threats.  Yet C-Suite “leaders” and Company Directors seem to assume a “if it’s working, don’t upgrade / patch” attitude.  This is a dangerous and frankly stupid attitude to adopt. Vulnerabilities are growing each year and out of the exploited vulnerabilities in 2015, 99 percent of them had Common Vulnerabilities and Exposures (CVE’s) published and had patches available.

Organisations use a plethora of applications to allow their businesses function, and with millions of applications to choose from, that help with accessing emails, browsing the internet, running videos, accessing reports and client data and many more business functions. Many of these applications are very widely used and companies naturally depend on these applications however applications do and will have vulnerabilities which hackers and cyber criminals exploit and access systems running the  unpatched / insecure applications.

Each year many CVE’s are posted on the National Vulnerability Database, which helps alert companies who are using these applications and inform them on the mitigation controls to reduce the risks of using such applications. Some applications, however, pose a much greater risk and unless those systems running these applications are locked down significantly the only alternative options are to blacklist them or remove them completely. Let’s take a look at some of those applications which you definately should not have on your systems.

 

#1 Adobe Flash Player

Adobe Flash Player formally known as “Macromedia Flash” or “Shockwave” is a multimedia application that helped enrich the experience when browsing the Internet and allows streaming of video and audio. It is also used in some desktop applications, mobile applications and games.

However, for many years, Flash has had a very poor record for security and vulnerabilities are everywhere for flash with over 400 CVE’s being published. Hackers and cyber criminals have been exploiting it for many years as it enables them to listen to your conversations and use your web camera to watch you in your office or home. Many web browsers have removed support for flash and block it from running, however, many companies and consumers are still using older web browser which still allow flash to run.

It is vital that every user upgrades to use the latest versions of web browsers (Microsoft Edge, IE, Firefox or Chrome) and to blacklist Adobe Flash or remove it from your system.

#2 Appl QuickTime for Windows

Apple QuickTime is a multimedia framework that was used for handling various digital video formats and was available on multiple platforms for Mac OS and Windows. The Windows version was also bundled in some versions of iTunes and also many applications that required QuickTime to play digital content provided download links to make it easy for someone to quickly install.

This year Apple decided to discontinue support for QuickTime on Windows and with several severe and dangerous security vulnerabilities that a hacker could exploit allowing them to take full control over your computer. QuickTime is no longer being updated and these security flaws or any newly discovered vulnerabilities will unlikely be fixed. This truly means that QuickTime for Windows is dead and should no longer be used.

This application should immediately be blacklisted and removed from all systems.

 

#3 Apple iTunes for Windows

Apple iTunes is a media player, media library and mobile device management software developed by Apple in order to be able to organize and manage all of the company’s mobile devices and digital media. It is almost impossible to use an Apple device without requiring the need to use iTunes. However, if you are a Windows user with an Apple device, then using iTunes on Windows is a major security risk. Apple iTunes has had more than 100 CVE’s published and is consistently in the top 10 most vulnerable applications each year. It is also commonly known that apple users do not keep updating iTunes to the latest versions, which typically come with many security updates or you could be using an outdated version that is also bundled with Apple QuickTime, which is listed as the top security risk with many existing exploits.
With iTunes posing a major security risk for many organisations and due to many old and legacy versions containing known and exploitable vulnerabilities, it is recommended to blacklist Apple iTunes for Windows or remove this from your systems.

 

 

#4 Microsoft Office 2007

With Microsoft Office 2007 about to officially end extended support in October 2017 and with mainstream support already ending in 2012 this means the end of life is coming for Office 2007. So if you are still using Office 2007 do not expect any further security updates in which it is a common target for many hackers and cyber criminals to find exploits in these applications due to its high common use across many organizations and consumers. Microsoft frequently provides many critical security updates so it is always important to stay patched and up to date with the latest versions and this makes moving away from Office 2007 more critical now than ever before due to the end of life. Office 2007 has very poor security, privacy, auditing and sharing features so while hackers target it, it also does not provide enough protection on the data created using Office 2007.

If you are using Microsoft Office 2007  STOP!  it is recommended to upgrade to the latest version, blacklist these older versions and remove them from your systems.

It is crucially  important that companies take a proactive approach to blacklisting and removing high-risk applications or applications that have entered end-of-life; they should be removed as they no longer get critical security updates to remove any major security flaws discovered. Hackers and cyber criminals commonly target these security flaws.

Blacklisting applications is a method used to prevent the installation or running of such applications and are denied system access. Blacklisting should be used to target prohibited applications or applications that cause a significant high security risk to companies like the applications listed above.

Blacklisting applications should be used in conjunction with application whitelisting to ensure your Data Security Action Plans are robust and fit for purpose.

Ageing infrastructure

As you know, cyber security is not all about software. Hardware can be a major issue as well.  This is especially true since the lifecycle of devices is becoming increasingly shorter.

If the hardware you use doesn’t allow you to install the newest patches for the software on it, then this indicates a critical weakness. If you use certain types of software that require older versions of plugins, such as Java, than that can also cause security issues.

When purchasing new hardware, consider how many updates it will be able to support. Carefully monitor all devices as they age and deteriorate.

It’s not about spending unneccesary money on something that is currently working, it’s about ensuring the itegrity of your systems and data and that you can run the latest versions of the software you need!

 

https://www.instahost.solutions/wp-content/uploads/2018/10/logo1.png
https://www.instahost.solutions/wp-content/uploads/2017/03/logo_white.png
Insta Security
Website Secured by InstaHost.co.uk
InstaHost Solutions

Our Mission is to deliver an industry leading, comprehensive service to all of our clients regardless of client size or complexity of services required, we are committed to continually striving to develop new, innovative services and technologies in order to continue deliver cutting edge service solutions to all of our clients. We give our clients full control of their digital business without a ridiculous price tag, and our friendly team offers their expertise at all times!

Subscribe

If you wish to receive our latest news in your email box, just subscribe to our newsletter. We won’t spam you, we promise!

    Applauz

    As the pioneer of the lean startup movement, APPLAUZ has dedicated it’s time to sharing effective business strategies that help new businesses and enterpreneurs put their money to work in the right way.

    2021 Copyright by InstaHost Solutions, Powered by InstaHost.co.uk. All rights reserved.