Ken
  Ken
Upstate New York
Age: Unknown
Entries: 7
 




Ken's Blog

What Are Zero Day Exploits

By Ken
posted 8/3/2009

Leave a Comment |  
(0) Comment

In the Information Security field, we have an event that we refer to as a "Zero Day".  Most of the time when we talk about a zero day, we are talking about a zero day exploit.  But occasionally, the term can be used to discuss a zero day vulnerability or flaw.  If you  are interested enough to follow me down this rabbit hole, I can help you understand all of this jargon and what it means to you and your business.

  StarReviews Top 3
Internet Security Software
   
  1) Security Shield 2010
  2) CA Internet Security 2009
  3) BitDefender Internet Security 2009
   
In order to understand the zero day, we must first understand the difference between a vulnerability and an exploit.  A vulnerability is a programming flaw that has the potential to be exploited in a way that jeopardizes the confidentiality, integrity, or availability of our information.  In short, a vulnerability is a bug that impacts security.  How does that differ from an exploit?

An exploit is a piece of code that takes advantage of (or exploits) the weaknesses made evident because of a vulnerability.  Or, more simply, an exploit is a computer program that uses a vulnerability in another computer program to make it do something it was not designed to do.  The proper application of an exploit to a vulnerable computer system, in the worst cases, leads to an unauthorized person (e.g. malicious hacker or script kiddy) gaining administrative access to your computer, across the Internet.

Now that we know what an exploit is, and how they take advantage of vulnerabilities, we can move farther down this rabbit hole.  While none of this is pleasant, in the best cases, a software vendor finds their own bug (vulnerability) and fixes it before anyone even knows there was a problem.  The software vendor then releases a "patch" which updates the programming code of the application, in effect swapping out the code that had the security flaw in it with code that is vulnerable to attack.  In these best case scenarios, an end user or business running this vendor’s software must apply the patch released in order to remedy the vulnerability.  The sad part of this version of the story is that millions of people do not update their software in any systematic fashion - and therefore stay vulnerable.

In another instance, an Information Security firm or freelancer (researcher) that specializes in finding vulnerabilities reviews a vendors product and finds a vulnerability.  This case can go pretty much like the one above, if the firm or freelancer follows the ethics most often used in the Information Security Industry.  These ethics state that when such a vulnerability is found, that the knowledge of the vulnerability is given (first) only to the vendor responsible for fixing the flaw.  The researcher is supposed to give the vendor time to fix the problem before telling the world.  When things go as planned, the vendor releases a patch, and the researcher releases their information to the public - and everyone is happy.  However, if the researcher does not give the vendor any time to fix the flaw - and releases the information to the public without any notice to the vendor - we have a zero-day vulnerability.  At this point the race is on between the vendor to fix the flaw and malicious hackers to come up with an exploit.

The last case is the most common when we are talking about zero day events.  In this scenario, the "researcher" is the malicious hacker.  He finds the flaw and tells no one about it.  He develops, tests, and deploys an exploit in the underground.  The public at large finds out about it when "things start happening" on their systems.  In effect the public learns about the issue through cyber-casualties.  The vendor and the Information Security Industry must capture a copy of the exploit code, and then reverse engineer (disassemble it and examine it in detail) the exploit in order to understand how it works.  Thereby, the security teams can try to find the vulnerability through examining the exploit.  Once that is done, the vendor can try to patch their vulnerable code.

In the past few months there have been several zero day events.  Adobe is fighting to fix flaws discovered after the release of a zero day exploit impacting even PDF files, likewise Microsoft is fighting to fix problems that impact their Microsoft Office Web Components which they describe as potentially creating a "browse and get owned" scenario, and the Mozilla team is in the cyber-trenches as I write this, trying to fix issues with Firefox. 

What should I do?  Watch for patches, apply patches, and keep you internet security software up to date!



Leave a Comment |  
(0) Comment


Zero Day Exploits | Zero Day Events | Vulnerable Code



Affiliate Marketing Program
Airline
AntiSpam Software
AntiSpyware Software
AntiVirus Software
Apartment Rental Service
Audio Bookstores
Auto Insurance Website
Auto Loan Website
Baby Planning Website
Background Check Services
Bargain Shopping Website
Blogging Website
Business Credit Card
Business Networking Website
Car Pricing Website
Car Rental
Catholic Dating
Cellphone Company
Christian Dating Website
Club of the Month
College Scholarship Website
College Textbook Website
Coupon Website
Credit Card Processing Service
Credit Report Website
Custom Promotional Product
Custom T-Shirt Websites
Data Recovery Software
Dating Website
Deal A Day Website
Debt Consolidation
Dental Insurance Websites
Discount Inkjet Cartridge
Download Website
DVD Burning Software
DVD Rental Website
eMail Marketing Service
Fantasy Sports
Fixed APR Credit Card
Flower Delivery Website
Font Download Website
Foreclosure Listing Website
Free eMail Service
Freelance Website
Game Rental Website
Genealogy Software
Genealogy Website
Gift and Gadget Website
Gift Basket Website
Greeting Card Website
Home Equity Loan
Hotel Reservation Website
Identity Theft Protection
Internet Security Software
Jewish Dating Website
Job Search Website
Low Interest Credit Card
Magazine Subscription Website
Message Board Service
MMORPG
Mortgage Refinance Loan
Movie Download Website
Movie Ticket Service
Music Download
Newspaper Subscription
No Annual Fee Credit Card
Nutrition and Health Website
Office Supply Website
Online Auction Website
Online Backup Services
Online Banking Website
Online Beauty Website
Online Bill Pay Website
Online Bookstore
Online Diet Service
Online Electronics Store
Online Fax Services
Online Handbag Website
Online Homework Help
Online Jewelry Website
Online Legal Website
Online Maternity Store
Online News Website
Online Perfume Store
Online Shoe Store
Online Sporting Goods Store
Online Stock Trading Website
Online Sunglass Store
Online Ticket Service
Online University Education
Paid Survey
Parental Control Software
Parenting Website
Party Planning Website
Payday Loan Website
People Search Website
Personalization Website
Pet Supply Website
Photo Printing Website
Photo Sharing Website
Pre-Paid Credit Card
Press Release Distribution Service
Real Estate Listing Website
Recipe Website
Registry Cleaner Software
Resume Writing Service
Ringtone Website
Screen Capture Software
Screensaver Website
Search Engine Submission Website
Self Publishing Website
Single Parent Dating Website
Social Networking Website
Stationery Website
Stock Photography Website
Student Credit Card
Student Loan Website
Study Guide Website
Supplemental Insurance Provider
Tax Preparation Service
Travel Reservations Website
Vacation Club Reviews
Video Sharing
Voice Over IP
Web Analytics Service
Web Hosting Reviews
Website Template Service
Wedding Favor Website
Wedding Planning Website
Affiliate Marketing Program
Airline
AntiSpam Software
AntiSpyware Software
AntiVirus Software
Apartment Rental Service
Audio Bookstores
Auto Insurance Website
Auto Loan Website
Baby Planning Website
Background Check Services
Bargain Shopping Website
Blogging Website
Business Credit Card
Business Networking Website
Car Pricing Website
Car Rental
Catholic Dating
Cellphone Company
Christian Dating Website
Club of the Month
College Scholarship Website
College Textbook Website
Coupon Website
Credit Card Processing Service
Credit Report Website
Custom Promotional Product
Custom T-Shirt Websites
Data Recovery Software
Dating Website
Deal A Day Website
Debt Consolidation
Dental Insurance Websites
Discount Inkjet Cartridge
Download Website
DVD Burning Software
DVD Rental Website
eMail Marketing Service
Fantasy Sports
Fixed APR Credit Card
Flower Delivery Website
Font Download Website
Foreclosure Listing Website
Free eMail Service
Freelance Website
Game Rental Website
Genealogy Software
Genealogy Website
Gift and Gadget Website
Gift Basket Website
Greeting Card Website
Home Equity Loan
Hotel Reservation Website
Identity Theft Protection
Internet Security Software
Jewish Dating Website
Job Search Website
Low Interest Credit Card
Magazine Subscription Website
Message Board Service
MMORPG
Mortgage Refinance Loan
Movie Download Website
Movie Ticket Service
Music Download
Newspaper Subscription
No Annual Fee Credit Card
Nutrition and Health Website
Office Supply Website
Online Auction Website
Online Backup Services
Online Banking Website
Online Beauty Website
Online Bill Pay Website
Online Bookstore
Online Diet Service
Online Electronics Store
Online Fax Services
Online Handbag Website
Online Homework Help
Online Jewelry Website
Online Legal Website
Online Maternity Store
Online News Website
Online Perfume Store
Online Shoe Store
Online Sporting Goods Store
Online Stock Trading Website
Online Sunglass Store
Online Ticket Service
Online University Education
Paid Survey
Parental Control Software
Parenting Website
Party Planning Website
Payday Loan Website
People Search Website
Personalization Website
Pet Supply Website
Photo Printing Website
Photo Sharing Website
Pre-Paid Credit Card
Press Release Distribution Service
Real Estate Listing Website
Recipe Website
Registry Cleaner Software
Resume Writing Service
Ringtone Website
Screen Capture Software
Screensaver Website
Search Engine Submission Website
Self Publishing Website
Single Parent Dating Website
Social Networking Website
Stationery Website
Stock Photography Website
Student Credit Card
Student Loan Website
Study Guide Website
Supplemental Insurance Provider
Tax Preparation Service
Travel Reservations Website
Vacation Club Reviews
Video Sharing
Voice Over IP
Web Analytics Service
Web Hosting Reviews
Website Template Service
Wedding Favor Website
Wedding Planning Website