Access and Feeds

Security: Pros and Cons of White-Hat-Discovered Vulnerabilities

By Dick Weisinger

White-hat ethical hackers work to find vulnerabilities in popular apps and software and attempt to alert the authors of the problem to avoid future exploits from the Black-Hat hacker bad guys. Good in theory. But does this approach just tip the scales towards the black-hats, giving them free surveillance that they can attempt to use and exploit before users are able to roll out security patches that would fix the discovered problems?

Adam Segal, author of “The Hacked World Order”, told CSO that “black-hats are ahead of white-hats. That is symptomatic of the larger problem in cybersecurity that offense still has the edge over defense. The defender has to worry about millions of lines of code, thousands of devices, thousands of networks. The attacker only has to be right once.”

One easy way for hackers to crack systems is to exploit unpatched known problems. There are a lot of problems out there. BugCrowd in 2020 reported a 65 percent increase in priority-one vulnerability submissions, the most severe type of bug that could cause critical damage.

Public vulnerabilities are a tip-off to black-hat attackers of problems. Once attackers know of a problem they can work to develop an exploit. Paradoxically, a vendor’s patch to fix a problem is often a gift to the attacker. Patches provide hackers with the solution that fixes the problem. How? Patches can be reverse engineered and the patch code often clearly points out the exact cause of the flaw, making it easier for the attacker to come up with code that can exploit the problem, and that exploit code can then be used to target systems that are yet to be patched.

One study found that it takes on average 97 days for an organization to test and deploy a patch. Many organizations want to make sure that the new software doesn’t introduce additional unintended problems. The delay in patching provides a window of opportunity to hackers.

A US government report found that “foreign cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations. Exploitation of these vulnerabilities often requires fewer resources as compared with zero-day exploits for which no patches are available.”

Digg This
Reddit This
Stumble Now!
Buzz This
Vote on DZone
Share on Facebook
Bookmark this on Delicious
Kick It on DotNetKicks.com
Shout it
Share on LinkedIn
Bookmark this on Technorati
Post on Twitter
Google Buzz (aka. Google Reader)
0 comments on “Security: Pros and Cons of White-Hat-Discovered Vulnerabilities
1 Pings/Trackbacks for "Security: Pros and Cons of White-Hat-Discovered Vulnerabilities"
  1. […] Security: Pros and Cons of White-Hat-Discovered Vulnerabilities  Formtek Blog […]

Leave a Reply

Your email address will not be published. Required fields are marked *

*