ie8 fix

Linux and Open Source

Steven J. Vaughan-Nichols & Paula Rooney

Qualys does more than complain about insecure open source

By | August 2, 2010, 5:38am PDT

Summary: Qualys is offering a free, open source tool, called Blind Elephant, that lets you see the depth of the open source versioning problem yourself.

In the last few years I have gotten several press releases about the insecurity of open source.

A small and welcome industry has emerged around it.

One of the key problem is simple versioning. Many people and companies don’t keep their open source up to date, so when a security hole is later found it may go unpatched for years.

Rather than just kvetch about it, Qualys is offering a free, open source tool, called Blind Elephant, that lets you see the depth of the problem yourself.

The software describes itself as a “web application fingerprinter.” It discovers the version of the application you’re running by by “comparing static files at known locations against precomputed hashes for versions of those files in all all available releases.”

Among the least-updated (and thus least-secure) open source programs in Qualsys’ own analysis are Movable Type, Joomla and phpBB.

The solution is dead simple. Update. Get the latest version, make certain it’s pushed out to all your desktops, and manage things professionally. Just because you’re running open source doesn’t mean you don’t have a professional installation.

What I like best about Qualys is its attitude concerning all this. Rather than condemning what is happening, or use it just as an excuse for a sales call, the company has taken action. And its excellent Sourceforge page even includes links to Sucuri and WAFP, projects which do similar things.

I also understand no elephants were harmed in the creation of this software.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dana Blankenhorn has been a business journalist for 30 years, a tech freelancer since 1983.

Disclosure

Dana Blankenhorn

Dana Blankenhorn has been a journalist, writer and part-time futurist for over 30 years.

At the present moment I run only a personal blog in addition to my ZDNet open source blog.

DanaBlankenhorn.Com has the subtitle The War Against Oil. In the past I have used it to write about political history, e-commerce, personal matters, some ideas related to open source, and The World of Always On, which is the idea of using sensors, motes and RFID to turn WiFi links into platforms for applications which live in the air.

My IRA account at Schwab holds a few tech shares, most notably some Intel and Applied Materials, but there are no open source companies in it. I don’t even own any CBS stock.

Biography

Dana Blankenhorn

Dana Blankenhorn has been a business journalist for nearly 25 years and has covered the online world professionally since 1985. He founded the Interactive Age Daily for CMP Media, and has written for the Chicago Tribune, Advertising Age's "NetMarketing" supplement, and dozens of other publications over the years.

1
Comments

Join the conversation!

0 Votes
+ -
good idea... but
A.Lizard 3rd Aug 2010
anything that has to be checked out via subversion and built from source is NOT ready for the enterprise.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix