Real Story Group. Make Better Technology Decisions.

Formerly CMS Watch. Here's our story
What Real Independence means. Find Out

  • Schedule a Demo
  • Free Sample
  • Contact
  • Subscriber Login
  • Your cart is empty.
Sign up for our Newsletter
  • Home
  • Evaluation Reports
  • Premium Subscriptions
  • About
  • Blog
  • Buy Now
  • Recent Entries
  • Get Custom Feeds

 

 

 

Thomas Kas Thomas

Quick: what do Joomla!, Drupal, and WordPress have in common?

18-Aug-2008

Tags: Web Content Management, Industry Standards, Open Source, Drupal, Joomla!, WordPress

Big Blue recently released its IBM Internet Security Systems X-Force 2008 Mid-Year Trend Statistics report, and it contains more than a few eyebrow-raisers. For example: Web-application-based security vulnerabilities have begun to outnumber reports involving conventional viruses and trojans (of the kind that target the operating system). We're now at the point where 51 percent of newly discovered software vulnerabilities depend in some way on web-page interactions.

Also, there's been a sharp surge in the number of vulnerabilities that involve SQL injection (as opposed to cross-site scripting). Meanwhile, the use of infected image files (.gif or .jpg) as a way to inflict mayhem is on the decline.

What really got my attention, though, is the new Top Ten list of vendors with the most vulnerability disclosures. Normally you would expect Microsoft to be at the top of that list (I would, at least). Instead, it's at Number 3, behind Apple and... Joomla!. Fortunately, Joomla! can be secured, but it's quite possible that many novice Joomla! installers do not.

Numbers 8, 9 and 10 are interesting, as well: Drupal, WordPress, and Linux.

The finding that no fewer than four of the top ten vendors with the most reported vulnerabilities are open-source projects is, at first blush, quite striking. But the results should be viewed with caution. In part, the rankings reflect a recent change in IBM's data-gathering methodology (which the report's authors are quick to point out). Another important caveat is that the numbers are not normalized against adoption rates or installed seats or any other usage metrics. They're based on raw numbers.

It's worth remembering, too, that open source projects are extraordinarily open about security vulnerabilities. Hence you would expect a comparatively high rate of reporting for an open-source product. Finding, publishing, and fixing security vulnerabilities is something the open-source community has gotten quite good at, particularly in the Linux world, where every line of code for the entire operating system (including all encryption routines, random-number-generating code, and so on) is available free for the downloading. Security flaws in Linux tend to be found and corrected with astonishing alacrity.

On the other hand, it's striking that three of the Top Ten contenders on IBM's security worry-list have PHP in common. You can read whatever you want to into that, I suppose. I'm not a PHP expert, but I'm enough of a web developer to know that languages don't create security problems; programmers do.

If you have the time and the inclination, download the IBM report. At 85 pages, it' a well-worthwhile lunch-hour read, if you care about web-app security ... as I think we all should.

    Now Get the Complete Real Story

    Vendor Evaluations

    Learn the real strengths and weaknesses of major vendors from around the world, in our research stream.

Tweet

close x

Free Sample Request

  Digital and Media Asset Management
  Document Management (ECM)
  Enterprise Collaboration & Social Software
  Enterprise Search
  Portals and Content Integration
  SharePoint Ecosystem
  Web Content Management
 Send me bi-weekly tips and insights from Real Story Group.
Your personal information, including your e-mail address, will be held in the strictest of confidence and will never be shared with anyone.

Subscriber Log In


Remember Me
Forgot password?


Not a subscriber?
Learn about our subscriptions

Research Mentioned in this Post

Vendor Evaluations

 | 

Our Newsletter

Get the Real Story bi-weekly.

Have Questions?

USA & Canada
+1 800 325 6190

UK
+44 (0) 20 3318 1911

International
+1 617 340 6464


All Other Inquiries

Our Customers Say

"The Web CMS Research is worth every penny!"

Gil Côté, President and CTO, iStudio Canada Inc.

next More

Real Story Group

Follow us on:  RSS  |  Twitter  |  Facebook  |  YouTube

Evaluation Reports

  • Web Content Management
  • Document Management (ECM)
  • Portals and Content Integration
  • Enterprise Search
  • Digital and Media Asset Management
  • SharePoint Ecosystem
  • Enterprise Collaboration & Social Software

Premium Subscriptions

  • Research Streams
  • Advisory Papers
  • Vendors Evaluated
  • Schedule Analyst Consultation
  • Online Education
  • Configure a Subscription

About Us

  • Our Methodology
  • Our Team
  • Media
  • Customer List
  • Events
  • Consulting
  • Contact Us

Need Help?

  • Talk to an Expert
  • FAQs
  • Customer Support
  • Contact Sales Team
  • Help with your account

Copyright Real Story Group 2001 - 2012. All rights reserved.

  • Contact Us
  • Copyright Policy
  • Privacy Policy
  • Terms of Use

Log In

Remember MeForgot password?

close x
close x

All analyst firms claim to be independent or vendor-neutral. We're different.

Real Independence


Get the real story on commercial and open source tools from a firm that works only for you, the technology customer.

close x

Newsletter Signup

Thank you for signing up for The Real Story Group Newsletter. You will receive our monthly newsletter, plus updates with new information on the technology streams you have expressed interest in below.










Choose the streams that you’d like to receive updates for: