Secunia's first report on Security Inspector

From over 400,000 detected applications, the Software Inspector tagged over 35% as insecure versions!

For IE 6.x users, 4.12% were insecure, which is a good sign; most people probably are aware of using Windows updates to get new IE versions.

For Adobe Flash 9.x users, over 53% were running insecure versions; a testament to both the popularity of Flash-based web content, and the lack of awareness on Flash vulnerabilities.

More than one third of Firefox 1.x users (35.47%) were found to be running vulnerable versions; while Opera users were safer, with only 13.04% running vulnerable versions of Opera 9x.

Only 6.8% users were found to run insecure versions of Skype 2.x, the popular VoIP program.

http://secunia.com/blog/4/

I know Security Inspector's system requirement does not include Vista yet but I went ahead and run it in Vista/IE7 (with protected mode on). 

Result:

7 Applications Detected in Total
0 Insecure Versions Detected Stick out tongue
7 Secure Versions Detected

Failed to detect some other 3rd party applications in Vista and the MU updates because there's no security updates for Vista yet so there are errors (see screenshot at http://www.dozleng.com/updates/index.php?showtopic=12191 . I hope it will support Vista in the next version of their scanner so it will detect other applications that I have on it Big Smile

I am using MBSA 2.0.1, BigFix and Pedestal Security Audit (webscan) to check for missing hotfixes in XP box.  This Security Inspector of Secunia is another neat scanner that I'll be using too!

Update:  Check out the discussion on the above at http://www.dozleng.com/updates/index.php?showtopic=12191.  There is a concern.  Security Inspector is flagging or catching too the Flash version that is in the backup location insted of catching only the proper and default location of Flash.  Secunia need to do correct this concern. 

Published Tue, Dec 12 2006 3:26 by donna

Comments

Tuesday, December 12, 2006 5:30 AM by Adel

# re: Secunia's first report on Security Inspector

i guess it's finally true that MS is foucsing more in security you may check this post illustrating how SQL Server 2005 flaws since relese = 0 http://bloggingabout.net/blogs/adelkhalil/archive/2006/11/29/In-your-face-_2D00_--SQL-Server-2005-security-flaws-since-release-_3D00_-0.aspx.

thanks for the article though.

Tuesday, December 12, 2006 5:51 AM by Adel Khalil

# In Your face 2 - Vista Protected Mode, IE7, IE6.x way secure than FF,Opera and Flash Player

This is the seconed epsiod of IN YOUR FACE this time, Donna has just posted about a little test she did