The following article was published largely on the Nikkei newspaper page 3 of 4.25.
What a do would be unpleasant article.
Companies that have made a killing in the IT, there should be a duty to deal as soon as possible.
If, and if not, you're not a decent company, and is not a decent human being, it is human scum.
" The defects in the site creation software "
Authorities and companies
Risk of cyber attack
In order to have a web site,bank and government agencies, and companies have been widely used,software to "struts 1", it found the 24th is that there is a (vulnerable) security flaws.
There is a risk of cyber attack that a site or altered stolen confidential information and personal information.
Currently there is no fix (patch) support has been completed this software. Method of attack has been published on the Internet already, it's need to be addressed as soon as possible.
Struts1 is available for free in the software to be used for the operation and site creation.
Companies and organizations is taken from the early 2000s, according to the Information-technology Promotion Agency, an independent administrative institution, today, many, it is said that is used by government agencies and companies.
U.S. non-profit organization Apache Software Foundation , the developer will ship the final version in 2008 , was stop providing patch to end the support to April 13 . Defect was found for the first time in '08 or later.
Rack of information security is a major discovery, it announced on the 24th.
The company has seen that there is a possibility that new defects are found in the future .
When receiving the cyber attacks leaned defects which may take over the system to move the site. To steal the information because it can all operations, or alteration, can stop the site.
By using plant viruses that lead to attack the next infected visitors is facilitated.
It has come up with a policy to make a patch for NTT data to deliver more system using struts1, such as government agencies.
But, the “undecided Create completion date “ is in the present situation.
One of the measures of the user such as a company is able to recreate the site using a new software .
Another’s emergency measures temporarily fend off the attack. Expected if the developer who built the system, it is possible to cope if you can access to specific attacks.
Trend Micro has started selling the software to prevent access attack, also available temporary using this. Symantec also has shipped a similar product.
The 24th, National Information Security Center called for early response and reminded to each ministry.
Continued below