Attack of the cyber-toxins / MIS, 15 March 2007
http://digbig.com/4rxsf
Patrick Gray
"Security used to mean buying a firewall, regularly patching your operating systems and installing some anti-virus software on your storage server or workstations. With AV and a firewall at your service and working in tandem, internet users outside your enterprise could connect to the appropriate IP ports on your web and email servers, while your workstations were shielded by the firewall from the outside world.
Today, the threat has been turned on its head. Application-level security vulnerabilities in client-side software like Internet Explorer, Word and PowerPoint mean that workstations are the new target of choice for hackers. Attacking enterprise servers directly has become so 2001. Now, there is more bad news. Your firewall can't really protect you against client-side attacks, and neither will traditional AV applications."