ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Become a ZDNet.co.uk member

Christian Harris

View blog's RSS Feed

e-biz

putting the 'e' into business

Thursday 10 April 2008, 11:43 AM

Is Your Web Site Vulnerable?

Posted by Christian Harris

NTA Monitor recently released some statistics which are enough to put the fear of God into any owner of an e-commerce site.

Allegedly, 60% of Web application tests performed for UK organisations showed that their Web sites contained weak encryption or cross-site scripting (XSS) vulnerabilities. Furthermore, over three quarters (78%) of Web sites tested contained one or more medium level risk that may enable external users to gain unauthorised access or disrupt service availability.

So what does this actually mean? Some applications are vulnerable to cross-site scripting attacks, which enable a hostile Web site to cause potentially malicious code such as JavaScript commands to misdirect or compromise your visitor’s browser. This can enable an attacker to collect sensitive information such as passwords and card payment details.

Web applications are commonly the most vulnerable part of an organisation’s network, as they necessarily allow Internet users to input and access data. Content and design is frequently altered in order to keep up with the demand for new features and functionality, but even simple changes could produce a new vulnerability that may threaten confidential information.

Too reduce your risk you should apply a hardening and patching procedure to all Internet-facing Web servers, use strong encryption (128-bit SSL) for all sensitive details - such as credit card numbers and passwords - and all user-supplied data should be properly sanitised before returning it to the browser or storing it in a database.


Comments on this post

Christian Harris

This member is ranked #16 in our top 100

  • Christian Harris
  • Lichfield
  • Member since: February 2008

Site Activity Rating 5

CoreTechs

Contacts

Number of Contacts: 0

Contacts' Latest Discussions

Number of Tracked Discussions: 151

Karen Friar Karen Friar

Return to the dark side?

Tuesday 1 July 2008, 2:31 PM

1 comment
Karen Friar Karen Friar

Faking a fingerprint (part 1)

Monday 30 June 2008, 10:30 AM

4 comments

Contacts' Latest Blogs

Number of Contacts Blogs: 0