favoritearticlesinc.com favoritearticlesinc.com
   Index >> About Us >> Privacy >> Terms of Use >> Add Url >> Submit Article
Search:   
Free links exchange
 
   

Drink & Food

   

Computers & Networking

   

Policies & Law

   

Property & Estate

   

Education & Learning

   

Investment & Finance

   

Health & Hygiene

   

Careers & Employment

   

Automotive

   

Self Help

   

Technology & Science

   

Art & Creative

   

Recreation & Entertainment

   

Business & Commerce

   

Lifestyle & Fashion

   

Healthcare & Medicine

   

Issues & News

   

Travel & Vacation

   

Malls & Shopping

   

Family & Home

   

Games & Play

   

Adventure & Sports

   

People & Society

   

Teens & Kids

 

Index –› Computers & Networking –› Security & Firewalls
 

5 Threats that make your Website Vulnerable, Part 2: Web Protocols are not Secure

 

Over 50% of all new vulnerabilities being identified on a weekly basis are attributed to web applications (SANS @RISK, The Consensus Security Vulnerability Alert)
More than 80% of all malware that emerged in the past year focus on application-level vulnerabilities (various sources, 2006).
In June 2006, 92 SQL injection and 34 cross-site scripting (XSS) new vulnerabilities were recorded on our database (Secunia)


The rationale behind HTTP protocol is to favor easy, quick and light communication and inter-connection. It has been designed to extensively share information, without really addressing security aspects. Indeed, these were considered as a constraint, supposed to slow traffic down and restrain freedom. As Jon Postel states (a key contributor of internet Requests For Comments) in his Law be conservative in what you do, be liberal in what you accept from others (Sept. 1981).
Very well known security principles are confidentiality, availability, integrity and auditability (ability to answer key questions such as who, what, when, where, to whom). HTTP protocol gives poor result on these aspects. HTTPS improves confidentiality aspects during transit but if initial traffic was malicious, web server will receive and process malicious SSL traffic ! Web protocols hardly authenticate, only partly guarantee confidentiality and integrity, do not protect against spoofing
Keep in mind that an URL sent by a browser is a command line to your web server : for instance an URL generating an SQL command or activating a CGI script.
At last, web protocols do not impose input validation, this is the major cause of their insecurity !
A solution is needed as web architectures are increasingly adopted in core IT systems !

The third article is about coding secure web sites

Richard Touret is manager at Binarysec, http://www.binarysec.com , security software company editing an intelligent web application softwall -or software firewall-. This Apache module adapts on most web sites, learning legitimate traffic to block any malicious request, including sql injection, cross-site scripting, directory traversal, forceful browsing, command injection, parameter tampering, attack obfuscation, buffer overflow...

Author: Richard Touret
 
Author Bio:
Richard Touret is a reputed author. Richard likes to write articles about this subject.
 
 
 

Related Articles

 
Nokia N80: Entertainment @ Work
 
10 Essentials To Creating A Blog That Pulls In Money Like a Magnet
 
Should Links Between Real And Virtual Economies Be Encouraged Or Banned?
 
Email Marketing Software Maxemail moves to version 4
 
Leveraging eBook Products
 
What Exactly is a Usb Bluetooth Dongle?
 
All About Spam and How to Control It With Anti Spam Software
 
How To Get Your Site Indexed Immediately
 
Freebies - Good Deal or a Waste of Time
 
For Lightning-Fast Speed, What You Need is Comcast Internet
 
 
 
 
 

The 10 Biggest Search Engine Optimization Mistakes: #6: No 'Alt Tags'

??Alt Tags?? ?C short for Alternate Tags were originally designed to contain the text to be displaye ... - David Bain
 

Who Else Wants To Maximize Their Google Adwords Success?

"Discover Three Simple But Incredibly Powerful Strategies That You Can Implement Right Now About The ... - 123456789
 

Linking For Website Traffic Generation

One thing gaining in popularity these days is building and exchanging links with other websites, and ... - Liane Bate
 
 

Effective Blogging - How to Get Wealthy Blogging

You call yourself a marketer but you are not a Blogger? Weblogs are a fact, you cannot ignore them, ... - Anton Linner
 

History of the Telephone -- from Bell to VoIP and Beyond

Everyone knows the story of Alexander Graham Bell inventing the telephone. There's the story of Bell ... - Lucy P. Roberts
 
 
   Index >> Privacy >> Terms of Use
© 2008 www.favoritearticlesinc.com All Rights Reserved.