Web application security vulnerabilities and strategies
Posted on 26 October 2011.
Bookmark and Share
The use of web applications has soared recently, due to the significant value they can add to enterprises by providing innovative ways to interact with customers. However, so have the dangers.

Along with the benefits of these capabilities come security vulnerabilities that create dangerous risk and exposure. ISACA issued a new, free white paper which outlines the causes of web application vulnerabilities, examines the associated risk and impacts, and provides advice to mitigate risk. The guidance applies to all types of software development activities.

New web applications are client-server based and platform independent, require less computing power, and can be seamlessly integrated with online resources and services. Their use can result in time and cost reduction of processes, increased customer satisfaction, and increased revenue.

However, web application vulnerabilities open the door to the exploitation of sensitive corporate information, disruption of service and theft of intellectual property. Some common vulnerabilities identified in the white paper include:
  • SQL injection
  • Cross-site scripting
  • Insecure direct object reference
  • Information leakage
  • Insufficient anti-automation.
Marc Vael, Director of the Knowledge Board and Chairman of the Cloud Computing Task Force at ISACA said: “Organizations are performing more and more high-value or highly confidential transactions through the internet thanks to the insight in the many new opportunities and benefits. But in many cases we notice that executive management is not (made) fully aware of the real security risks.”

Vael continued: “On the contrary, managers tend to push hard to go ahead and launch the web solution(s), even when these are not properly tested. Thus a lot of assumptions and a false sense of trust reigns in many organizations on the security of their web applications, until it is too late.”

The free white paper is available here (registration required).






Spotlight

A closer look at Mega cloud storage

Posted on 21 May 2013.  |  Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Wed, May 22nd
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //