Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Controlling Spyware: Tips and Techniques | Main | Googling for Vulnerabilities »

Usual Suspects Top List of Website Vulnerabilities

A new report on Web site vulnerabilities claims 9 out of 10 sites have critical vulnerabilities with 7 out of 10 vulnerable to Cross-Site Scripting (XSS). Other top vulnerabilities include information leaks, content spoofing, SQL injection, insufficient authentication and insufficient authorization. (See Web Developers Guide to Preventing Cross Site Scripting Attacks in the Web Security Digital Library for more on CSS as well as articles on preventing SQL Injection and Web Portal security.)

There are a couple of unexpected findings, though.

The WhiteHat Website Security Statistics Report found that Cross-Site Request Forgery (CSRF) had not made it to the top 10 yet. Given that there are not well established and effective techniques for dealing with this it is a welcome surprise to see it is not a top problem yet. On the down side, the researchers expect the use of this vulnerability to grow; eWeek reports:

The company expects CSRF eventually to land in the No. 2 spot, right behind XSS.

The other surprising finding is that retail is a top performing vertical but, as the WhiteHat press release says, others are not doing so well:

Verticals not faring as well include Insurance, which tops the list with 84 percent of websites having vulnerabilities that fall into the urgent, critical or high severity ranking, followed closely by Information Technology at 72 percent, and Healthcare and Financial Services neck-and-neck at 64 and 60 percent respectively

It's not clear what types of vulnerabilities are plaguing the healthcare and financial services - information leaks would be the most troubling.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/683

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net