articleandcontent.com articleandcontent.com
Site Home About Us Security & Privacy ToS Place Your Link Submit Article
Search:   
Add Url
 

Art & Creative

Online & Indoor Games

Fashion & Relationships

Research & Science

Automobiles

Computers & Software

News & Media

Shopping & Auction

Government & Politics

Healthcare & Treatment

Business & Services

Sports

People & Society

Recreation & Entertainment

Hygiene & Health

Teens & Children

Family & Home

Self Enhancement

Property & Agents

Education & Learning

Tour & Travel

Banking & Finance

Jobs & Employment

Drink & Food

 

Site Home › Computers & Software › Security & Firewalls
 

5 Threats that make your Website Vulnerable, Part 2: Web Protocols are not Secure

 
Author: Richard Touret

Over 50% of all new vulnerabilities being identified on a weekly basis are attributed to web applications (SANS @RISK, The Consensus Security Vulnerability Alert)
More than 80% of all malware that emerged in the past year focus on application-level vulnerabilities (various sources, 2006).
In June 2006, 92 SQL injection and 34 cross-site scripting (XSS) new vulnerabilities were recorded on our database (Secunia)


The rationale behind HTTP protocol is to favor easy, quick and light communication and inter-connection. It has been designed to extensively share information, without really addressing security aspects. Indeed, these were considered as a constraint, supposed to slow traffic down and restrain freedom. As Jon Postel states (a key contributor of internet Requests For Comments) in his Law be conservative in what you do, be liberal in what you accept from others (Sept. 1981).
Very well known security principles are confidentiality, availability, integrity and auditability (ability to answer key questions such as who, what, when, where, to whom). HTTP protocol gives poor result on these aspects. HTTPS improves confidentiality aspects during transit but if initial traffic was malicious, web server will receive and process malicious SSL traffic ! Web protocols hardly authenticate, only partly guarantee confidentiality and integrity, do not protect against spoofing
Keep in mind that an URL sent by a browser is a command line to your web server : for instance an URL generating an SQL command or activating a CGI script.
At last, web protocols do not impose input validation, this is the major cause of their insecurity !
A solution is needed as web architectures are increasingly adopted in core IT systems !

The third article is about coding secure web sites

Richard Touret is manager at Binarysec, http://www.binarysec.com , security software company editing an intelligent web application softwall -or software firewall-. This Apache module adapts on most web sites, learning legitimate traffic to block any malicious request, including sql injection, cross-site scripting, directory traversal, forceful browsing, command injection, parameter tampering, attack obfuscation, buffer overflow...

Author Bio:
Richard Touret is an expert on this subject. Richard has written several articles in the past on this topic.
You can search for this article using: network security, firewalls, computer network security, network security software, free firewalls
 
 
 

Related Articles

 
World Cup ?06: I?d Like to Teach the World to Blog
 
Anatomy of a Website
 
Self Publishers: High Earners Make A Significant Part of Their Income From Affiliate Programs
 
Don't Want Spam with Your Online News and Info..?
 
E-Cheques and Online Commerce
 
Triple Your Sales By Turning Objections and Flaws Into Powerful Benefits!
 
How to Choose a Web Hosting Company
 
Origami Software Visualization Tools
 
Free Traffic Generator information
 
Your Blue Print For A Successful Web Site
 
 
 
 

How to Get Indexed by Google and Alexa; aka How to Get Ranked by Google and Alexa

I am so tired of waiting for 3 to 4 weeks for my website to be ranked and indexed by google and alex ... - Roger Stanton
 

Your 3 Best Options for Quickly Multiplying Your Website's Income

Why is it that so few websites earn anywhere near their true potential for their owners? Lack of tig ... - Rockford Tapscott
 

Freelance Writing: Write An Article A Day To Boost Your Career

Want to boost your freelance writing career to a whole new level? You can, with the "article a day" ... - Angela Booth
 
 

3 Steps To Getting Hundreds Of Backlinks To Your Website Absolutely Free

This article explains 3 simple steps to getting hundreds of backlinks to your website absolutely FRE ... - Cory Threlfall
 

What is SCM or Supply Chain Management?

Supply Chain Management is popularly known as SCM also. Supply Chain Management solution also know a ... - Yogesh Ahire
 

Effective Communication for Webmasters

The primary aim of your website is to communicate. In order for webmasters to convey their thoughts ... - Gene DeFazzio
 

The Clickbank Profit Machine -- See Sales Streaming in Within 24 Hours

The Clickbank Profit Machine is an ebook whose tagline is typically seductive -- "See sales streamin ... - Michael Stimpson
 

Types of Keyboards

Types of keyboards - pros and cons - reviews and facts. - Logan Rokwild
 
 
Site Home -> Security & Privacy -> ToS  
© 2006-2008 www.articleandcontent.com All Rights Reserved Worldwide.