security.itworld.com
  Search  
Security Home Page Security Webcasts Security White Papers Security Newsletters Security News Security Topics Careers ITworld Voices ITwhirled The Security site of ITworld.com

Web application security audits

ITworld.com 09/21/2006

James Gaskin, ITworld.com

Listen to the column "Web Application Security Audits", or visit our Podcast Center to hear more by James Gaskin.

There are four Web vulnerability tool companies, and one, Acunetix (.com) now offers a free audit through a download on their Web site. Through this service, they have gathered plenty of information about the state of Web development security even though they've been a commercial product for less than a year.

On this topic

Good news? Off the shelf applications do have holes, but they get patched by the vendor. Bad news? Custom applications don't get patched, and the typical mix of in-house and third party developer teams means programming best practices remains a slogan on a poster. About two thirds of the free audits run by the Acunetix utility report high vulnerability on the tested Web application.

If you're doing e-commerce and take customer credit cards, the newspaper headlines await your first misstep. No longer are hackers looking for defacement glory; they now look for revenue by ripping off you and your customers.

If management balks at paying for another security service, point out where you already have security: firewalls, desktops, mobile devices, routers, and authentication. Leaving your Web applications insecure makes no more sense than building a brick wall but using a gate made from chain link fencing. Isn't your Web site the public face of your company, receiving thousands of hits per day? Shouldn't that be as secure as possible?

If you're not a programmer, Cross Site Scripting and SQL Injection may not mean much to you. Ask your Webmaster, however, and you'll get a different response. Just make sure he or she isn't eating, or you may have to do the Heimlich maneuver.

Every dynamic object on your Web site must be checked for vulnerabilities. This not only includes shopping carts but forms and any other interactive application.

Don't forget your supply chain. Any extranet interfaces provided to suppliers or customers must be verified. If you don't really trust your own employees, how can you trust the employees in another company? Of course, if you're in security, you've learned not to trust anyone.

If you're a history fan, you can remember back to President Reagan talking about a treaty with the Soviet Union. He promised to trust but verify. Sounds like a good approach to your Web site security as well.

James E. Gaskin writes books (16 so far), articles and jokes about technology and real life from his home office in the Dallas area. Gaskin has been helping small and medium sized businesses use technology intelligently since 1986. Write him at readers@gaskin.com.




Sponsored Links

Closing the Gap Between Patient and Caregiver
Optical network solutions from AT&T provide scalable, secure bandwidth to keep the health care provider and the patient connected, despite increasing network traffic.
FREE virus, spyware & adware scan
Find the malware your AV missed with the Sophos Threat Detection Test.
Web Penetration & App Testing
Web Penetration Security Services. 300+ Clients. Free, Quick Quotes!
See how EASY REMOTE SUPPORT can be. Try WebEx FREE!
DELIVER SUPPORT MORE EFFICIENTLY. Remotely Control Applications. Leap Securely through Firewalls!
TAKE CONTROL OF REMOTE COMPUTERS
Support, configure and install applications and updates remotely for greater efficiency.
» Buy a link now

Advertisements
Sponsored links
Top 5 Reasons to Combine App Performance and Security
KODAK i1400 Series Scanners stand up to the challenge
Bring harmony to your mix of UNIX-Linux-Windows computing environments
Locate Hidden Software on business PCs with this free tool
 Home   Defensive measures  Tactical
www.itworld.com    open.itworld.com     security.itworld.com     smallbusiness.itworld.com
storage.itworld.com     utilitycomputing.itworld.com     wireless.itworld.com

 
Contact Us   About Us   Privacy Policy    Terms of Service   Reprints  

CIO   Computerworld   CSO   GamePro   Games.net   IDG Connect   IDG World Expo   Infoworld   ITworld   JavaWorld   LinuxWorld  MacUser   Macworld   Network World   PC World   Playlist  

Copyright © Computerworld, Inc. All rights reserved

Reproduction in whole or in part in any form or medium without express written permission of Computerworld Inc. is prohibited. Computerworld and Computerworld.com and the respective logos are trademarks of International Data Group Inc.