Advertisement
Promo

Online business Toolkit

Report details common Web flaws

Published: 14 Jan 2003 17:29 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A group of security experts on Monday released a list of Web site flaws that it believes are the primary culprits in undermining the security of online applications.

In a 23-page report, the Open Web Applications Security Project said that the OWASP Top Ten is intended to help developers and corporate security administrators close the holes that allow attackers into many companies.

"When an organisation puts up a Web application, they invite the world to send them HTTP requests," the report said. "Attacks buried in those requests sail past firewalls, filters, platform hardening, and intrusion detection systems without notice because they are inside legal HTTP requests."

Web sites that send information to other applications, such as a database or e-commerce server, inside the company's network should be analysed for the 10 security problems as soon as possible, according to the report.

The top vulnerability: Sites that don't validate information before sending it to another server. Attackers can use such a flaw to send malicious code designed to compromise back-end applications through the Web server.

Another major problem, the report said, is a failure to enforce restrictions on user activity. Many attackers log on as one user and then find ways of accessing the data of other users on the system.

Other major issues include cross-site scripting, buffer overflows and remote administration flaws.

"This list is an important development for consumers and vendors alike," Stephen Christey, principal information security engineer for the MITRE Group, a nonprofit system engineering contractor, said in a statement. "It will educate vendors to avoid the same mistakes that have been repeated countless times in other Web applications."

Christey added that the list gives consumers a set of requirements to which they could hold software makers accountable.

The OWASP list resembles a set of 20 flaws released by the SysAdmin, Audit, Networking and Security (SANS) Institute and the FBI every year.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Security News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
38 out of 88 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters