Web Security for emerging web-application threats

15 March 2010
Web 2.0 is thriving, and so too are applications that take advantage of this technology. Interactive sites like LinkedIn, Twitter and even company websites are becoming ever more popular, and yet, many IT departments are unprepared for today’s emerging threats. As more companies take to the web to conduct business, the opportunity for attack is increased and organisations need to re-adjust security practices for the Web 2.0 world.

Traditionally, potential security breaches, or vulnerabilities, target personal and business information that is created and stored in certain Web 2.0 applications, such as Google Docs and Mobile Me. Using JavaScript programmes developed to capture data, hackers can redirect users to a perfect copy of the site they’re expecting to see. When log-in details are entered, they’re unknowingly sent to the attacker, providing them with information they need to access sensitive business information.

New attack methods are constantly being employed by hackers, taking advantage of technologies that are already in place. Attackers continuously try to bypass security systems in place on sites such as Facebook, and gain access to information using the code that is running on the browser through the third-party.

There is a difference in the way attackers operate; some choose to exploit web applications, like Twitter, while others choose to exploit the web browser. Here hackers pepper large numbers of websites with JavaScript which enables them to collect data on visitors to targeted sites. Rather than specific web applications being targeted, the browser instead acts as the delivery mechanism, where links can be used to either redirect users to other ‘fake’ sites, or load damaging content.

In early web attacks, it was all about site defacement where content would be edited, with messages being incorporated or offensive images being added. This has changed and the emphasis is on remaining undetected so that site owners will not know that security has been compromised. JavaScript enables hackers to use these attacks for financial gain instead of to just be a nuisance.

Many people associate hacking with credit-card and bank fraud – but this is not the case. ID theft is not just about being able to spend somebody else’s money; it can be used to set-up credit accounts with business suppliers or open-up new premises, all at another’s expense.

Whilst hackers are constantly evolving and adapting to new technologies, businesses are responding just as well. Employees, as well as IT departments, are now aware of security risks and most companies have IT security policies in place. Patches, security alerts and updates are now issued regularly from vendors and should be monitored and downloaded when available.

In addition, there are a number of tools which can help prevent attacks – web application scanning in particular. This is an automated process which searches for software vulnerabilities in websites by launching its own attacks and analysing the results.

Technology continues to advance at an alarming rate – and with it those people who are willing to exploit others for financial gain. By staying informed of potential risks and combining the tried and tested preventative methodologies, IT departments can ensure they are well-equipped to deal with the constant threat of Web 2.0 attacks.

Qualys Technologies is exhibiting at Infosecurity Europe 2010, on 27th – 29th April, Earl’s Court, London, www.infosec.co.uk.

 

Latest bank and financial services security articles

 Misconfigured networks are the easiest IT resource hackers exploit

 The Return of Ransomware and Do-it-Yourself Botnets

 OmniPerception facial biometric technology can accurately identify a face without the person having to look directly into the camera

 Data protection laws are too relaxed and require revision

 Zeus financial malware targets online banking customers by exploiting Verified by Visa and MasterCard SecureCode security programs

 MITec, FAC and Ukash provide a fully integrated and secure alternative cash payments solution in Mexico

 Imperva's data security suite helps enterprises protect not only web applications and databases but file systems as well

 NVT's integrated hybrid CCTV and alarm system protects Banco de Costa Rica

 Mykonos security appliance stops IT security attacks before the damage is done

 35 percent of companies believe their Intellectual Property has been handed over to competitors

...[view more articles on bank and financial services security]...

 

Other security websites:

Bank and Finance security links

Kabul Bank Security Tight as Afghan Finance Chiefs Plan Response Armed security officers guarded Kabul Bank’s headquarters as finance officials prepared to outline steps to restore confidence in Afghanistan’s biggest private lender after reports of losses triggered withdrawals.

Security guard killed at Ingles identified Security guard killed at Ingles identified

Bank Rakyat expands Ar-Rahnu Xchanges BANK Rakyat is expanding the Ar-Rahnu Islamic pawnbroking by setting up Ar-Rahnu Xchanges at all 124 branches nationwide, says managing director Datuk Kamaruzaman Che Mat. So far, 20 Ar-Rahnu Xchanges are in operation, including 17 operated by the bank itself and three under franchise, he said. Three more Ar-Rahnu Xchanges under franchise will be run by the Wawasan Co-operative in Bandar Sunway ...

Deutsche Bank Names RBS's Kaur as Global Group Audit Head to Succeed Giles Deutsche Bank AG , Germany’s biggest bank, named Royal Bank of Scotland Group Plc’s Pam Kaur global head of group audit to succeed Andrew Giles, who will retire.

Pressure is on Palestinians' West Bank security force to stem anti-settler violence Palestinian security forces, reformed and retrained, have made a strong show of force, arresting hundreds of suspects. But human rights groups accuse them of detaining people without proper cause. Recent Palestinian attacks on West Bank settlers, which are likely to increase in response to relaunched peace talks, pose one of the biggest challenges yet to U.S.-trained Palestinian security forces ...

Security stepped up at Kabul Bank Armed police are posted outside the main branch of Kabul Bank as customers continue to withdraw money amid fears it may collapse.

Bank Muamalat Q1 net profit jumps to RM33.4m BANK Muamalat Malaysia Bhd's net profit more than doubled to RM33.4 million in the first quarter ended June 30 2010 on higher operating income and improved asset quality. The bank's pre-tax profit for the three months rose 117 per cent to RM44.8 million from RM20.7 million in the previous corresponding period. Bank Muamalat's net provisions narrowed considerably to RM16.6 million, a drop of 69 ...

directory of bank and financial security suppliers
Search directory Register your company
Bank Security books:

SEARCH NEWS
DIRECTORY
Google