The need for stronger web application security was once again highlighted
today by the release of new research that found 90 percent of firms' web sites
contain vulnerabilities that could allow external users to disrupt web services
or allow unauthorised access.
The Web Application Security Report 2007, by IT security consultancy
NTA Monitor, also found that virtually
all organisations tested had at least one low-risk issue that could provide
attackers with information such as web server software type and make.
The research is the result of a year's work of testing with the firm's
customers, according to NTA marketing manager Sarah Turner.
"The implications of these vulnerabilities will vary in criticality depending
on the organisations and the type of sites they have," Turner added. "But some
of our customers are banks and charities. If you're dealing with bank account
details and credit card data [web app] security should be a high priority."
To improve their web application security, the report recommends that firms
ensure their web servers are always up to date with patches.
It also advises that organisations make users use their mouse and keyboard
when logging in, to mitigate the threat from keyloggers, and implement account
lockout mechanisms after a limited number of failed attempts, in order to avoid
“brute force” attacks on accounts.
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Affiliate & Media marketing manager - Welwyn Garden CityWho's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales ... more >
Web/Project Manager - £33,118 to £35,694 + Benefits Cutting-edge research is our business. You'll give us the cutting-edge web technologies to match. The Economic and Social Research Council is the UK's leading research agency for ... more >
Business Analyst - £30,000 - £35,000 - Solihull We are in need of a Business Analyst with strong analytical skills and a penchant for learning the domain knowledge of the Utilities sector (Gas industry in ... more >
Are you stuck in a dead end job? Do you want to take control of your salary, life and career? Advent IT and computer training offers advanced, professional training and helps you find the right ... more >More job opportunities