Showing posts with label web server security. Show all posts
Showing posts with label web server security. Show all posts

Wednesday, October 03, 2012

An approach for Website Security Testing

Any businesses where the more important data is stored in the web application or lot of transactions are involved over the web, hackers turn ey to it. To make sure that the confidential data remains confidential, with getting exposed to online criminals, it is very much essential to make sure the web tests are carried out in a periodic basis. Website Security Testing plays a vital role in ensuring, that your web data and application is secure and confidential.

Below are few important functional testing invovled in web application security testing.

1. Vulnerability Check - checking for any security holes ie. weaknesses in the web application.

2. URL Manipulation - unintended behavior in the web server leading to unintended manipulation of urls.

3. SQL Injection - commonly used for website hacking

4. XSS (Cross Site Scripting)

5. Spoofing - Genarally a Hoax website / Email is created to look alike like a genuine website or a existing leading brand

Any websites that carries out financial transactions it is a must to secure their website with a period website security testing and penetration testing, to ensure that thier web server is secure.

Monday, August 09, 2010

Web Server Security

Operating Systems still continue to be vulnerable to attacks if the security patches are not installed periodically, which gives way to malwares and massive internet worms. Sometime ago, the internet worm conficker, which is also known as downadup was creating big chaos over the internet, which lead to huge losses to the corporate and website owners. Meanwhile there was also number of buffer overflow attacks reported during the year 2009. It’s quite common that all the web servers do have vulnerability, but its good the website owner need to safeguard their valuable digital assets by periodically updating the security patches and by running quality server security software products, which would prevent from the web server being vulnerable i.e. accessible to the hackers.



Below are a few one-liner precautionary steps that will help you in securing your Web server.
1. Install the Security Patches whenever available
2. Check the client side of the website by running a Malware Scan to ensure the users are safe
3. Disable the unnecessary scripting languages in your web servers, as hacker may target them
4. Subscribe and Keep monitoring the security vendor's security alerts
5. Most importantly use a tough Alpha-numeric-Symbol based password
6. Check for vulnerabilities by running a vulnerability analyser to check your web server security holes
7. Set up permissions at different levels so that no one can access as an administrator, expect the person intended for.
8. DON'T test any new or unknown scripts in your main web server, because some untrusted scripts may inject a malware in your server

Also, now Google provides a free tool called "SkipFish" - a web application security reconnaissance tool, which can run a security audit to your website. Here is the link for your convenience http://code.google.com/p/skipfish/
Still wondering how the attack takes place, here is a pictorial representation of Top Cyber Security Risks by Sans.org http://www.sans.org/top-cyber-security-risks/tutorial.php

Is taking a Bank Loan Good or Bad?

Definitely taking a bank loan shouldn't be a choice for you and should be the last resource if you need to. You may be wondering, why am...