Web-based attacks can take many forms, with effects ranging from mild inconvenience when a Web site no longer loads properly (such as the recent redirection of Barack Obama's Web site to Hillary Clinton's) to complete compromise of the user's system.
Recent attention has been focussed on the use of SQL injection, where database commands are able to be inserted into the site, and the terrible effects that such attacks have had recently.
Cross Site Scripting (XSS), and Cross Site Request Forging (CSRF) vulnerabilities have been considered by many as more distraction than vulnerability type, a problem which hasn't been helped when there is still some confusion about how some published vulnerability examples can be classed.
Most examples of XSS or CSRF vulnerabilities have been to steal authentication details from cookies set by various sites such as eBay, banking sites and webmail providers, or to temporarily replace Web site content for users when they follow a crafted link.
The problem that these attacks can have is that many of them take place in the user's browser, and not necessarily on the site. The impermanence of any attack makes it hard to tell when there is a problem and when there is something that needs to be done by the site developers.
There are teams of researchers working towards understanding more about XSS and CSRF problems, including those who are working to demonstrate cases where permanent effects can result from following a simple hyperlink.
The team at GNUCitizen are one of the leading groups to be looking at these problems and have already demonstrated a number of examples where a combination of the above vulnerability types can lead to the compromise of a common family of routers used by home broadband users in the United Kingdom.
More recently, there has been a case published where vulnerabilities in the uTorrent BitTorrent client can be leveraged and exploited through CSRF vulnerabilities, resulting in the eventual compromise of a victim's system. Users of the uTorrent client should update to the latest version and apply care from where they obtain their .torrent files.
If a number of these vulnerabilities look simplistic, it is because often they are.
The main problem for developers is in understanding how a feature or part of a site may be unintentionally exposed for manipulation, and then using secure development practices to implement their site. It has taken many years of major vulnerabilities and problematic exploits for the concepts of secure development and secure development practices to start spreading through the desktop and network application developer community.
Increasing reports and cases of online vulnerabilities should be a sign to online developers that they are going to have to apply the same sort of principles to their own work if they want it to withstand the online environment.
These problems are going to become of greater importance in the future as more devices and technologies are created to have a web interface for management, even if the user is unaware that such an interface exists. The Open Web Application Security Project (OWASP) has one of the best sets of online resources for finding out more about web based vulnerabilities and is comprised of many of the best minds currently working in this particular field of Information Security.
Computerworld Member Login
Beyond Virtualisation - The Roadmap to 2012
CIO Breakfast Briefing
8:30am - 10:30am
Brisbane | 22 July | Sofitel Brisbane
Sydney | 23 July | Four Seasons Hotel
Canberra | 24 July | The Hyatt
Attend and discover:
- What happens after virtualisation
- The benefits automation drives
- When automated infrastructures will emerge
- What the roadmap to 2012 looks like
- How to deliver an automated architecture
- How to maximise your investment in virtualisation
- +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future. - +
Data Management Edition #9: Data centre makeover 24/04/2008 07:43:06
This week CW Live looks at the death of the old style data centre which is undergoing its first makeover in more than 30 years.
Zepto release the Mythos, the 2nd installment in the Centrino 2 refresh 2008-07-09 12:05:00+10
Symantec Data Protection Solutions Preferred by Users and Industry Experts 2008-07-09 11:56:00+10
Residential VoIP: Let’s Get Naked, Declares IDC 2008-07-09 10:43:00+10
Frost & Sullivan: Australia’s Mobile Advertising Spend to Grow 300 Per Cent in 2008 2008-07-09 07:57:00+10
DIARY ALERT - Symantec data leakage prevention seminars 2008-07-08 17:20:00+10
Extending Business Solutions across the Organisation
It is difficult for companies to overcome business challenges when employees are not connected to their business management solution. Discover Microsoft Dynamics Client for Microsoft® Office and SharePoint® Server and connect Microsoft Dynamics more closely with personal productivity solutions and much more.








