Web applications open to hack attacks

Resulting 'serious flaws' leave 97 per cent of sites open to abuse

Written by Emma Nash

Only three per cent of web-based applications are secure enough to resist hackers, according to research.

Tests conducted on behalf of application testing specialist Sim Group show that 97 per cent of websites have 'serious security flaws', leaving data and systems open to abuse.

If the situation continues, trust in online services could be damaged, deterring already nervous consumers from buying online.

Businesses must test web-based applications for security flaws with the same stringency they apply to hardware and networks, warned Sim Group managing director Bob Bartlett.

"This figure doesn't surprise me, and it's probably something to do with head-in-the-sand syndrome," he said.

"People that have a website and are putting any volume through it are looking at it and thinking: 'Maybe there's a bit of fraud going on, but not to worry because I'm still making a profit'. People are ignoring the problem."

Tests of 300 web applications were undertaken by web security specialist Sanctum. Of the 97 per cent of serious security flaws identified, almost 40 per cent would allow malicious intruders to gain full control of information.

About 23 per cent of flaws constituted a privacy breach, while 21 per cent would allow electronic shoplifting.

About five per cent of the flaws would allow intruders to modify information, and a further five per cent allowed malicious users to hijack transactions.

Some two per cent of the holes were so serious the websites could have been deleted.

Bartlett said that more use of penetration testing would help to dispel consumer fears.

"The more testing you do, the more trust you have in the thing you are using. You are then communicating that trust to your customer," he added.

Tags:

Further reading

Hackers bigger threat than rogue staff

Survey of financial firms finds 90 per cent of security breaches come from outside   More...

Related articles

vnunet.com comment: Bill Gates powers down

A reflection on the highs and lows of Gates's Microsoft   More...

UK government guilty of DPA breach

Website farce exposes details of 50,000 applicants   More...

Hackers 'seeding' legitimate websites

SQL injection attacks colonising big name sites   More...

Check Point puts ForceField around browsers

ZoneAlarm plays in the sandbox   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

21 Jul 2008

3.12 MBGlobal internet reach, online spending and the space race More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Security

Major DNS flaw revealed

Experts sound alarms over early disclosure   More...

Nintendo DS

Dodgy Chinese Nintendo chargers recalled

Experience could shock some users   More...

Advertisement

Houses of Parliament

Official 'spying' requests top 500,000

Information includes web records and itemised phone bills   More...

Hacking

Small firms naïve about security

SMBs remain prone to attack, says study   More...

Advertisement