A Guide to Discovering Web Application Insecurities, Before Attackers Do
Don J. Williams · 2005
It is all over the news: web based attacks are climbing, month over month, year over year. At the same time companies are attempting to combat such attacks, attackers are devising new methods to infiltrate systems. In the event you were on a reality show for the last few years and missed the latest news, just take a glance at these alarming statistics: “By exploiting a vulnerability in Microsoft's IIS web server product, over • 250,000 web sites are thought to have been compromised by the ’Code Red’ worm, in the course of a 9 hour period.” (Danyliw) “When asked what types of losses their organizations experienced last • year, over half of respondents (56%) report operational losses, 25% state financial loss and 12% declare other types of losses.” (CERT) “In 1998, 50% of those surveyed reported no attack-related downtime • whereas this year (2004), only 6% make such a claim.” (Hume. p.54) “Nearly half of the fastest-growing U.S. companies have suffered security • breaches, but most still aren't prepared to dedicate enough resources to address the problem, according to a study by PricewaterhouseCoopers.” (PWC) Web based attacks require attention today, and the consequences can be devastating for businesses who fail to take information security seriously. To protect against an attacker, you have to think defense. Truly defensive postures can always beat out offense. For purposes of discussion, this paper will focus on discovery techniques companies can employ to uncover insecurities in web-based applications and system infrastructure. The following will provide valuable information on tools to determine if vulnerabilities are present and techniques application owners can deploy to mitigate potential attacks. While many of the tools showcased allow for multiple hosts to be assessed, this paper will demonstrate techniques based on a single host (application).