Web 2.0 services (vulnerability, threats and protection measures)

Jasmin Ćosić · 2009

Normal 0 21 false false false MicrosoftInternetExplorer4 st1\:*{behavior:url(#ieooui) } /* Style Definitions */ table.MsoNormalTable {mso-style-name:Table Normal; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:; mso-padding-alt:0cm 5.4pt 0cm 5.4pt; mso-para-margin:0cm; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:Times New Roman; mso-fareast-font-family:Times New Roman; mso-ansi-language:#0400; mso-fareast-language:#0400; mso-bidi-language:#0400;} Web 2.0 services, vulnerability, threats and protection measures (CECIIS 2009) Jasmin ?osi? Faculty of Organization and Informatics University of Zagreb Pavlinska 2, 42000 Varaždin, Croatia [email protected] Author(s) Name(s) Author Affiliation(s) Department/Institute Full Address(es) E-mail(s) Abstract . Every 15 seconds a new malicious webpage (page with malwares) is discovered in the world, and up to 85% of those pages are regular and legitimate whose owners have no idea that their page was hacked and that the hackers embedded „malwaresinto those pages. Studies have shown that the cause of the problems are new web technologies (less is attributed to vulnerability of web servers and browsers; mostly to web applications) also failures of programmers and designers, administrators of sites, where these applications are hosted, and the web users. In this article I will attempt to give a cross-sectional view of this field and point at the most vulnerable parts at the web 2.0 services in 2007 and in 2008. I will also try to give certain recommendations and guidelines for what needs to be paid special attention to during the IS development phases; and also how one can protect the final users, what the managers can do, what designers of application can do, as well as the administrators of the system on which the servers spin to make hackers' job harder. Keywords . Web 2.0,Security,Vulnerability,Web application,Hackers

Read the paper · More papers on PaperTik