Web‐Based Vulnerabilities

Anup K. Ghosh, Kurt Baumgarten, Jennifer Hadley, Steven Lovaas · 2012

This chapter reviews the primary software components that make up Web applications, with a primary focus on e-commerce. It provides an overview of the risks to each of these components. The chapter discusses the weakest links in Web applications, including Web clients, network protocols, front-end Web servers, back-end databases, application servers, and the platforms on which they run. It highlights that the most common vulnerability in e-commerce systems is misconfiguration of software. Because the responsibility for software configuration lies with the user, a security policy must be implemented and enforced. Once a system is configured, it is important to subject it to third-party validation and testing. A third-party audit can ensure that the configured system, including routers, firewalls, servers, and databases, meets the specifications of the security policy. The system also should be tested periodically against well-known, common attacks as well as against newer threats as they arise.

Read the paper · More papers on PaperTik