Web applications fail security tests

'Serious flaws' leave 97 per cent of sites open to abuse

Written by Emma Nash

Only three per cent of web-based applications are secure enough to resist hackers, according to new research.

Tests conducted on behalf of application testing specialist the Sim Group showed that 97 per cent of web sites have 'serious security flaws', leaving data and systems open to abuse.

If the situation continues, trust in online services could be seriously damaged, deterring already nervous consumers from buying online.

Businesses must test web-based applications for security flaws with the same stringency they apply to hardware and networks, says Sim Group managing director Bob Bartlett.

'This figure doesn't surprise me, and it's probably something to do with head in the sand syndrome,' he said.

'People that have a web site and are putting any volume through it, are looking at it and thinking, "maybe there's a bit of fraud going on, but not to worry because I'm still making a profit". People are ignoring the problem,' he said.

Tests of 300 web applications were undertaken by web security specialist Sanctum. Of the 97 per cent of serious security flaws identified, almost 40 per cent would allow malicious intruders to gain full control and access to information.

Around 23 per cent of flaws constituted a privacy breach, while 21 per cent would allow electronic shoplifting.

About five per cent of the flaws would allow intruders to modify information, and a further five per cent allowed malicious users to hijack transactions. Around two per cent of the holes were so serious the web sites could have been deleted.

Bartlett says that more use of penetration testing would help to dispel consumer fears.

'There's no doubt that testing does increase trust,' Bartlett said. 'The more testing you do, the more trust you have in the thing you are using. You are then communicating that trust to your customer.'

Tags:

reader comments

related articles

A Question of Trust

A Question Of Trust

Computing's special report looks at the role of security in the future of e-commerce. 30 Jan 2004

 

Watchdog slams Skipton over data loss

Loss of 14,000 customer records breached Data Protection Act 21 Feb 2008

McKinnon supporters appeal to Home Office

Hacker's lawyers turn to Home Secretary to stop extradition 02 Sep 2008

vnunet.com comment: Bill Gates powers down

A reflection on the highs and lows of Gates's Microsoft 28 Jun 2008

related whitepapers

today's top stories

IT's stock is soaring at the LSE

London Stock Exchange IT chief David Lester explains to Angelica Mari how the integration of Borsa Italiana is keeping his team busy, despite the worsening economy 20 Nov 2008

Keeping IT in fashion

John Bovill has been hooked on retail since his early years as a fashion market trader. His industry knowledge is now helping him build a slick IT operation, reports Charlotte Moore 20 Nov 2008

Cutting-edge IT delivers the goods

Chief technology officer Jay Bregman explains how constant innovation is part and parcel of his strategy for delivering competitive advantage at eCourier 20 Nov 2008

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Keeping IT on track

Catherine Doran, winner of Computing’s IT Leader of the Year award, tells Angelica Mari of her determination to drive on with technology-led transformation at Network Rail despite uncertainty over funding 19 Nov 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will attempts to rebrand IT as a "cool" choice of profession increase the number of IT graduates?

Will attempts to rebrand IT as a "cool" choice of profession increase the number of IT graduates?

Can brand building reverse a decline in IT graduate numbers?

Previous poll results

Latest audio and video articles

Video

The definitive guide to converged communications

Five key trends and five best practice tips to help you improve your corporate communications 20 Nov 2008

PodcastAudio

Computing podcast: Europol's data sharing woes; credit card protection at Cotton Traders

The pan-European fight against organised crime is undermined by lax data sharing arrangements; and Cotton Traders enhances its credit card protection 20 Nov 2008

Latest in-depth articles

StarFeatures

Retaining the stars of IT

Jim Mortleman investigates the innovative techniques IT leaders are using to hang on to their star performers 20 Nov 2008

Dave BaileyComment

Clouds darken outlook for Vista's successor

Windows 7 looks like being an improvement on Vista, but economic and environmental concerns may mean few enterprises will rush to adopt it 20 Nov 2008

Advertisement

Primary Navigation