Sans Institute advises on internet risks

15 Nov 2006

Be the first to comment

A Computing logo
security logo

Data breaches through web application vulnerabilities remain a major threat to firms, according to the latest report from IT security training organisation Sans Institute.

Attacks are now numbering 400,000 to 500,000 in one day, many targeted at web hosting providers, according to report editor Rohit Dhamankar of intrusion-prevention specialist TippingPoint.

Further reading

"Often people are in a hurry to create a custom app that has a lot of functionality, because PHP is a good tool, but it will be riddled with problems, " he explained, citing the rise in popularity of web scripting languages such as PHP and Perl. "A lot of the attacks are zero-day, although they don't get the same publicity as those on Microsoft products, and at the web apps' back-end is often stored [sensitive] data."

Dhamankar said firms should consider creating hardened environments for running these applications, and developers could take steps to engineer-in greater security from the start.

The report also highlighted rapid growth in attacks, specifically zero-day attacks, on Microsoft applications that have hitherto been thought of as reliable, such as PowerPoint, Word and Excel.

Reader comments

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

  • Digg
  • Tweet

Newsletters

Sign up for our FREE newsletters

Technology Patent Wars

Large companies such as Microsoft, Facebook and Google have been hoovering up technology patents recently. Is this stifling innovation?

88 %

5 %

7 %