openPR Logo
Press release

Cross-Site Scripting ranks first in top security risks

09-20-2006 12:04 PM CET | IT, New Media & Software

Press release from: Acunetix Ltd

Acunetix calls for regular website auditing to guard against attackers’ new preferred flaw

London, UK – 19 September, 2006 – In recent years, buffer overflows topped the list as the most popular vulnerability used by hackers to compromise websites. However, the latest report from Mitre Corp., a US government funded research organization, clearly indicates that hackers are moving away from acts of vandalism to the more lucrative exploits of data theft. In fact, Cross-Site scripting and SQL Injection are now the most preferred hacking techniques used by hackers since these vulnerabilities allow access to such data as credit card details.

The Common Vulnerabilities and Exposures (CVE) project by Mitre, reported that out of the 4375 security issues catalogued in the first nine months of 2006, web-related flaws have captured the top three spots: 21.5 percent of the CVEs were cross-site scripting (XSS) vulnerabilities; 14 percent SQL Injection and 9.5 percent php “includes”. Buffer overflows came fourth, at 7.9 percent.

The increasing popularity of XSS bugs indicates that attackers are concentrating more on programming languages typically used for Web applications, such as Java, .Net and PHP. Buffer overflows, on the other hand, affect executable files written in languages such a C.

Assessing the security of a website

This increase in Web-based flaws stems directly from the simplicity of exploiting such vulnerabilities as XSS, and the enormous number of web applications freely available. In general, websites with such web applications as shopping carts, forms, login pages and dynamic content are always a prime target for attack. This is because, web applications require open and direct access to backend databases to function properly. If improperly coded, these common applications become easy gateways to social security numbers, credit card details and even medical records.

About Acunetix Web Vulnerability Scanner

Acunetix Web Vulnerability Scanner ensures website security by automatically checking for SQL injection, Cross site scripting and other vulnerabilities. Furthermore, Acunetix protects against the embedding of Javascript malware in a web-page through its JavaScript Analyzer. Such protection secures all AJAX applications. Acunetix WVS also checks password strength on authentication pages and automatically audits shopping carts, forms, dynamic content and other web applications. As the scan is being completed, the software produces detailed reports that pinpoint where vulnerabilities exist.

Acunetix provides free audit to help companies determine the security of their websites

Enterprises who would like to have their website security checked can register for a free audit by visiting www.acunetix.com/security-audit. Participating enterprises will receive a summary audit report showing whether their website is secure or not. Summary reports will be delivered within five business days of submission.

All product and company names herein may be trademarks of their respective owners.

For more information:
Please email Tamara Borg: tamara@acunetix.com
Acunetix Ltd: Tel: (+44) 0845 6126712, Fax: (+44) 0845 6126716
URL: http://www.acunetix.com.

About Acunetix

Acunetix was founded to combat the alarming rise in web attacks. Its flagship product, Acunetix Web Vulnerability Scanner, is the result of several years of development by a team of highly experienced security developers. Acunetix is a privately held company with headquarters based in Europe (Malta), a US office in Seattle, Washington and an office in London, UK. For more information about Acunetix, visit: http://www.acunetix.com; http://www.acunetix.de.

This release was published on openPR.

Permanent link to this press release:

Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.

You can edit or delete your press release Cross-Site Scripting ranks first in top security risks here

News-ID: 11374 • Views:

More Releases from Acunetix Ltd

New WebsiteDefender Service Guards Your Website Against Malware and Hackers
New WebsiteDefender Service Guards Your Website Against Malware and Hackers
Acunetix Launches New Online Service that Scans Your Website for Malware, Vulnerabilities and Provides Automated Backup & Restore London, UK, June 5 2012 – Acunetix, a pioneer in web security and the developer of Acunetix Web Vulnerability Scanner, today announced the release of WebsiteDefender – an online security monitoring service which helps you secure your websites or blogs against malware and hacker activity. Cybercrime and web malware is on the
For the fourth time in a row, Acunetix Web Vulnerability Scanner Voted Windowsec …
February 23, 2011 – Leading Windows Security resource site, WindowSecurity.com, announced today that Acunetix Web Vulnerability Scanner was selected the winner in the Web Application Security category of the WindowSecurity.com Readers’ Choice Awards. “Our Readers’ Choice Awards give visitors to our site the opportunity to vote for the products they view as the very best in their respective category,” said Sean Buttigieg, WindowSecurity.com manager. “WindowSecurity.com users are specialists in their field
Acunetix Publishes PCI Compliance Guide
The paper aims to help companies meet impending PCI requirements London, UK – May 30, 2007 – Businesses that rely on payment by credit cards are required to comply with the PCI security standards by September 2007. Non compliance could result in loss of merchant account, severe fines and lawsuits. In view of these new regulations, Acunetix has published a PCI Compliance Guide to help companies understand the concept behind the
Hackers Steal 19,000 Personal Customer Details from AT&T Online Store
Acunetix calls for regular website auditing to guard against the loss of personal sensitive data through web vulnerabilities London, UK – 06 September, 2006 – Last weekend, hackers pilfered the personal data of nearly 19,000 DSL equipment customers through a vulnerability in AT&T’s online store. The affected site was shut down within hours of the attack being launched. In a statement, AT&T attributed the motive of the attack to a criminal

All 5 Releases


More Releases for Web

Web Development Company| Web Design and Development Services | Web Designing Com …
Web Design and Development Company a creative web design and Development Company specialized in HTML5 and Wordpress. We have designers and developers who have the expertise to blend in beauty with the best of the technology. We have 1000 of wordpress themes to fit every business type. If you have a website or looking to get a new one design which has the most sophisticated look and loaded with functionality, please feel
Web Development Company| Web Design and Development Services | Web Designing Com …
Web Design and Development Company is part of Ardor Technology Solutions an offshore PHP web development and multimedia company based in Chennai, India offering the best solutions at much affordable price. The service includes e-Commerce Development, Website Design, Website Development, Graphic Design, 3D Modelling /Animation/Texturing/Lighting, Mobile Apps’ and SEO. Web Design and Development Company have team of 25+ experienced IT professionals dedicated to deliver customize and open source technology business
Web development company Kolkata, Web Design Company India, ecommerce web develop …
Comval web is one of the best service provider company in india. We provide Website Development services and maintainance. software development, Website Designing, Logo Designing, Domain Registration, E-Marketing , Web Hosting,Bulk SMS, Website Development Company in India offers professional web services at reasonable price. Get customized website design, logo Flash design,Internet Marketing, Domain Registration, E-Marketing , Web Hosting .Bulk SMS at your doorstep. Comval web is one of the best
Kirk Communications’ Web Design Agency Delivers Fast Web Solutions
Portsmouth NH, November 20, 2011— Kirk Communications (http://www.kirkcommunications.com), has become a web design agency that has provided clients across all industries with innovative websites. By specializing in website design and development, Kirk’s web design agency is able to quickly deliver web solutions to clients faster than any other website design & development company. The website design and development services of Kirk are very extensive. Whether clients need a full website
Inexpensive Web Space: New affordable Web Servers by Bitpalast
Summary: Bitpalast lifts the premium support requirement from its web servers and now offers affordable web servers and affordable web space. Body: Chicago, November 27, 2010. Bitpalast has lifted the premium support requirement from its web servers. Web space is now available without premium support and has become more inexpensive. Affordable web space is new territory for Bitpalast, since up to now the web-hosting provider made a name for itself mainly with
predic8 launches Public Web Services Registry Web Site
predic8, a provider of open source SOA tools and professional services announces the launch of service-repository.com, an online registry for Web Services. After an initial test phase the Website is now available for the public. The site is not the first directory of free Web Services, but it has some new features that distinguish it from pure lists. Thomas Bayer, the founder of predic8 said: "It is very complicated to explain