<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>Web Hosting Geeks&#039; Blog &#187; website attack</title> <atom:link href="http://webhostinggeeks.com/blog/tag/website-attack/feed/" rel="self" type="application/rss+xml" /><link>http://webhostinggeeks.com/blog</link> <description>Web Hosting Industry News, Latest Trends, and Analyses.</description> <lastBuildDate>Thu, 24 May 2012 11:11:11 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.2</generator> <item><title>Cross Site Scripting: The Underestimated Website Attack</title><link>http://webhostinggeeks.com/blog/cross-site-scripting-the-underestimated-website-attack/</link> <comments>http://webhostinggeeks.com/blog/cross-site-scripting-the-underestimated-website-attack/#comments</comments> <pubDate>Thu, 09 Apr 2009 19:29:40 +0000</pubDate> <dc:creator>Art</dc:creator> <category><![CDATA[Security Issues]]></category> <category><![CDATA[DoS]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[HTML]]></category> <category><![CDATA[Javascript]]></category> <category><![CDATA[website attack]]></category> <category><![CDATA[XSS]]></category><guid
isPermaLink="false">http://webhostinggeeks.com/blog/?p=281</guid> <description><![CDATA[Cross site scripting or simply XSS, is one of most common threats facing website owners today.  This exploit occurs at the application layer, usually targeting scripts embedded in a web page from a client-side browser rather than the server-side.  In general, XSS is an attack that takes advantages of weaknesses in client-side technologies such as [...]]]></description> <content:encoded><![CDATA[<p
align="left">Cross site scripting or simply XSS, is one of most common threats facing website owners today.  This exploit occurs at the application layer, usually targeting scripts embedded in a web page from a client-side browser rather than the server-side.  In general, XSS is an attack that takes advantages of weaknesses in client-side technologies such as HTML and Javascript.  The intent of cross site scripting is to manipulate the scripts within a web application and execute them in a malicious manner for the benefit of the attacker.</p><p
align="left">Cross site scripting is one of several threats that uses vulnerable applications to exploit a website.  The major difference with XSS is that it does not have the ability to directly steal sensitive information from a back-end database.  Unfortunately, this has led several webmasters to believe that XSS isn&#8217;t a high-risk threat.  Ironically, many have gone on to learn the hard way, forced to suffer through public defacement and embarrassment.</p><p
align="left"><strong>The Consequences of Cross Site Scripting </strong></p><p
align="left">The damaged inflicted by XSS exploits is widely documented.  There have been cases where large corporate websites were hacked by this attack with the results almost always being catastrophic.  Cross site scripting is used to achieve a wide variety of malicious goals and below are some of the most common:</p><p
align="left">DoS (Denial of Service) Attacks</p><p
align="left">Accessing sensitive, unauthorized information</p><p
align="left">Modifying browser and security settings</p><p
align="left">Spying on victims&#8217; computing activities</p><p
align="left">Website defacement</p><p
align="left">Identity theft</p><p
align="left">The consequences of a successful XSS attack can be crippling for businesses of any size.  Security vulnerabilities in some of the most popular websites have led to the theft of credit card numbers and other identifying customer information.  Consumers have been duped into clicking links that direct them to a rogue site purporting as a legitimate business.  Unaware of the malicious ploy, the customer enters their details into the application, handing them right over to the hacker.  If you are the cause of your customers being compromised, they will rightfully lose trust in your site&#8217;s security, a situation that could lead to liability issues and ultimately the loss of your business.</p><p
align="left"><strong>Educate Yourself About Cross Site Scripting</strong></p><p
align="left">The increasing number of successful attacks is proving that large enterprises are just as vulnerable as organizations working on a smaller budget.  What this really shows is that there is not necessarily a lack of resources, yet a lack of awareness within businesses at all levels.  Numerous security reports reveal that a great number of applications on the web are vulnerable to XSS.  Sadly, is not uncommon to find website owners putting their customers and business at risk by not practicing sound security.</p><p
align="left">On the surface, cross site scripting may not seem as severe as other threats but that is what makes it so dangerous.  This is one exploit far too many webmasters are not prepared for.  Until more become aware, the problem will only escalate and continuously claim new victims.  Unless you want a disaster on your hands, take every measure you can to ensure that your web applications are secure.</p><h3  class="related_post_title">Related posts:</h3><ul
class="related_post"><li><a
href="http://webhostinggeeks.com/blog/browsers-aiding-in-website-attacks/" title="Browsers Aiding in Website Attacks ">Browsers Aiding in Website Attacks </a></li><li><a
href="http://webhostinggeeks.com/blog/web-design-yourself-outsource/" title="Web Design: Do it Yourself or Outsource?">Web Design: Do it Yourself or Outsource?</a></li><li><a
href="http://webhostinggeeks.com/blog/google-dart-new-language-arrives/" title="Google Dart – Ready or not, a new Language Arrives">Google Dart – Ready or not, a new Language Arrives</a></li><li><a
href="http://webhostinggeeks.com/blog/markup-languages-attack/" title="When Markup Languages Attack">When Markup Languages Attack</a></li><li><a
href="http://webhostinggeeks.com/blog/control-panels-their-limits/" title="Control Panels – What are Their Limits?">Control Panels – What are Their Limits?</a></li><li><a
href="http://webhostinggeeks.com/blog/google-chrome-browser-cracked/" title="Google Chrome Browser Cracked">Google Chrome Browser Cracked</a></li><li><a
href="http://webhostinggeeks.com/blog/conventional-web-development-vs-content-management-systems/" title="Conventional Web Development Vs Content Management Systems">Conventional Web Development Vs Content Management Systems</a></li><li><a
href="http://webhostinggeeks.com/blog/static-html-pages-vs-cms-generated-sites/" title="Static HTML Pages vs CMS Generated Sites">Static HTML Pages vs CMS Generated Sites</a></li><li><a
href="http://webhostinggeeks.com/blog/protecting-your-site-from-ddos-attacks/" title="Protecting Your Site from DDoS Attacks ">Protecting Your Site from DDoS Attacks </a></li><li><a
href="http://webhostinggeeks.com/blog/healthy-website-security-practices/" title="Healthy Website Security Practices ">Healthy Website Security Practices </a></li></ul>]]></content:encoded> <wfw:commentRss>http://webhostinggeeks.com/blog/cross-site-scripting-the-underestimated-website-attack/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Browsers Aiding in Website Attacks</title><link>http://webhostinggeeks.com/blog/browsers-aiding-in-website-attacks/</link> <comments>http://webhostinggeeks.com/blog/browsers-aiding-in-website-attacks/#comments</comments> <pubDate>Mon, 29 Dec 2008 16:00:45 +0000</pubDate> <dc:creator>Art</dc:creator> <category><![CDATA[Security Issues]]></category> <category><![CDATA[Active X]]></category> <category><![CDATA[Chrome]]></category> <category><![CDATA[cross site scripting]]></category> <category><![CDATA[exploits]]></category> <category><![CDATA[Firefox]]></category> <category><![CDATA[hackers]]></category> <category><![CDATA[Javascript]]></category> <category><![CDATA[Opera]]></category> <category><![CDATA[Safari]]></category> <category><![CDATA[SQL injection]]></category> <category><![CDATA[web browser]]></category> <category><![CDATA[website attack]]></category><guid
isPermaLink="false">http://webhostinggeeks.com/blog/?p=133</guid> <description><![CDATA[Website attacks are on the rise with intruders using an array of hacking techniques from cross site scripting to SQL injection.  Although careless development and insecure applications play a major role in a site&#8217;s vulnerability, the typical web browser is a contributing factor as well. Despite the fact that several improvements have been made, none [...]]]></description> <content:encoded><![CDATA[<p>Website attacks are on the rise with intruders using an array of hacking techniques from cross site scripting to SQL injection.  Although careless development and insecure applications play a major role in a site&#8217;s vulnerability, the typical web browser is a contributing factor as well.</p><p>Despite the fact that several improvements have been made, none of the top web browsers are completely secure.  Because of this, many web security experts are projecting that website attacks will continue to be an issue.  The combination of enhanced functionality and the lack of adequate security implementations have left a number of browsers vulnerable to sophisticated attacks.  Some researchers are saying that the increasing number of exploits is the direct result of Web 2.0 technologies and advanced web hosting features.</p><p><strong>Evolution in Technology Opens Doors to Further Threats</strong></p><p>Things were fairly innocent in the early days of the internet when static pages were prevalent, before technologies such as JavaScript and Active X came into play.  Today&#8217;s World Wide Web is dominated by dynamic web-based applications and complex server-side scripting languages, factors that enable browsers to be used in various ways to exploit websites.  Gary McGraw of Cigital, a software security company, agrees that these feature-rich designs have made browsers far less secure, stating that they are structured more like complete operating systems.</p><p>This past September Google released Chrome, its new web browser which was immediately faced with stiff competition in the form of Microsoft Internet Explorer, Mozilla Firefox, Apple Safari and Opera.  While internet users have a wide variety of browsers to choose from, the options are still limited in terms of security, including Chrome.  Experts contend that the browser war of who can out do one another in the feature department is what ultimately leads to these security vulnerabilities.</p><p>Though quite serious, the security issues associated with today&#8217;s popular web browsers are not attributed to a lack of effort.  Some say that developers are doing all they can but when considering the fact that website attacks such as cross site scripting and cross site request forgery are typically the result of design, these flaws tend to be much harder to fix than bugs found in software code.  Observers suggest that the vulnerabilities are not going to disappear entirely but do stress that browser developers can do more to enhance security.</p><p>In general, development teams only have a little time to address browser vulnerabilities before the hacker community is able to discover them.  Developers are being encouraged to practice browser security just like those who make other software products.  This is extremely important as the major web browsers literally have hundred of millions of users.  One solid approach towards website security is standardized authentication, something that would need to be addressed by system administrators.  Another recommendation is for browser developers to design products that alert users when they are being directed to intranet zones such as localhost or RFC1918 as attackers are increasingly targeting internal devices.  Security firms have also predicted that the manner in which data is handled when requests are made between a browser and website should play a critical part in future designs.</p><h3  class="related_post_title">Related posts:</h3><ul
class="related_post"><li><a
href="http://webhostinggeeks.com/blog/web-browsers-comparison/" title="Comparing The Best Web Browsers ">Comparing The Best Web Browsers </a></li><li><a
href="http://webhostinggeeks.com/blog/google-chrome-browser-cracked/" title="Google Chrome Browser Cracked">Google Chrome Browser Cracked</a></li><li><a
href="http://webhostinggeeks.com/blog/authentication-hacking-is-your-site-vulnerable/" title="Authentication Hacking: Is Your Site Vulnerable? ">Authentication Hacking: Is Your Site Vulnerable? </a></li><li><a
href="http://webhostinggeeks.com/blog/major-threats-to-business-website-security/" title="Major Threats to Business Website Security ">Major Threats to Business Website Security </a></li><li><a
href="http://webhostinggeeks.com/blog/how-to-find-secure-shared-hosting/" title="How to Find Secure Shared Hosting ">How to Find Secure Shared Hosting </a></li><li><a
href="http://webhostinggeeks.com/blog/the-vulnerability-of-ajax-applications/" title="The Vulnerability of AJAX Applications">The Vulnerability of AJAX Applications</a></li><li><a
href="http://webhostinggeeks.com/blog/cross-site-scripting-the-underestimated-website-attack/" title="Cross Site Scripting: The Underestimated Website Attack">Cross Site Scripting: The Underestimated Website Attack</a></li><li><a
href="http://webhostinggeeks.com/blog/malware-attacks-on-the-rise/" title="Malware Attacks on the Rise">Malware Attacks on the Rise</a></li><li><a
href="http://webhostinggeeks.com/blog/google-dart-new-language-arrives/" title="Google Dart – Ready or not, a new Language Arrives">Google Dart – Ready or not, a new Language Arrives</a></li><li><a
href="http://webhostinggeeks.com/blog/godaddy-account-hack/" title="What the New User can Learn from the GoDaddy Account Hack">What the New User can Learn from the GoDaddy Account Hack</a></li></ul>]]></content:encoded> <wfw:commentRss>http://webhostinggeeks.com/blog/browsers-aiding-in-website-attacks/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Content Delivery Network via Amazon Web Services: CloudFront: d3pnguju6g7vh.cloudfront.net

Served from: webhostinggeeks.com @ 2012-05-25 21:20:16 -->
