Most websites can be "easily hacked"
By Rene Millman,
Most websites have vulnerabilities that could allow hackers to access systems or to launch Denial of Service (DoS) attacks, according to new findings.
The research carried out by security consultants NTA Monitor, found that 90 per cent of organisations' websites contain at least one or more flaws that could allow external users to gain unauthorised system access or disrupt service availability. A further 33 per cent of websites were found to have widely known critical vulnerabilities that are actively exploited by hackers.
The company's Web Application Security Report 2007 found that attackers focusing on web application security problems are actively developing tools and techniques for exploiting them.
Roy Hills, technical director at NTA Monitor said that with an increasing number of people using the internet for banking, shopping and bill payments it was "high time that organisations took greater steps towards protecting these revenue generating and efficiency enabling systems."
Hills recommended that organisations reduce the risk of having their website hacked by having an account lockout mechanism in place to put stops on accounts permanently or temporarily, as this would help prevent attackers from being able to use brute force to access user accounts.
He also said that meta characters such as single quotes, double quotes and semi colons should be avoided in order to minimise the threat of SQL injection attacks which, he said, were "a high risk vulnerability".
The advice comes a day after security company Zone-H found that 20,365 websites had been accessed and defaced by one hacker in 24 hours. The Turkish hacker, known as aLpTurkTegin, managed to access and deface the sites, including one for popular TV series Battlestar Galactica.
You may also like...
advertisement
Latest Security Features
Q&A: The ID card commissioner talks cards and controversy
We spoke to ID card commissioner Sir John Pilling about his thoughts on the identity scheme and why we might all think he's a bit of prat down the line.
- So you've been hacked, now what?
- The problems facing Internet Explorer
- Year in Review: 2009 in your words
- Top 10 security predictions for 2010
- Year in Review: Top tech stories of 2009
- The worst IT disasters of 2009
- Five free security software suites
- How to stay safe shopping online
- Is it time to switch to IPv6?
Latest Security Reviews
Symantec Backup Exec 2010 review
Rating: ![]()
advertisement
Most popular
- Google updates Chrome, awards security bonus
- Why is Microsoft accelerating Service Pack 1?
- Report: Macs cost less to run than Windows PCs
- Your Views: Google Street View across the UK
- Q&A: Conrad Wolfram on communicating with apps in Web 3.0
- O2 condemns 'bullying' law firms for threatening file-sharers
- Windows Phone 7 review ? hands on
- Dell Vostro V13 review
- Digital Economy Bill to cost ISPs up to £500 million
- Reviews round-up: Windows Phone 7 and Firefox Mobile
Latest News Videos in Security
Video: Why security is everybody's responsibility
Rik Ferguson, senior security advisor at Trend Micro says it's up to all of us to make security work.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.




