Web Hacking - Attacks And Defense

The early Web storefronts were designed by using scripting languages such as Perl,
 running on a Web server, and interacting with flat files instead of databases.
The systems were heterogeneous; that is, each component was distinct and separate.
As Web technologies matured, vendors such as Microsoft and Sun Microsystems came up
 with homogeneous e- commerce framework technologies and other vendors joined the race.


 Web storefront technologies began to feature multilayered applications involving
middleware and middle-tier binary components such as ISAPI filters and Java beans.

Integration with databases allowed applications to migrate from flat files to relational
 databases RDBMS, such as MS-SQL server, Oracle, and MySQL. Similarly, for storefronts,
 technologies such as Dynamic HTML DHTML and Flash started gaining popularity,
 because they made the shopping experience both visually appealing and pleasant.


 However, each stage of evolution brought new vulnerabilities and new dimensions of attack.
 Incidents of robberies from electronic storefronts rose dramatically, and stealing
information and money on the Web became intolerable, desperately needing technical attention.

Where do hackers find loopholes in e-business systems? Whenever a business decides to establish
 or upgrade an electronic presence, things don't happen all at once. At one stage or another,
different technologies are integrated with existing systems. Businesses thrive on evolution,
not software. Mixing and matching various technologies over a period of time leaves
opportunities for vulnerabilities to creep.

The root causes of vulnerabilities plaguing electronic storefronts are:

         Poor input validation

         Improper use of cookies

         Poor session or state tracking

         Assumptions that HTML and client-side scripting cannot be tampered with.

         Improper database integration

         Security loopholes in third-party products


Tthese issues throughout the remainder of this chapter by following the experiences
 of a company that decided to place its business on the Web.

The second obvious mistake was using client-side scripts to perform input validation.
 Code developers are always tempted to use JavaScript or VBScript to have code executed
on the client side and remove the burden from the server. However, client-side scripts are as
 fragile as hidden fields when it comes to the lack of tamper resistance. Client-side scripts
 only are to be used for smooth navigation or adding extra interactivity and presentability to
the Web page. An attacker can easily bypass or modify client-side scripts and circumvent any
checks enforced by them. As in the Acme case, attackers can inject negative quantities with ease,
 bypassing any restriction imposed by the embedded JavaScript. Similarly, some Web-based storefront
 systems perform arithmetic operations on the client side, such as computing the total quantity and
price of an order within the fill-out form itself. To the customer, it is a nice feature when they
can see prices updated on the browser without submitting the values to the server and waiting for
a response.
Related Posts:
  • The Motorola Moto X The Motorola Moto X- speedy camera                Nice voice command well-crafted design.          &n… Read More
  • LG Optimus LG has begun rolling out the Android 4.4 KitKat firmware update for LG Optimus G Pro.  The first market to get it is LG's homeland - South Korea. The update is available on two of the three Korean telecoms - SKT an… Read More
  • Why classified site needed New hampshire skilled trades/artisan jobs classifieds - craigslist how are gemstones  classified this is why two different gemstones may have the same size but different  weights and vice versa -- a one carat round… Read More
  • Android 4.3 for Sony Xperia    Apparently Sony has been working on Android 4.3 Jelly Bean firmware update and it will soon begin rolling out. The first country to get it should be France as the SFR carrier has already approved the ROM re… Read More
  • Nokia Lumia Lumia 930 launch date, but Microsoft and Nokia may have moved up the schedule.  The Nokia Lumia 630 will succeed the 620, which got lost in the shadow of the highly popular Lumia 520. Its rumored specifications inc… Read More
  • Web Development today Web Development today Wordpress for web developers 2nd edition stephanie leary wordpress for web developers is a complete guide for web designers and developers who want to begin. Website development  web development s… Read More
  • Nokia Lumia 630 - Russia- just €160 Nokia Lumia 630 went official just a few days ago. It is among the first smartphones to run Windows Phone 8.1 with Lumia Cyan out of the box.  The smartphone is considered as a successor of the Lumia 620. Nokia has … Read More
  • Work from home-online Work from home business opportunities made easy  working from home is a huge dream for a lot of people for many different reasons no matter the reason, finding a free work from home job can be time consuming. … Read More
  • Japanese market-LG G3 The Japanese market version of LG's yet to be revealed G3 flagship might have leaked  on Twitter. A duo of press shots showing a mysterious high-end LG handset made the rounds on the social network, courtesy of @evl… Read More
  • ways to make money at home fast How to turn a little money into - learn to trade stock options find a job use the beehives  new job search engine to find work just enter a few keywords, and your location, and you re on your way it s easy and free. Wi… Read More
  • Amazon phone-Six cameras  KGI Securities analyst Ming-Chi Kuo predicted in a note to clients that Amazon -US will launch its own brand smartphone in 3-6 months, using the same hardware strategy as used for its e-reader and tablet. For thos… Read More
  • how to make money online  http://money-clips-online.com  http://www.turboonlinebusiness.com  http://www.affiliatejob.org  http://www.onlinemoneymakingsecrets.biz  http://onlineworknet.com  http://reeonlinemoney.n… Read More
  • HTC looking to smartphone market HTC has big plans, and most of them are probably riding on the success of the new HTC One, aka the M8. Reception to the new device has been good, so HTC's projections may very well come to fruition. Peter Chou, CEO and … Read More
  • Microsoft to release two GDR updates for WP8.1 Microsoft separates Windows Phone 8 updates into major and minor ones -   so far we've seen one major 8.1 and three minor ones GDR 1, 2 and 3. The company is reportedly planning at least two GDR updates for … Read More
  • Google packs-new gaming features Google took a big step over the weekend to address problems with in-game  purchases, but that's not all that the company has in store for game developers this week. As the annual Game Developers Conference ki… Read More