{"id":1941,"date":"2011-03-04T07:00:37","date_gmt":"2011-03-04T15:00:37","guid":{"rendered":"http:\/\/www.formtek.com\/blog\/?p=1941"},"modified":"2011-03-04T07:00:37","modified_gmt":"2011-03-04T15:00:37","slug":"security-insecure-web-applications-plague-companies","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/security-insecure-web-applications-plague-companies\/","title":{"rendered":"Security: Insecure Web Applications Plague Companies"},"content":{"rendered":"<p>A new study finds that a large number of web applications are not secure and companies that use those applications either aren&#8217;t aware of the problem or falsely believe they are protected. \u00a0The <a title=\"Ponemon Study on Application Security\" href=\"http:\/\/www.cenzic.com\/resources\/reg-required\/whitePapers\/Ponemon2011\/\" target=\"_blank\">study <\/a>comes from the Ponemon Institute and was sponsored by security vendor companies <a title=\"Barracuda Networks\" href=\"http:\/\/www.barracudanetworks.com\/ns\/?L=en\" target=\"_blank\">Barracuda Networks<\/a> and <a title=\"Cenzic security\" href=\"http:\/\/www.cenzic.com\/\" target=\"_blank\">Cenzic<\/a>.<\/p>\n<p>Grant Murphy, vice president at Barracuda Networks, said that &#8220;There is a real disconnect between the desire and the actual implementation of security\u00a0counter measures that are appropriate for Web application security.&#8221; <a title=\"Bio for Mandeep Khera\" href=\"http:\/\/www.cenzic.com\/company\/management\/khera\/\" target=\"_blank\"> Mandeep Khera<\/a>, chief marketing officer at Cenzic, <a title=\"Mandeep Khera on budgets for web application security\" href=\"http:\/\/www.esecurityplanet.com\/trends\/article.php\/3924046\/Do-You-Need-a-Web-Application-Firewall.htm\" target=\"_blank\">said <\/a>that at many companies the budget for coffee is bigger than the budget for web application security.<\/p>\n<p>The most common types of web insecurities include:<\/p>\n<ul>\n<li>SQL injection<\/li>\n<li>cross-site scripting<\/li>\n<li>input validation flaws<\/li>\n<li>code injection errors<\/li>\n<\/ul>\n<p>The <a title=\"Ponemon Institute\" href=\"http:\/\/www.ponemon.org\/index.php\" target=\"_blank\">Ponemon Institute<\/a> found the 41 percent of the organizations surveyed had more than 100 different web application. \u00a0The following reasons were cited as to why it is important to secure web applications:<\/p>\n<ul>\n<li>62 percent &#8211; Data protection<\/li>\n<li>51 percent &#8211; Compliance<\/li>\n<li>15 percent &#8211; Job Security<\/li>\n<\/ul>\n<p>The report found that even though 51 percent said that compliance is important to them, 43 percent were not at all familiar with <a title=\"OWASP\" href=\"http:\/\/en.wikipedia.org\/wiki\/OWASP\" target=\"_blank\">OWASP<\/a>, the <a title=\"OWASP\" href=\"http:\/\/www.owasp.org\/index.php\/Main_Page\" target=\"_blank\">Open Web Application Security<\/a> project. \u00a0OWASP is a key element of the <a title=\"PCI standard\" href=\"https:\/\/www.pcisecuritystandards.org\/\" target=\"_blank\">PCI standard<\/a>.<\/p>\n<ul>\n<li>66 percent of respondents do testing for vulnerabilities with less than 25 percent of their web applications.<br \/>\n40 percent test only 5 percent of their applications and 20 percent of organizations do no testing<\/li>\n<li>53 percent expect their web hosting provider to manage the security of their web applications<\/li>\n<li>47 percent estimate that an attack on their servers could cause damages ranging from $100,000 to $500,000<\/li>\n<li>73 percent of organizations have applications that have been hacked into at least once during the past two years<\/li>\n<\/ul>\n<p><a title=\"Bio for Larry Ponemon\" href=\"http:\/\/www.ponemon.org\/management\" target=\"_blank\">Larry Ponemon<\/a>, founder of the Ponemon Institute, <a title=\"Ponemon on web application security\" href=\"http:\/\/www.net-security.org\/secworld.php?id=10550\">said <\/a>that &#8220;while IT practitioners recognize the criticality of secure Web applications, their organizations do not provide adequate resources and expertise to manage the risk. \u00a0Over half of the respondents we polled believe they do not have resources to detect and remediate insecure Web applications, and 64 percent said they believe that their organization have inadequate governance and usage policies.&#8221;<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-insecure-web-applications-plague-companies%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>A new study finds that a large number of web applications are not secure and companies that use those applications either aren&#8217;t aware of the problem or falsely believe they are protected. \u00a0The study comes from the Ponemon Institute and<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/security-insecure-web-applications-plague-companies\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-1941","post","type-post","status-publish","format-standard","hentry","category-content-management"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/1941","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=1941"}],"version-history":[{"count":0,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/1941\/revisions"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=1941"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=1941"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=1941"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}