{"id":9,"date":"2006-02-10T15:09:49","date_gmt":"2006-02-10T23:09:49","guid":{"rendered":"http:\/\/www.formtek.com\/blog\/?p=9"},"modified":"2006-02-10T15:09:49","modified_gmt":"2006-02-10T23:09:49","slug":"web-site-scanning-for-vulnerabilities","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/web-site-scanning-for-vulnerabilities\/","title":{"rendered":"Web site scanning for vulnerabilities"},"content":{"rendered":"<p align=\"left\">By <a title=\"Web Application Vulnerabilities\" href=\"http:\/\/www.itbusinessedge.com\/item\/?ci=12059\" target=\"_blank\">one estimate<\/a> more than 50-60% of all Web applications and web sites contain some critical vulnerability that can be easily compromised. Using SSL, firewalls and locked-down servers can lead to a sense of security, but none of these things address the issue of web application hacking &#8212; attacks made through ports 80 and 443.<\/p>\n<p>Database-driven dynamic content is clearly the main area of vulnerability. Any web app that operates dynamically based on user input has the potential to be compromised by maliciously altering the data communicated to the server.<\/p>\n<p><center><img loading=\"lazy\" decoding=\"async\" id=\"image8\" height=\"341\" alt=\"Web Security\" src=\"http:\/\/formtek.com\/blog\/wp-content\/uploads\/2006\/02\/WebSecurity.gif\" width=\"560\" align=\"left\" \/><\/center><br \/>\nTwo common types of <a title=\"Web Application vulnerability\" href=\"http:\/\/en.wikipedia.org\/wiki\/Security_vulnerability\" target=\"_blank\">vulnerabilities<\/a> are called <a title=\"SQL Injection\" href=\"http:\/\/en.wikipedia.org\/wiki\/SQL_Injection\" target=\"_blank\">SQL Injection<\/a> and <a title=\"Cross Site Scripting (XSS)\" href=\"http:\/\/en.wikipedia.org\/wiki\/Cross_site_scripting\" target=\"_blank\">Cross Site Scripting<\/a> (XSS).\u00a0 SQL injection is the ability to inject and run arbitrary SQL code without having standard database access.\u00a0\u00a0 XSS means to forcibly insert html or script into another web page.<\/p>\n<p><a title=\"Web application scanning software\" href=\"http:\/\/www.windowsecurity.com\/whitepapers\/Importance-Web-Application-Scanning.html#solution\" target=\"_blank\">Scanning software<\/a> is now available that can automatically exercise pages of a web application, looking for potential vulnerabilities.\u00a0<\/p>\n<p><a title=\"Whitehat Security\" href=\"http:\/\/www.whitehatsec.com\" target=\"_blank\">Whitehat security<\/a> has a good set of <a title=\"Whitehat Security Slides\" href=\"http:\/\/www.whitehatsec.com\/presentations\/challenges_of_scanning.pdf\" target=\"_blank\">slides<\/a> describing web application vulnerability issues.\u00a0 It discusses limitations of today&#8217;s web scanning software.\u00a0 The current generation of software is really only good at looking at technical vulnerabilities.\u00a0 There is another realm of logical vulnerability issues not addressed.\u00a0 And then there is a big hurdle for being able to identify and load scenarios into the web scan software so it knows how to access all or most pages of the application.<\/p>\n<p>Given these limitations, it still seems like web scanning software is a huge step forward to identify vulnerabilities.\u00a0 At <a title=\"Formtek, Inc.\" href=\"http:\/\/www.formtek.com\/blog\/wp-admin\/www.formtek.com\" target=\"_blank\">Formtek<\/a>, our development and engineering groups have used a couple of these Web Scan products: <a title=\"WatchFire Web Application Scanning software\" href=\"http:\/\/www.watchfire.com\/default.aspx\" target=\"_blank\">WatchFire<\/a> and <a title=\"Acunetix Web Application Scanning software\" href=\"http:\/\/www.acunetix.com\/\" target=\"_blank\">Acunetix<\/a>.<\/p>\n<p>We were basically pleased with the results.\u00a0 Working with our QA people, we identified scenarios that do thorough coverage of our app web pages.\u00a0 With the scenarios in place, we then pointed the scanners to our web-based apps.\u00a0 The reports that were generated were very detailed.\u00a0 They also alerted us to some things we had never considered.\u00a0 I&#8217;d recommend the use of the web scanning tools.<\/p>\n<p>Based on our findings, the Formtek | Orion version 4.4.1.10 patch was created.\u00a0 Re-running the scan tools against this version of Orion came up clean.\u00a0 Going forward, we plan to make the use of a web application scanner a standard part of the Formtek QA test cycle.<!--025d4a1d93380c6335f3328f521fbebc--><\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fweb-site-scanning-for-vulnerabilities%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>By one estimate more than 50-60% of all Web applications and web sites contain some critical vulnerability that can be easily compromised. Using SSL, firewalls and locked-down servers can lead to a sense of security, but none of these things<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/web-site-scanning-for-vulnerabilities\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,31],"tags":[],"class_list":["post-9","post","type-post","status-publish","format-standard","hentry","category-content-management","category-security"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/9","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=9"}],"version-history":[{"count":0,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/9\/revisions"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=9"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=9"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=9"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}