{"id":716,"date":"2014-05-24T11:17:50","date_gmt":"2014-05-24T16:17:50","guid":{"rendered":"http:\/\/www.serverpronto.com\/spu\/?p=716"},"modified":"2018-07-31T10:30:00","modified_gmt":"2018-07-31T15:30:00","slug":"vulnerabilities-and-exploits-to-guard-against-in-web-apps","status":"publish","type":"post","link":"https:\/\/www.serverpronto.com\/spu\/2014\/05\/vulnerabilities-and-exploits-to-guard-against-in-web-apps\/","title":{"rendered":"Vulnerabilities to Guard in Web Apps"},"content":{"rendered":"<p><em><span style=\"line-height: 1.5em;\">Though it may be hard for developers to accept, there is a wide range of different security threats that may target their apps, and they continue to change and improve. Developers and website owners should be aware of some of the most common attack vectors which may bring different challenges. So, by reading up on a few of these frequent attacks, developers will be able to focus on creating a great user experience while feeling confident their applications are secure. Here we summarize some of the potential attacks we can face on a daily basis.<!--more--><\/span><\/em><\/p>\n<h2>6. XSS Scripting Attacks<\/h2>\n<p>XSS attacks (cross-site scripting attacks) are some of the most common attacks, so almost all developers will need to be ready to deal with them. Mostly this is the use of known vulnerabilities in JavaScript, Flash and other similar on-site technologies to run arbitrary code.<\/p>\n<p>So, it is relatively easy to set a script to search for and attack applications out there randomly. Just about any novice hacker is capable of setting up these types of scripts, and its report\u00c2\u00a0they made up around 84% of the attacks made in 2013. Although they are not sophisticated, they still allow hackers to gain access to user\u00e2\u20ac\u2122s data.<\/p>\n<h2>5. CRIME<\/h2>\n<p>CRIME (Compression Ratio Info-leak Made Easy) is a vulnerability that has sprung up that is capable of capturing cookies and session high jacking. It can yield information that can be sold by the hackers. So, it is an exploit that used vulnerabilities in HTTP compression and can defeat\u00c2\u00a0at the client or server end. However, at the beginning of 2014, there are still a vast number of websites and browsers that are open to the attack.<\/p>\n<h2>4. BREACH<\/h2>\n<p>Browser Reconnaissance and Exfiltration via Adaptive Compression of Hypertext (BREACH) is one of the newest security threats out there, based on CRIME. It has already exposed some vulnerabilities in some favorite online apps. The exploit works by brute forcing a few bytes of https traffic which is compressed. And then working out the rest, allowing the traffic to decode. It will enable the attacker to see the https content. The easiest way to fix this exploit is to disable HTTP compression, but it has also suggested HTTP compression could be disabled only when potential attacks could occur.<\/p>\n<h2>3. Identity Theft<\/h2>\n<p>It is important to note that identity theft continues to be a significant concern. It can be an attack that has happened elsewhere &#8211; perhaps the attacker has managed to get the user\u00e2\u20ac\u2122s password from their computer by using malware or a similar exploit. Developers need to think about how they would deal with this type of attack. So, the attacker appears to have all the credentials of the original user. Including potentially additional security checks for unusual activity.<\/p>\n<h2>2. DDOS<\/h2>\n<p>Denial of service attacks is one of the oldest techniques used by hackers. It has recently been used in earnest by attackers wanting to protest the activities of businesses. App developers should think about how vulnerable they may be to these kinds of attacks. So, if they notice that their apps are sensitive to these attacks, they should try to introduce ways to minimize disruption.<\/p>\n<h2>1. SQL Vulnerabilities<\/h2>\n<p>This last entry on the list will be essential to consider. It has proved to be a challenge for developers over the years. And continues to be one of the easiest ways for attackers to gain access to a significant amount of database content. SQL vulnerabilities occur when the attacker on the database can run arbitrary database code. Allowing access to the database. So, the only way to combat this type of exploit is to have good code in the first place that doesn\u00e2\u20ac\u2122t allow such code to execute.<\/p>\n<p><a href=\"https:\/\/www.serverpronto.com\">ServerPronto<\/a> offers the best affordable and secure hosting service in all dedicated server packages.<\/p>\n<p>Photo credit Flickr \/\u00c2\u00a0<a href=\"http:\/\/www.flickr.com\/photos\/carbonnyc\/\">CarbonNYC<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Though it may be hard for developers to accept, there is a wide range of different security threats that may target their apps, and they continue to change and improve. Developers and website owners should be aware of some of the most common attack vectors which may bring different challenges. So, by reading up on<\/p>\n","protected":false},"author":9,"featured_media":717,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[86],"tags":[123,17,171,112,172,168,22,170,169,18],"class_list":["post-716","post","type-post","status-publish","format-image","has-post-thumbnail","category-server-security","tag-cloud","tag-dedicated-server","tag-exploit","tag-hosting","tag-identity-theft","tag-security-threats","tag-server","tag-vulnerability","tag-web-apps","tag-web-hosting","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/716","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/comments?post=716"}],"version-history":[{"count":5,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/716\/revisions"}],"predecessor-version":[{"id":2535,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/posts\/716\/revisions\/2535"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media\/717"}],"wp:attachment":[{"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/media?parent=716"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/categories?post=716"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.serverpronto.com\/spu\/wp-json\/wp\/v2\/tags?post=716"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}