9. Disclose your vulnerabilities
Posted on 12 May 2008 at 15:07
IT security revolves around the concept of vulnerability: the attacker wants to find and exploit it, while your aim is to ensure that it doesn't exist. Unfortunately, while the former is child's play, the latter is harder than it may seem. As Lawson explains: "All software has faults; this is an immutable fact about code written by humans. It's critically important computer systems are kept up to date, as the updates fix the bugs that could lead to a compromise by a hacker. Microsoft has made this incredibly easy with the Automatic Updates tool. Ensure this tool is running to download updates automatically. Corporate environments should test all updates prior to deployment to ensure the update doesn't affect business functions."
The Microsoft Baseline Security Analyzer (www.microsoft.com/technet/security/tools/mbsahome.mspx) is another easy-to-use tool designed for the IT professional that can help small and medium-sized businesses to determine their security state in accordance with Microsoft security recommendations.
But what about when you move away from your computer and the vulnerabilities of the OS, and look towards your website instead? Fogerty recommends two distinct approaches: web-server and web-application testing. "With web-server testing you're testing the underlying web server (IIS, Apache) to make sure it's patched and in a hardened configuration. Run free tools like Nikto or Nessus to check for vulnerabilities," he says. Both are available to members of Hackerwhacker as mentioned earlier.
"With web-app testing, you are looking at the application that sits on the web server. This is usually a custom application and could be susceptible to SQL Injection, Cross Site Scripting (XSS) and Cross Site Request Forgery (CSRF) vulnerabilities if the developers have not used 'defensive programming'; that is, not validating input from the client before acting on it," Fogerty adds. "There are plenty of free web-app testing proxy tools that act as a middle-man between the client and server. You can then insert 'malicious' data into the HTTP stream to see if the web app fails to deal with it." Try Achilles (www.mavensecurity.com/achilles), Burp (www.portswigger.net/proxy) or Paros (www.parosproxy.org/download.shtml) for starters.
Author: Davey Winder
From around the web
For more details about purchasing this feature and/or images for editorial usage, please contact Jasmine Samra on pictures@dennis.co.uk
advertisement
- Windows 8 on ARM to run desktop apps... but only Office
- Windows 8 pauses desktop apps to save energy
- Mobiles boost Apple profits... and there's more to come
- Ubuntu rips up drop-down menus
- RIM founders fall on their swords
- Microsoft to tweak Windows 8 Start screen
- Weak PC sales expected to hit Microsoft's profits
- 802.11ac routers to hit 800Mbit/sec this year
- Asus Transformer Prime gets HD upgrade
- Netgear brings apps to routers for “smart networks”
- Chrome's shine getting lost in translation
- BytePac: the cardboard hard disk enclosure
- How tech loosens our grip on reality
- Hokum watch: Safer Internet Day
- Why I'm deleting Adobe from my PC
- Prepare to be patronised: it's Safer Internet Day
- Dear Sony, Samsung and every other tech company in the world: stop trying to be Apple
- Will Apple's Final Cut Pro X update placate the pros?
- Smartr Contacts for iPhone review
- Switching to Office 365's Outlook Web App
advertisement
