Cenzic web app report highlights security problems

+ 0
expand close

Summary: Will we ever get a secure Internet? There’s no cause for optimism in the latest Cenzic report into web app security . A few highlights: 7 out of 10 Web applications analyzed by Cenzic were found vulnerable to Cross-Site Scripting attacks ...  Click to expand...

Will we ever get a secure Internet? There’s no cause for optimism in the latest Cenzic report into web app security. A few highlights:

  • 7 out of 10 Web applications analyzed by Cenzic were found vulnerable to Cross-Site Scripting attacks
  • 70% of Internet vulnerabilities are in web applications
  • FireFox has the most reported browser vulnerabilities at 40%; IE is 23%
  • Weak session management, SQL Injection, and poor authentication remain very common problems
  • 33% of all reported vulnerabilities are caused by insecure PHP coding, compared to 1% caused by insecurities in PHP itself.

OK, it’s another report from a security company with an interest in hyping the figures; but I found this one more plausible than some.

The PHP remarks are interesting; it would be good to see equivalent figures for ASP.NET and Java.

 
close

This Week in Rojo [The best of the blogosphere every week.]

Rojo: Digg Stars; Google Matrix; ObamaSpace

 Diggbait anyone? The Wall Street Journal surveyed who’s who when it comes to influencing social-networking sites like digg and Reddit, and finds just 30 of 900,000 registered digg users are responsible for a third of stories on its home page, blogs Business 2.0.

» Subscribe to the This Week in Rojo newsletter