Risk
11/30/2006
05:12 PM
Connect Directly
RSS
E-Mail
50%
50%

E-Tailers Leaving Money On The Table Thanks To Weak Web Sites

One week after I'd already bought three holiday presents online I learned that the vast majority of Web sites are vulnerable to attack by malicious hackers and that such security concerns are expected to drive away potential customers who would have shelled out nearly $2 billion online this year. The only real surprise is why those numbers aren't higher.

One week after I'd already bought three holiday presents online I learned that the vast majority of Web sites are vulnerable to attack by malicious hackers and that such security concerns are expected to drive away potential customers who would have shelled out nearly $2 billion online this year. The only real surprise is why those numbers aren't higher.Eight in 10 Web sites are vulnerable to attack, according to a sneak peek WhiteHat Security offered this week at its new Web application security risk report, which the company will begin issuing quarterly starting in January. To put this in perspective, that's the same percentage of dentists who recommend sugar-free gum to their patients who chew gum. For any company worried about how a Web-site outage would affect their brand image this gift-buying season, if you haven't already audited your Web apps for vulnerabilities, it's already too late.

WhiteHat founder and CTO Jeremiah Grossman fingered the culprits during Wednesday's presentation. Cross-site scripting vulnerabilities were found in 71% of the 300 sites WhiteHat researched. Grossman pointed out that this percentage jumps to 90% when sites offering e-commerce were evaluated. No other category of vulnerability--including information leakage, predictable resource location, or content spoofing--was found in more than 30% of the sites WhiteHat evaluated.

Of course, not all vulnerabilities are created equal: more than one-third of the sites evaluated had a high level of severity, meaning the exploitation of a vulnerability could lead to the loss of customer data, passwords, or other critical information. Nearly three-quarters of the sites contained a vulnerability--in most cases a cross-site scripting problem--that would have a middling-level of impact on a business. Many sites have multiple vulnerabilities with different levels of severity.

"If there are 100 million Web sites out there, it's a Swiss cheese type of environment," said Grossman, who's the embodiment of converged IT and physical security, given that he's a well-respected security researcher and holds a blue belt in Brazilian jujitsu.

That's not to say the news is all bad. The prevalence of buffer overflows has dropped, to the point where they didn't even make WhiteHat's list. Grossman pointed out that buffer overflows aren't too common in custom-built Web applications, which were present in all of the sites evaluated.

Does this mean that e-tailers will continue to leave money on the table when potential customers are scared off by security risks? Gartner thinks so, saying that $1 billion is lost because of shoppers who refuse to spend money online, while another $913 million is lost because those who do shop online are wary of online security.

One obvious measure of relief is for businesses to regularly audit their Web applications for security vulnerabilities, particularly after changes have been made to those apps. Although no online shopping strategy is foolproof, consumers should stick with well-known retailers and use their credit cards rather than debit cards when making a purchase (gift cards are best, but you probably won't have many of those until after the holidays). They should also save all e-mails sent to them by the e-tailer acknowledging the purchase.

If a loss of confidence in online transactions seems like a big deal, that's because it is. Businesses can offer all of the discounts, personalization features, and customer conveniences they want, but that won't help them win back the business of a customer who's been burned by identity theft.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6117
Published: 2014-07-11
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

CVE-2014-0174
Published: 2014-07-11
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2014-3485
Published: 2014-07-11
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

CVE-2014-3499
Published: 2014-07-11
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

CVE-2014-3503
Published: 2014-07-11
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.