Risk
11/30/2006
05:12 PM
50%
50%

E-Tailers Leaving Money On The Table Thanks To Weak Web Sites

One week after I'd already bought three holiday presents online I learned that the vast majority of Web sites are vulnerable to attack by malicious hackers and that such security concerns are expected to drive away potential customers who would have shelled out nearly $2 billion online this year. The only real surprise is why those numbers aren't higher.

One week after I'd already bought three holiday presents online I learned that the vast majority of Web sites are vulnerable to attack by malicious hackers and that such security concerns are expected to drive away potential customers who would have shelled out nearly $2 billion online this year. The only real surprise is why those numbers aren't higher.Eight in 10 Web sites are vulnerable to attack, according to a sneak peek WhiteHat Security offered this week at its new Web application security risk report, which the company will begin issuing quarterly starting in January. To put this in perspective, that's the same percentage of dentists who recommend sugar-free gum to their patients who chew gum. For any company worried about how a Web-site outage would affect their brand image this gift-buying season, if you haven't already audited your Web apps for vulnerabilities, it's already too late.

WhiteHat founder and CTO Jeremiah Grossman fingered the culprits during Wednesday's presentation. Cross-site scripting vulnerabilities were found in 71% of the 300 sites WhiteHat researched. Grossman pointed out that this percentage jumps to 90% when sites offering e-commerce were evaluated. No other category of vulnerability--including information leakage, predictable resource location, or content spoofing--was found in more than 30% of the sites WhiteHat evaluated.

Of course, not all vulnerabilities are created equal: more than one-third of the sites evaluated had a high level of severity, meaning the exploitation of a vulnerability could lead to the loss of customer data, passwords, or other critical information. Nearly three-quarters of the sites contained a vulnerability--in most cases a cross-site scripting problem--that would have a middling-level of impact on a business. Many sites have multiple vulnerabilities with different levels of severity.

"If there are 100 million Web sites out there, it's a Swiss cheese type of environment," said Grossman, who's the embodiment of converged IT and physical security, given that he's a well-respected security researcher and holds a blue belt in Brazilian jujitsu.

That's not to say the news is all bad. The prevalence of buffer overflows has dropped, to the point where they didn't even make WhiteHat's list. Grossman pointed out that buffer overflows aren't too common in custom-built Web applications, which were present in all of the sites evaluated.

Does this mean that e-tailers will continue to leave money on the table when potential customers are scared off by security risks? Gartner thinks so, saying that $1 billion is lost because of shoppers who refuse to spend money online, while another $913 million is lost because those who do shop online are wary of online security.

One obvious measure of relief is for businesses to regularly audit their Web applications for security vulnerabilities, particularly after changes have been made to those apps. Although no online shopping strategy is foolproof, consumers should stick with well-known retailers and use their credit cards rather than debit cards when making a purchase (gift cards are best, but you probably won't have many of those until after the holidays). They should also save all e-mails sent to them by the e-tailer acknowledging the purchase.

If a loss of confidence in online transactions seems like a big deal, that's because it is. Businesses can offer all of the discounts, personalization features, and customer conveniences they want, but that won't help them win back the business of a customer who's been burned by identity theft.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7896
Published: 2015-03-03
Multiple cross-site scripting (XSS) vulnerabilities in HP XP P9000 Command View Advanced Edition Software Online Help, as used in HP Device Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Tiered Storage Manager 6.x through 8.x before 8.1.2-00, HP XP P9000 Replication Manager 6.x and 7.x before ...

CVE-2014-9283
Published: 2015-03-03
The BestWebSoft Captcha plugin before 4.0.7 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

CVE-2014-9683
Published: 2015-03-03
Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted filename.

CVE-2015-0656
Published: 2015-03-03
Cross-site scripting (XSS) vulnerability in the login page in Cisco Network Analysis Module (NAM) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCum81269.

CVE-2015-0890
Published: 2015-03-03
The BestWebSoft Google Captcha (aka reCAPTCHA) plugin before 1.13 for WordPress allows remote attackers to bypass the CAPTCHA protection mechanism and obtain administrative access via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.