Risk
11/30/2006
05:12 PM
Connect Directly
RSS
E-Mail
50%
50%

E-Tailers Leaving Money On The Table Thanks To Weak Web Sites

One week after I'd already bought three holiday presents online I learned that the vast majority of Web sites are vulnerable to attack by malicious hackers and that such security concerns are expected to drive away potential customers who would have shelled out nearly $2 billion online this year. The only real surprise is why those numbers aren't higher.

One week after I'd already bought three holiday presents online I learned that the vast majority of Web sites are vulnerable to attack by malicious hackers and that such security concerns are expected to drive away potential customers who would have shelled out nearly $2 billion online this year. The only real surprise is why those numbers aren't higher.Eight in 10 Web sites are vulnerable to attack, according to a sneak peek WhiteHat Security offered this week at its new Web application security risk report, which the company will begin issuing quarterly starting in January. To put this in perspective, that's the same percentage of dentists who recommend sugar-free gum to their patients who chew gum. For any company worried about how a Web-site outage would affect their brand image this gift-buying season, if you haven't already audited your Web apps for vulnerabilities, it's already too late.

WhiteHat founder and CTO Jeremiah Grossman fingered the culprits during Wednesday's presentation. Cross-site scripting vulnerabilities were found in 71% of the 300 sites WhiteHat researched. Grossman pointed out that this percentage jumps to 90% when sites offering e-commerce were evaluated. No other category of vulnerability--including information leakage, predictable resource location, or content spoofing--was found in more than 30% of the sites WhiteHat evaluated.

Of course, not all vulnerabilities are created equal: more than one-third of the sites evaluated had a high level of severity, meaning the exploitation of a vulnerability could lead to the loss of customer data, passwords, or other critical information. Nearly three-quarters of the sites contained a vulnerability--in most cases a cross-site scripting problem--that would have a middling-level of impact on a business. Many sites have multiple vulnerabilities with different levels of severity.

"If there are 100 million Web sites out there, it's a Swiss cheese type of environment," said Grossman, who's the embodiment of converged IT and physical security, given that he's a well-respected security researcher and holds a blue belt in Brazilian jujitsu.

That's not to say the news is all bad. The prevalence of buffer overflows has dropped, to the point where they didn't even make WhiteHat's list. Grossman pointed out that buffer overflows aren't too common in custom-built Web applications, which were present in all of the sites evaluated.

Does this mean that e-tailers will continue to leave money on the table when potential customers are scared off by security risks? Gartner thinks so, saying that $1 billion is lost because of shoppers who refuse to spend money online, while another $913 million is lost because those who do shop online are wary of online security.

One obvious measure of relief is for businesses to regularly audit their Web applications for security vulnerabilities, particularly after changes have been made to those apps. Although no online shopping strategy is foolproof, consumers should stick with well-known retailers and use their credit cards rather than debit cards when making a purchase (gift cards are best, but you probably won't have many of those until after the holidays). They should also save all e-mails sent to them by the e-tailer acknowledging the purchase.

If a loss of confidence in online transactions seems like a big deal, that's because it is. Businesses can offer all of the discounts, personalization features, and customer conveniences they want, but that won't help them win back the business of a customer who's been burned by identity theft.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0972
Published: 2014-08-01
The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly prevent write access to IOMMU context registers, which allows local users to select a custom page table, and consequently write ...

CVE-2014-2627
Published: 2014-08-01
Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01 allows remote authenticated users to gain privileges for NetBatch job execution via unknown vectors.

CVE-2014-3009
Published: 2014-08-01
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct ph...

CVE-2014-3302
Published: 2014-08-01
user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.

CVE-2014-3534
Published: 2014-08-01
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a c...

Best of the Web
Dark Reading Radio