_Application Vulnerability
A Web application vulnerability is a security weakness in a website or its environment. Vulnerabilities usually occur when there is a site development or implementation flaw.
Depending on the type of flaw, malicious users might exploit vulnerabilities, which could change the website, collect visitor's personal information, steal visitor's browser data `or perform other harmful actions to the site or visitors. Vulnerabilities can be difficult for Web developers to locate because, in many cases, they do not affect the intended use of the application. Plus, there are hundreds of "known" vulnerabilities and new ones are discovered daily. For example: If a log-in page submits credentials in "clear text," the log-in information is sent to the server unencrypted. Visitors can log in and might not notice any issue. Attackers who discover the "clear text" vulnerability might try to intercept another visitor's log-in information and exploit it. You can resolve this issue by adding an SSL certificate to the website which encrypts transactions between visitors and the site. To avoid vulnerabilities regularly evaluate your site and its environment for flaws. Also, use a daily vulnerability scanner, such as Website Protection Site Scanner, to detect issues. Hackers today have an ever increasing list of weaknesses in the web application structure at their disposal, which they can exploit to accomplish a wide variety of malicious tasks. New flaws in web application security measures are constantly being researched both by hackers and by security professionals. Most of these flaws affect all dynamic web applications whilst others are dependent on specific application technologies. In both cases, one may observe how the evolution and refinement of web technologies also brings about new exploits which compromise sensitive databases, provide access to theoretically secure networks, and pose a threat to the daily operation of online businesses. Web Application Vulnerabilities
Article source: http://help.godaddy.com/article/4486?isc=&locale=en Article source: http://www.acunetix.com/vulnerabilities/ |
