Share

Here are the top 10 website attacks

Cape Town – Cyber criminals can make running a website a nightmare, but a few tips could help mitigate common cyber attacks on your site.

“Many website owners only think about security after their site gets hacked, but knowledge is power: If you know what the threats are you can arm yourself appropriately and get one step ahead of the hackers,” said Myron Salant, web services product manager at Webafrica.

Here are his top 10 threats for websites:

1.    Injection
Injection happens when hostile data is sent to an interpreter as part of a query or command. This data tricks the interpreter, resulting in unintended commands and corrupt data. It’s a common problem in web applications, particularly with SQL injection.

2.    Cross-site scripting
When an application sends user-supplied data to a web browser without first validating or encoding it, cross-site scripting (XSS) can occur. This lets hackers execute scripts in the victim's browser that hijack user sessions or vandalise websites.

3.    Insecure direct object references
Web applications don’t always verify that the user is authorized for the target object. Without an access control check or similar protection, supposedly secure data can be accessed and stolen by attackers.  

4.    Cross-site request forgery
CSRF tricks a victim into submitting fake HTTP requests via cross-site scripting or image tags. It’s an issue for web applications that inadvertently allows hackers to predict the details of a transaction - for example, automatically-generated session cookies. Attackers create hostile web pages which generate forged requests indistinguishable from real ones.

5.    Insecure cryptographic storage
It’s hard to believe but many web applications still do not properly protect sensitive data such as credit card numbers and personal details. Attackers can easily access poorly encrypted data and use it to commit credit card fraud, identity theft and other data-related crimes.

6.    Failure to restrict URL access
An application may protect sensitive functionality only by not displaying relevant URLs to unauthorized users. By accessing those ULRs directly, attackers can exploit this weakness to perform unauthorised operations.

7.    Invalidated re-directs and forwards
Web applications may re-direct and forward visitors to other pages and websites without proper validation. Attackers can then re-direct victims to phishing or malware sites or use forwards to access unauthorised pages.

8.    Broken authentication and session management
Account credentials and session tokens are sometimes not properly protected. Attackers simply use stolen passwords, keys and authentication tokens to steal other users' identities and commit crimes.

9.    Security misconfiguration
Attackers exploit security configuration weaknesses at any level whether it’s the platform, web server, application server, framework or custom code. These flaws give attackers unauthorised access to default accounts, unused pages, un-patched flaws, unprotected files and system data.

10.    Insufficient transport layer protection
When applications fail to authenticate, encrypt and protect sensitive network traffic, they may support weak algorithms, use expired or invalid certificates, or execute commands incorrectly.

While knowledge about these attacks won’t guarantee that your site will be hack-proof, Salant argues that common sense security measures could block many attacks.

“If you are unsure about the right security solution for your website, speak to your web developer – as the cliché goes, prevention is better than cure.”

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.01
+0.0%
Rand - Pound
23.79
+0.0%
Rand - Euro
20.40
+0.0%
Rand - Aus dollar
12.44
-0.3%
Rand - Yen
0.12
+0.3%
Platinum
933.40
+0.9%
Palladium
995.00
+0.5%
Gold
2,339.75
+0.3%
Silver
27.61
+0.7%
Brent Crude
89.01
+1.1%
Top 40
68,437
0.0%
All Share
74,329
0.0%
Resource 10
62,119
0.0%
Industrial 25
102,531
0.0%
Financial 15
15,802
0.0%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders