Archive for the 'XSS Errors' Category

24
Nov
09

SQL Injection

Is your website vulnerable to a SQL Injection attack? Has your website been hacked recently?

These are questions you should be asking is you operate or own your own website.

To quote USAToday: Website-infecting SQL injection attacks hit 450,000 a day! What does this mean to you? It means that your website might be a target. Through our independent research we have found SQL injection exploits and XSS vulnerabilities throughout every kind and sort of website. On might say their website is fine because they don’t collect credit card information but that’s simply untrue. There are several reasons why an attacker might hack your website:

  1. Profit. An attacker might attack your website in order to gain access to sensitive information such as credit card numbers or personal information which might compromise your clients/visitors identity resulting in identity theft.
  2. Defacement. This form of attack is meant to simply take over your website and replace pages with hacked pages. This is a form attack is bragging about hacking ability and typically circulates within the hacking community. You can find out more about these types of hacks at the Hacker Bragging post located at www.zone-h.org.
  3. Large Scale. Most of us won’t ever see this form of hack or hack attempt since it’s normally initiated for wide scale profit reasons and typically the focus or larger groups or organizations. The targets are typically large companies with either huge data banks or private/financial records which are either sold on a black market or used to harm large companies and/or their reputations.

The best way to ensure your website is protected is to have a penetration test run. These tests can check for vulnerabilities which a hacker might use in order to gain access to your website of the server your website is hosted on. You may also want to run a full penetration test even if you have a PCI Compliance badge on your website to ensure your client’s safety and security. Most PCI Scans are not heuristic so they are not intended to perform a deep scan.

Secure your website, secure your client information today by scanning your website. Click here.




May 2012
M T W T F S S
« Nov    
 123456
78910111213
14151617181920
21222324252627
28293031  

Months

Recent Entries


Follow

Get every new post delivered to your Inbox.