April 23, 2008
In This Issue
Tech Talk

The Need for Web Application Scanning

Any application developed by a human is very likely (albeit certainly) to have some type of vulnerability in it. This becomes even more of an issue when the software being developed does not have any IT or security functionality at all, causing the developers assigned to the project to typically not have deep experience in secure coding practices. Although this issue occurs in any application, from the lowest embedded assembly code to the highest level .NET interpreted code, one location seems to have the least amount of secure coding practices with the maximum exposed surface: web applications.

There are numerous examples of how web applications have caused innumerable amounts of damage to companies. SQL injections reveal customer information; XSS breakdown customer reliability in the vendor; remote file include vulnerabilities allow attackers to take over the web server. It would only take a few minutes on any news website searching for web breaches to realize that this new “frontier” may actually be the most dangerous frontier thus far in our computer evolution.

With the rise of “Web 2.0” applications, we are seeing a large trend towards EaaS (Everything as a Service). Every major software company right now likely has a project to enable previously console applications to have some sort of web-based front-end. Customers are driving this evolution, wanting fewer applications installed in their desktops and more hosted in a “secure” and stable offsite location from the vendor. Although we cannot disagree that this is a very cool evolution of software, we are again seeing the rapid advancement of technology move a bit quicker than the security practices surrounding it.

Web developers often times are focused on providing a very interactive experience to the end user. Especially in the “Web 2.0” world, many of the applications being developed have their contact purely developed by end-users. As was the case with all of the different vulnerabilities seen within desktop and server applications, user-input is typically the entry point of an attacker to deliver an exploit for a vulnerability. The modern-day web developers typically do not understand vulnerabilities, security issues, or the attackers that are trying to exploit their applications. Instead, they consistently focus on ensuring that: 1 – the product is very powerful, cool, or innovative; 2 – the product works. Rarely do you see the mandatory other step adopted recently by so many large desktop/server developers being 3 – is the product secure?

Commonly VERSA articles are meant to show the InfoSec warriors how to protect themselves. However, in this case, many of the VERSA readers are unlikely to be the main developers of web applications. Therefore, the call to action will shift from a “protect” to an “evangelize” need. Those that know security must drive the protection of web applications until the web developer community starts commonly practices secure coding practices.

There are a few processes and tools that can help security evangelists and web application developers ensure that their applications are properly secured from the most common vulnerabilities.
Knowledge – As was the case with standard memory-based vulnerabilities a decade ago, developers are not privy to all of the different types of vulnerabilities that are exposed within web applications and how to ensure that their code does not allow them to be exploited. This knowledge can be derived from many resources including: Web Application secure development books, security conference briefings, and tools being deployed by attackers. One notable place to learn a great deal is the OWASP initiative, a conglomeration of web-based application security tools and documentation.

Testing
Perhaps the most powerful way to get through to a developer with the implications of a vulnerability is to show them with a demonstration attack. There are many different web-application scanning tools on the market (some being better and more robust than others of course) that can scan a web application for vulnerabilities, and actually demonstrate the vulnerability at the end. For the large web-app testing, there are secure exploit toolkits available as well that can help to identify the potential result of the attack, such as the data that might have been revealed during a SQL injection attack. If testing for vulnerabilities is done during the development lifecycle, developers will become much more familiar with what web application vulnerabilities have the potential to do, while also ensuring that they learn better practices for future development projects.

Constant Verification
The web application vulnerability realm is a rather young one, and new types of vulnerabilities and exploits are being discovered often. Because some legacy web applications might not have been scanned for the latest and greatest vulnerabilities, it is very important that security teams regularly test web applications from the outside point of view (similar to a penetration test) with a cutting-edge web application scanner to verify that no newly discovered threats were pre-existing on their applications. Some companies of course offer this as a service to keep the weight off of the internal security teams as well.

Web applications are rapidly becoming the most powerful delivery method of content for the future. Unfortunately, many security vulnerabilities are being discovered that could cause issues for developers if they do not ensure that they understand and test for vulnerabilities within their web applications. This is a quickly emerging issue that will gain even more importance as the emergence of web applications continues.

Source: Andre Derek Protas, Director of Research and Preview Services

News & Articles
The following articles represent the opinions of their respective authors. They do not necessarily represent the opinions of eEye Digital Security.

eEye Digital Security REM Security Management Appliance 1505
"Put this 1U security appliance in your small business's equipment rack and you may worry about your budget, but not about your security. The eEye Digital Security REM Security Management Appliance 1505 is expensive for small businesses, but it does a very good job of providing integrated vulnerability assessment along with security- and incident-management services." Full Article

Web Security Scanning Is Paramount
"A Web Exclusive from Windows IT Pro writer Mark Joseph Edwards on the importance of Web Security Scanning" Full Article

eEye to Add Retina Web App Scanner
"New software is rebranded version of NT Objectives's NTOSpider" Full Article

View All Media Coverage
"eEye and its security solutions have been covered by numerous press and media associations." Full Article

Reader Q&A

Q: During March madness, I noticed a large spike in surfing sports websites from the office. What can we do to avoid some of this loss in productivity?

A: While we at eEye enjoy sports as well; we understand that this might cause some business issues. We would suggest some sort of web-filtering. This can either be through a network-based proxy, or through some sort of client-side protection mechanism. eEye’s Blink comes pre-loaded with example protection rules against some social networking sites that could be replicated for such incidents...check it out!

Have a question you would like answered? Send it to versa@eEye.com, and win an eEye t-shirt if we select your question for an upcoming newsletter.

Announcements

eEye Expands Line of Security Management Appliances
Retina 651 Scanner Combats Cyber-Crime; Aids SMB and Large Organizations Full Article

eEye Unveils Retina Web Security Scanner
Partners with NTO on Integrated Threat Management Suite Full Article

eEye Security Solutions Used by Over Half of the Fortune 100
More than 50 of the Fortune 100 Use eEye Digital Security Products & Solutions Full Article

View All Articles and Announcements
eEye and its security solutions set have introduced a number of newsworthy security advisories and security technology deliveries that have been covered by the press. Select any of the links below to view more details regarding our most recent articles and announcements. Full Article

Etcetera

Stay Up-to-Date with eEye Research
eEye Research has seen some staggering results from the recent influx in Blink Personal/Neighborhood Watch users. This data is offering eEye Research a distinct insight into host-based vulnerability and attack trends to offer enhanced protection into Blink. Keep an eye on the eEye Research Portal http://research.eeye.com/ for future projects that have arisen because of the mass use of Blink Personal including Neighborhood Watch reports and attack trends. More

Vulnerability Expert Forums
The monthly Vulnerability Expert Forum focuses on recently announced critical vulnerabilities - from Microsoft and other software vendors. eEye's Internet security experts will describe the actions necessary to protect your systems from the threats that target these vulnerabilities. More

HOW TO SUBSCRIBE
To subscribe to this and other eEye newsletters, please visit: http://www.eeye.com/html/resources/newsletters/subscribe.html

FEEDBACK
The eEye newsletter staff welcomes any comments, questions or suggestions from our readers. We hope that you will not hesitate to contact us with any feedback you may have. Send all feedback to versa@eeye.com.

DISCLAIMER
The information within this newsletter may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties with regard to this information. In no event shall the author be liable for any damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk.

NOTICE
Permission is hereby granted for the redistribution of this newsletter electronically. It is not to be edited in any way without the express consent of eEye. If you wish to reprint the whole or any part of this newsletter in any other medium excluding electronic medium, please email versa@eeye.com for permission.