How Secure Are Your Web Applications?

31 October 2018by Abdallah Alhajeid

Web applications and web sites deliver accessible and powerful services to consumers and businesses throughout the world. At the heart of modern banking, e-commerce and cloud-based IT provision, they are an attractive and easy target for cyber criminals. In common with all software, web applications contain vulnerabilities which can be exploited by a hacker to steal confidential information directly or to create a transmission platform to infect another computer with malware.

 

What are web application vulnerabilities?

The Open Web Application Security Project (OWASP) is an industry-recognised community of software developers dedicated to helping organisations develop and maintain the security of applications and APIs. Published every two years, the OWASP Top Ten Application Security Risks report provides a definitive list of key software weaknesses.

 

OWASP Top Ten 2017 (updated Jan 2018) Application Risks

A1 – Injection A6 – Security Misconfiguration
A2 – Broken Authentication A7 – Cross Site Scripting (XSS)
A3 – Sensitive Data Exposure A8 – Insecure Deserialization
A4 – XML External Entities (XXE) A9 – Using Components with Known Vulnerabilities
A5 – Broken Access Control A10 – Insufficient Logging & Monitoring

 

Code injection is the number one problem

Databases that contain valuable personal and financial data have always been a prime target for cyber criminals. Code attacks such as SQL Injection allow attackers to spoof identity, tamper with existing data and cause repudiation issues such as voiding transactions or changing balances. They can also allow the data to be deleted, made unavailable or transferred to another location. Code injection attacks work by introducing data into a vulnerable application (particularly a command or query) and changing the course of the program execution. Injection flaws are found in SQL, LDAP, XPath, OS commands, XML parsers and SMTP headers.

 

Cross-site scripting (XSS)

Cross-site scripting is the second most prevalent issue in the OWASP Top 10 and is found in around two-thirds of all web applications. XSS enables attackers to inject client-side scripts into web pages viewed by web browsers. Frequent targets include sites that let users share content such as blogs, social networks, video sharing platforms and message boards. XSS vulnerabilities are particularly common in web browsers and have been identified in earlier versions of Word Press and its related plug-in applications.

 

How do you identify web vulnerabilities?

Penetration testing or ethical hacking is the key technical audit tool for the cyber risk assessment of web sites and their applications. A web application penetration test is designed to identify security weaknesses which have been unknowingly added by software developers as they design, code and publish their software. It will also discover security flaws in the web servers and web browsers used to run the applications.

 

What is a web application penetration test?

Performed with the permission of the software owner, a web application penetration test uses a series of automated and manual processes to identify vulnerabilities and demonstrate how they can be used to facilitate a cyber attack. Measures and controls to prevent or mitigate the impact of an attack are recommended for each major vulnerability. This information is delivered in a Penetration Test Report which is used as a practical guide to improving the security of the software application. It is also used to meet the organisational requirements for compliance to standards such as the Payment Card Industry Data Security Standard (PCI DSS) and ISO 27001.

 

Penetration test report

A web application penetration test report should include an overview of the tests performed, an executive management summary, a technical summary and a technical detail section. The National Cyber Security Centre recommends the use of Common Vulnerability Scoring System (CVSS) to describe characteristics of a vulnerability and define a numerical score reflecting its potential severity of impact. Remedial activities that prevent or mitigate the cyber exploits associated with each vulnerability should be identified and linked to references that provide further detailed background information.

 

The benefits of a web application penetration test include:

  • Develop and support strong authentication and access control
  • Identify common software vulnerabilities that include SQL injection and XSS
  • Prevent unauthorised access to web servers and databases
  • Ensure cyber security is assessed at each stage of the software development life cycle (SDLC)
  • Ensure compliance to data security standards that include PCI DSS and ISO 27001

 

 

——————–

Wizard Cyber offers a range of penetration testing services including network, wireless and web application assessments. Our tests are performed by an experienced team who are certified by CREST (the Council of Registered Security Testers) and have over 15 years of combined experience in the field of information assurance and penetration testing. They are guided by the best practice testing methodology as published by OWASPOSSTMM, CVSS and the SANS Institute.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation