stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Web Security Errors and an Open Source Revenue Opportunity







Web Security Errors and an Open Source
Revenue Opportunity

Web Security Errors and an Open Source
Revenue Opportunity
01/14/2003 06:32 PM

Web Security Errors I normally wouldn't blog this much but so many of us here do web development that its good for all of us to review these. Yes I know we all know better but I'd virtually guarantee that we all have done at least one of these in the last 24 months: Unvalidated parameters: Information from Web requests isn't validated before being used by a Web application. Attackers can use these flaws to attack backside components through a Web application. Broken access control: Restrictions on what authenticated users are allowed to do aren't properly enforced. Attackers can exploit these flaws to access other users' accounts, view sensitive files, or use unauthorized functions. Broken account and session management: Account credentials and session tokens aren't properly protected. Attackers who can compromise passwords, keys, session cookies, or other tokens can defeat authentication restrictions and assume other users' identities. Cross-site scripting flaws: The Web application can be used as a mechanism to transport an attack to a user's browser. A successful attack can disclose the user's session token, attack the local machine, or spoof content to fool the user. Buffer overflows: Web application components in some languages that don't properly validate input can be crashed and, in some cases, used to take control of a process. These components can include CGI, libraries, drivers, and Web application server components. Command injection flaws: Web applications pass parameters when they access external systems or the local operating system. If an attacker can embed malicious commands in these parameters, the external system may execute those commands on behalf of the Web application. Error-handling problems: Error conditions that occur during normal operation aren't handled properly. If an attacker can cause errors that the Web application doesn't handle, he or she can gain detailed system information, deny service, cause security mechanisms to fail, or crash the server. Insecure use of cryptography: Web applications frequently use cryptographic functions to protect information and credentials. These functions and the code to integrate them have proven difficult to code properly, frequently resulting in weak protection. Remote administration flaws: Many Web applications let administrators access a site using a Web interface. If these administrative functions aren't very carefully protected, an attacker can gain full access to all aspects of a site. Web and application server misconfiguration: Having a strong server configuration standard is critical to a secure Web application. These servers have many configuration options that affect security and aren't secure out of the box. [_Go_] The full report is here. Nice job guys. Thank you. And Just One More Oh and I'd also kick in one other security glitch that's related to these but not specifically mentioned: Installing Open Source applications on the quick. You know the drill -- you grab some code, install it and then poof! The client is running it and is happy so you kinda ignore it. And you don't realize that the default installation leaves the password in the clear! Think I'm kidding? For example a lot of php applications use .inc for include files as their extension so config.inc is viewable by anyone who knows it exists. A Chance for Open Source Revenues Although I have no actual metrics on this I suspect it is quite common. Now this makes me think that a possible revenue opportunity for Open Source authors is something like "Security Check", for $99 or $X (per server), I'll check over your installation and make sure you don't have any holes. Given that a lot of Open Source applications are rolled into hosting / consulting, it would be relatively easy to pass this type of cost onto the ultimate customer.




This is a GrokNews Entry: (what is grok?)





Similar Items

Web Security Errors and an Open Source Revenue Opportunity

Grok Headline matches for Web Security Errors and an Open Source Revenue Opportunity

Open source opportunity, open source
risk


Open source opportunity, open source
risk
09/22/2004 10:44 AM
I've been traveling more than usual lately, and while on the road I've been working my way through the ITConversations audio archive. It's full of gems, and one of them is Doug Kaye's interview with Philip Greenspun. While discussing the ArsDigita flameout, Greenspun offers insightful perspectives on the opportunity, and the risk, of open source as a business model. ...

Open source apps are seen as new
business opportunity


Open source apps are seen as new
business opportunity
04/05/2005 05:19 PM
SAN FRANCISCO - The next wave in open source development is applications, which presents opportunities for open source vendors to focus on the small- and medium-sized businesses that established commercial vendors cannot reach, said Larry Augustin, CEO of Medsphere Systems and a founder of VA Linux Systems, on Tuesday.

Open source apps are seen as new
business opportunity (InfoWorld)


Open source apps are seen as new
business opportunity (InfoWorld)
04/05/2005 05:18 PM
InfoWorld - SAN FRANCISCO - The next wave in open source development is applications, which presents opportunities for open source vendors to focus on the small- and medium-sized businesses that established commercial vendors cannot reach, said Larry Augustin, CEO of Medsphere Systems and a founder of VA Linux Systems, on Tuesday.

Reiser4 file semantics: An opportunity
for open source


Reiser4 file semantics: An opportunity
for open source
09/09/2004 05:28 AM
Some people feel that the Reiser4 file semantics will present problems for the Linux community. In a nutshell, every file now looks like a directory and can be opened as a directory. The names in that directory are not new files but metadata associated with the file, as documented by Hans Reiser on the Namesys site. The immediate response in the community has been that this is too big a change and should be withdrawn. I humbly propose that this is a challenge we should face head on now or we may not have an opportunity to do so in the future.

Large opportunity for revenue-assurance
(RA) external spending as carriers
estimated revenue leakage to be as much
as 15 percent.


Large opportunity for revenue-assurance
(RA) external spending as carriers
estimated revenue leakage to be as much
as 15 percent.
07/14/2004 03:05 AM
[PRWEB Jul 14, 2004]

Top Open-Source Security Applications


Top Open-Source Security Applications 06/17/2005 03:37 PM

Open Source Law and National Security


Open Source Law and National Security 09/13/2004 05:19 AM
How many paragraphs of rules and regulations can a society have before no one can predict how it will respond to critical situations? The answer, as demonstrated on 9/11/2001 is: "Not very many." Lawyers need to go open source and let the public bang on their code.

Defending Open Source Security


Defending Open Source Security 02/14/2004 08:03 AM

Open Source Security: Still A Myth


Open Source Security: Still A Myth 09/17/2004 11:52 AM

Open Source a National Security Threat


Open Source a National Security Threat 07/27/2004 11:22 AM

Microsoft, Open Source and National
Security


Microsoft, Open Source and National
Security
04/23/2004 01:24 AM
Two weeks ago, I wondered out loud about the top 10 worst IT business decisions ever made and nominated HP's decision to follow DEC down the road to oblivion for top spot. Today I'd like to suggest that the U.S. Defense Department's continued use of Microsoft's software is likely to top a future list of this kind. The equation here is simple. First, recognize that Microsoft's software security depends crucially on keeping its source code secret. That's not a comment from an anti-Microsoft bigot -- it's the testimony given under oath by Microsoft vice president Jim Allchin. Even limited release of Microsoft's code, Allchin told judge Colleen Kollar-Kotelly's federal court in May 2002, would threaten national security because the code is both seriously flawed and widely used in the Defense Department. But consider that only nine months later, in February 2003, Microsoft announced an agreement giving communist China full access to the source code for Windows and related tools.

Cryptography and the Open Source
Security Debate


Cryptography and the Open Source
Security Debate
07/20/2004 02:34 PM

New flaws foul open-source security


New flaws foul open-source security 06/10/2004 08:05 AM
ZDNet Jun 10 2004 12:14PM GMT

Security holes splatter Open Source


Security holes splatter Open Source 06/11/2004 04:54 AM

An eye opener on open source Internet
security


An eye opener on open source Internet
security
07/26/2004 08:46 AM

DOES open source software enhance
security?


DOES open source software enhance
security?
03/06/2004 02:04 AM

Missing Open Source Security Tools?


Missing Open Source Security Tools? 06/28/2004 06:16 PM

Two Open-Source Databases Spring
Security Leaks


Two Open-Source Databases Spring
Security Leaks
05/20/2004 08:20 PM
A researcher has found critical flaws in CVS and Subversion; updates have been posted.

Security fears push users to open source


Security fears push users to open source 12/05/2003 05:32 PM
Personal Computer World Dec 5 2003 4:19PM ET

More flaws foul security of open-source
repository


More flaws foul security of open-source
repository
06/09/2004 05:29 PM

Apple Cites Open Source Core Security


Apple Cites Open Source Core Security 09/02/2004 12:41 AM
Slashdot Sep 2 2004 4:37AM GMT

Security flaws could corrupt open source
databases


Security flaws could corrupt open source
databases
05/20/2004 04:15 AM

Open-Source Security Tools Touted at
InfoSec


Open-Source Security Tools Touted at
InfoSec
04/05/2005 10:21 PM
A security consultant encourages cash-strapped businesses to consider open-source security tools and utilities to help cope with the increasing spate of malicious hacker attacks.

NOSI, the Nonprofit Open Source
Initiative, announces the release of its
new guide "Choosing and Using Open
Source Software: A Primer for
Nonprofits."


NOSI, the Nonprofit Open Source
Initiative, announces the release of its
new guide "Choosing and Using Open
Source Software: A Primer for
Nonprofits."
02/17/2004 11:57 PM
As per a recent post, I love to see (and hope to one day do it myself) Open Source Software in Non-Profits. Seems http://www.nosi.net found my post: http://thelostolive.net/tlo/comments.php?id=1786_0_1_0_C And commented the release of its new guide "Choosing and Using Open Source Software: A Primer for Nonprofits." And now in their own words: ___snip____ -- From: Katrin Verclas Email: steering (a) nosi.net Hi, Kevin - NOSI actually just released a new...

Chairman Bill's 'magic spam cure' - a
revenue opportunity?


Chairman Bill's 'magic spam cure' - a
revenue opportunity?
01/28/2004 07:29 AM
Analysis

Database, Security, Storage Are Next
Layers For Open Source Commoditization


Database, Security, Storage Are Next
Layers For Open Source Commoditization
01/19/2004 09:36 AM

Announcing Windows Open Source Security
Framework - SafetyNet


Announcing Windows Open Source Security
Framework - SafetyNet
09/23/2004 11:51 PM

Open source Internet protocol security
project gets nod from Novell


Open source Internet protocol security
project gets nod from Novell
06/17/2004 03:31 AM

Open-source activist Bruce Perens joins
open-source defense group


Open-source activist Bruce Perens joins
open-source defense group
05/07/2004 04:33 PM
A key leader in the open-source software movement has been appointed to the board of Open Source Risk Management, which is defending the legal standing of open-source software.

Websites Worldwide Get a Unique
Opportunity to Generate Recurring
Revenue with the RatePubs Global
Network.


Websites Worldwide Get a Unique
Opportunity to Generate Recurring
Revenue with the RatePubs Global
Network.
07/13/2004 03:08 AM
The RatePubs Network solves the two main problems for websites; how to get fresh, local, interactive content, and how to generate a recurring revenue stream. Pubs and bars worldwide will also benefit with a cost-effective targeted advertising channel. [PRWEB Jul 13, 2004]

Web Accessibility for the Web Hosting
Industry. Widerweb, a new revenue and
service opportunity announced by Moore
Innovations Ltd.


Web Accessibility for the Web Hosting
Industry. Widerweb, a new revenue and
service opportunity announced by Moore
Innovations Ltd.
08/17/2004 02:00 AM
WiderWeb is a new service and revenue opportunity for web hosting companies. It enables web hosts for the first time to aid customers in making their web sites compliant with accessibility legislation. The WiderWeb web accessibility gateway provides an automated transcoding function to change a standard web site into a W3C accessible version, on a per user request basis with full session control. It also allows users to customise the gateway controls so that sites are delivered in a truly personalised fashion. [PRWEB Aug 17, 2004]

Homeland Security Executive Don L.
Rondeau is named as the Transportation
Security Advisor for The International
Association for Counter Terrorism and
Security Professionals."This is a
volunteer appointment and an opportunity
to serve"Don L. Rondeau


Homeland Security Executive Don L.
Rondeau is named as the Transportation
Security Advisor for The International
Association for Counter Terrorism and
Security Professionals."This is a
volunteer appointment and an opportunity
to serve"Don L. Rondeau
08/27/2004 01:27 PM
In an effort to ensure that the private sector is fully engaged in the counter terrorism discussion. The premiere counter terrorism association names one of the private sectors best and brightest to lead the efforts of its Transportation Security /Counter Terrorism efforts. [PRWEB Aug 25, 2004]

Do You Suffer from Open Source Phobia? -
six reasons you might relent and be
ready for an extreme makeover - OPEN
SOURCE - Magazine - Darwin Magazine


Do You Suffer from Open Source Phobia? -
six reasons you might relent and be
ready for an extreme makeover - OPEN
SOURCE - Magazine - Darwin Magazine
03/08/2004 11:20 PM
http://www.darwinmag.com/read/030104/open.html ASK A GROUP OF corporate IT leaders whether they'd rather stick their arms into a box of tarantulas or allow open source software (OSS) on their networks, and odds are most would start rolling up their sleeves. Not to do any downloading, either.

Slashdot on Open Source Ideas and Open
Source Life


Slashdot on Open Source Ideas and Open
Source Life
06/23/2004 08:27 PM
As Canada protects the patents on genes, Download Aborted wonders whether the genetic code should be considered Open Source. It's slashdotted here. And as atonement for saying something positive about the people at Microsoft — man, you folks are rough! — here's some slashdottism about the anti-Open Source think tanks that Microsoft is funding. (But I still like the Microsofties I've met. So there.)...

Online Crime, Compliance Issues, Worker
Mobility, SOA, and Open Source Are
Mega-Trends for IT Security, Says Burton
Group


Online Crime, Compliance Issues, Worker
Mobility, SOA, and Open Source Are
Mega-Trends for IT Security, Says Burton
Group
07/13/2004 05:36 PM

Open source process for open source
development


Open source process for open source
development
04/05/2005 11:50 AM

Sun has given every possible indication that Open Solaris will be run as a true open source project. The latest indication is the make-up of the board of directors: Casper Dik, Roy Fielding, Al Hopper, Simon Phipps, and Rich Teer. (via Simon Phipps - congrats Simon!)


Symantec Norton Internet Security
AutoProtect Errors


Symantec Norton Internet Security
AutoProtect Errors
03/30/2005 11:39 AM
Addict3d.org Mar 30 2005 2:55PM GMT

Gates: Security can be an asset and
opportunity


Gates: Security can be an asset and
opportunity
07/29/2004 01:50 PM
REDMOND, WASHINGTON - Microsoft Corp. is looking to turn security from a "concern" into a "business asset" and "opportunity" for the company through software enhancements and management applications, the software maker's chairman and chief software architect Bill Gates said Thursday.

BE Conference 2005 Registration Now
Open; Go to www.be.org to Register for
Once-a-Year Learning Opportunity


BE Conference 2005 Registration Now
Open; Go to www.be.org to Register for
Once-a-Year Learning Opportunity
04/05/2005 06:16 AM
ZDNet India Apr 5 2005 10:24AM GMT
Grok Description matches for Web Security Errors and an Open Source Revenue Opportunity
GrokA matches for Web Security Errors and an Open Source Revenue Opportunity

Web Security Errors and an Open Source Revenue Opportunity

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

It's crunch time for
Apple - again

Tolkien saga helps
Bloom's career
blossom

Death Valley
pictures

404 error
XSLT-process 2.2 for
Emacs released

Safari and Chimera
The Hacker FAQ
Jeff Turner as
Cocoon committer

Another Cocoon
committer: Michael
Melhem

Free software Java
platforms

My new job at Google
New weblogger:
Costin of Tomcat
fame

Weapon of the Week
Brief: Hobbyist
gives up
WindowsXP.nu domain
to Microsoft

Blogger Heads to
Google

Google responds to
search ranking suit

Google Fights
Lawsuit Over Search
Results

Semantic
obsolescence

W3C Team Presents at
PAGE2003 in Tokyo,
Japan

Inheritance
Considered Harmful
(PDF)

News Server Glitch
Angers AOL Customers

Hi. I'm Scott and
I'll Be Your
Internet Agent for
Right Now

Read Keith Today
HTML to text
converter and markup
remover

Hobbyist surrenders
WindowsXP.nu domain
to Microsoft

New University
website to debut
late this month

Microsoft Gains
Control of Windows
Domain

Scalable Vector
Graphics (SVG) 1.1
and Mobile SVG Are
W3C Recommendations

NewGate Internet
Wins Five New
Clients for Search
Campaign ...

Internet 'robots' to
catch uni cheats

geoURL, RSS, and
PHP-Nuke

Squirrel Mail
Alternative Anyone?

Alexa Toolbar
Suggested Links Come
From Where?

Getting in the
Google Image Engine

Can You Trust Your
Web Host?

K-What?
Five steps to
designing a secure
system with TCB

China's human rights
practices coloured
by party congress:
rights ...

AllTheWeb Adds
Espotting

Keyword Lists at
Bottom of Page

Flash MX and Special
Characters

Tracking E-A-Friend
Email Forwarding

Three Inseperable
Friends Want to
Start a Business

Style and Internal
vs. External Links

Build a
fine-grained,
event-based
framework for your
applications

Two SQL Server
maintenance tips to
help you service
like a pro

Help business
drivers identify the
reports they need

Servlets offer a
simple alternative
to CGI

Easily configure Red
Hat 8 and Apache

Tips for managing
Section 508 testing

what is grok?