Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 19, 2008

Web Security Scanning Is Paramount

RSS
Subscribe to Windows IT Pro | See More Internet Articles Here | Reprints

A couple of weeks ago, a few high-profile sites were hacked. The sites were properties of CNET Networks (ZDNet Asia, TV.com, News.com, and mySimon.com), TorrentReactor, and possibly others. The hack consisted of injecting an IFRAME tag into Web pages, and the IFRAME led to malicious content.

According to Dancho Danchev, who discovered the problem (see the URL below for more information), more than 100,000 Web pages were affected at the sites I mentioned. While news of these hacked sites spread rapidly, they certainly weren't the only sites affected.

http://ddanchev.blogspot.com/2008/03/zdnet-asia-and-torrentreactor-iframe-ed.html

I ran a query at Google and within seconds discovered that University of Pittsburgh, North Carolina State University, and the heavily trafficked Internet Archive (archive.org) were also infected--to name only a few. To see the extent of the damage yourself, type "intitle:iframe src" in the Google search field. To see if Google has indexed any of your sites' pages as being affected, type "site:yourdomainname in the Google search field. You can visit Google's Advanced Operators page at the URL below for more help with the intitle: and site: tags.

http://www.google.com/help/operators.html

This particular attack takes advantage of sites that don't sanitize user-supplied input, typically entered in a Web form. In these instances, the hacker enters a search query string along with the text of an HTML-based IFRAME tag. The sites' search engines cache the query string and the query results without removing unwanted content, such as HTML. As a result, the user-supplied query string (which contains HTML) becomes part of the cached Web pages. When someone lands on an affected cached page, the IFRAME injects unwanted content onto the page that could lead to malicious content. Compounding the problem further, the cached pages show up in search engines, which of course can lead to widespread infection.

In "Online Fraud Continues to Escalate" (February 20, at the URL below) I wrote about online fraud as reported by Cyveillance. The company had issued a report that stated that of all the phishing pages discovered in first quarter 2007, 34 percent were hosted on compromised existing Web sites. The recent widespread injection of IFRAME tags goes to show just how easily a site can be compromised. If you haven't scanned your sites for vulnerabilities, you should probably get started right away.

http://www.windowsitpro.com/Windows/article/articleid/98332/online-fraud-continues-to-escalate.html

Back in November 2007, I wrote about a comparative review of Web security scanners conducted by Larry Suto, an application security consultant. You can read about that report at the first URL below. Suto examined three commercially available Web application scanners: NT OBJECTives' NTOSpider (at the second URL below), Watchfire AppScan (at the third URL), and SPI Dynamic's WebInspect (now known as HP WebInspect, at the fourth URL). Suto found NTOSpider to be the superior product.

http://windowsitpro.com/article/articleid/97517/web-security-scanning-david-vs-goliath.html

http://ntobjectives.com/products/ntospider.php

http://www.watchfire.com/products/appscan/default.aspx

http://www.spidynamics.com/products/webinspect/

Last week, I learned that NT OBJECTives and eEye Digital Security have teamed up. eEye is now using NTOSpider as the core of its newly launched Retina Web Security Scanner (RWSS--at the URL below). I recently spoke with John-Marc Clark (VP of marketing at eEye) and JD Glaser (CEO at NT OBJECTives), and they told me that going forward, NT OBJECTives will handle the evolution of NTOSpider and that eEye will continue it to use as the basis for future upgrades to its RWSS product.

http://www.eeye.com/html/products/RetinaWebScanner/index.html

Clark said that eEye sees a significant demand for Web scanners, thus the company's entry into the field. Right now, RWSS is strictly a software offering. However, sometime in the next several months, the company will make RWSS available as a plug-and-play appliance. In the more distant future, the company might also offer RWSS as a Web-based managed service. Given what Suto found in his comparative analysis, eEye's RWSS product could be a strong solution.

There are certainly other Web scanning tools available for your consideration. Some of the tools I know about are listed below:

Acunetix Web Vulnerability Scanner

Cenzic Hailstorm

Web Security Auditor

N-Stalker Web Application Security Scanner 2006

Nikto 2 (open source)

Pantera (open source)

Parasoft WebKing

Sandcat

VForce

Wapiti (open source)

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Managing Virtual Sprawl

As some wise person once said, nothing is ever truly free. Such is the case with VMs, which can quickly mutate from a cost-reducing Dr. Jekyll into a time-consuming, profligate nightmare that would do Mr. Hyde proud. ...

What service packs and fixes are available?

...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...


Security Whitepapers St. Bernard Managed Protection Services

How to Evaluate and Choose a Messaging Archiving Solution

An IT Investment That Pays Real Dividends: Building ROI with your Email System

Related Events Black Hat USA, August 2-7

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Order Windows IT Pro VIP and SAVE!!
Get it all with Windows IT Pro VIP A $500+ value foir only $279!

Monthly Online Pass - Only $5.95!
Get instant access to 9,000+ articles from Windows IT Pro Magazine!!

Buy One Get One!
Order Windows IT Pro & Get SQL Server Magazine FREE!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.




ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

EXCHANGE 2007 Mastery Series – May 29, 2008
3 Info-packed eLearning seminars for only $99! Learn the pros and cons of your mailbox high availability options, see real-world examples of Transport Rules, and get started with basic PowerShell commands with Mark Arnold, MCSE+M and Microsoft MVP.

Windows IT Pro Master CD: Take the Experts with You!
Find the solutions you need in thousands of searchable articles, helpful bonus content, and loads of expert advice with the Windows IT Pro Master CD. Order comes with a 1-year subscription to the new, online articles posted every day!

SQL Server Magazine Master CD: Take the Experts with You!
Find the solutions you need in thousands of searchable articles, helpful bonus content, and loads of expert advice with the SQL Server Magazine Master CD. Order comes with a 1-year subscription to the new, online articles posted every day!

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes. And add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Become a fan of Windows IT Pro on Facebook
Join the Windows IT Pro fan club on Facebook. Chat with other IT Pros, upload your pictures, check out what's up n' coming in the next issue and more!



Become a Response Point Specialist
Earn more with the small biz phone solution from Microsoft.

Get Started with Oracle on Windows DVD
Learn how Oracle gives you the power to grow by providing a scalable, easy-to-use platform for running your business at a price you can afford.

Agent-less Remote Backup Service, Free 30 Day Trial
Award winning remote backup service at a competitive price with no min GB/month. Sign up Now!
Windows IT Pro Home Register About Us Affiliates / Licensing Press Room Media Kit Contact Us/Customer Service  
SQL Connected Home IT Library SuperSite FAQ Wininfo News
Europe Edition Office & SharePoint Pro Windows Dev Pro Windows Excavator 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing