Security - CIOInsight
Home arrow Security arrow Page 10 - Black Hat 2010: 10 Security Hotspots for CIOs
RECENT NEWS



CIO STRATEGY
The Perfect IT Book for the Business?

Parkinson needs a book that explains IT to the business. Got any suggestions?    

  Security


Black Hat 2010: 10 Security Hotspots for CIOs



By Sean Martin


  Table of Contents:
  1. Black Hat 2010: 10 Security Hotspots for CIOs
  2. Cloud Security Challenges
  3. Virtualization Pitfalls
  4. Risk Management: Depth or Breadth?
  5. Collaboration Carries Exploit Potential
  6. Enterprise Mobility Has Inherent Risks
  7. Open-Source Tools Carry Dangers
  8. System Hardening: Its Time Has Come
  9. SSL and HTTPS: Not So Strong?
  10. Web-Based Attacks Gain Power
  11. Social Networking Hides Hazards

The annual Black Hat Technical Security Conference is known for its colorful audience, many of which are self-described hackers. Here are the 10 hottest security topics from the event, plus actions every CIO can take to minimize enterprise risks.

Rate This Article:
Add This Article To:

Black Hat 2010: 10 Security Hotspots for CIOs - Web-Based Attacks Gain Power


( Page 10 of 11 )

Web-based attacks remain a hot topic. The Google Web Toolkit (GWT), for example, allows for some of the quickest, slickest web-based applications to be built today. But the framework, built entirely in JavaScript, provides significant support for remote procedure calls (RPC). While the engineer has the option to securely implement the RPC, it turns out that insecure remote functionality is very common via the GWT. And, you guessed it, these insecure implementations result in vulnerabilities that can be exploited to compromise these pretty, slick web applications.

Even with the PCI requirement to store cardholder data in an encrypted fashion, hackers have found ways to bypass database encryption methods by using SQL injections through web applications in order to gain an escalation of privilege. With these newly acquired SYS-level privileges, hackers can obtain clear text data from an Oracle database backend – regardless of whether or not the data is stored as encrypted content in the database.

The standard response to these types of risks include employing web filtering, application control, and vulnerability assessment technologies, coupled with selecting securely built applications from your business solution vendors. If your organization is building custom web applications, these applications should be built using secure coding best practices while leveraging tools and services to validate that what has been built was done securely.



 
 
>>> More Security Articles          >>> More By Sean Martin
 


FEATURED SPONSORED VIDEOS

FEATURED SPONSORED ARTICLES

Erasable E-Paper Saves Trees, Cuts Costs

Why Smart Companies Should Adopt the Lessons of Gaming

Interest in Mobile WiFi Hotspots Fuels New Solutions

A Closer Look at Public Cloud Security

View More Articles

  Brought to You By
Click Here




EDITORS' PICKS

LATEST STORIES


Advertisement
FEEDBACK
Ziff Davis Enterprise RSS Feeds

Sponsored Links
  • Try Windows Azure free for 90 days

  • Introducing the world's first family of systems with integrated expertise

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 77% of the Fortune 500 Manage Content Securely with Box.
  • Leverage your virtual computing environment with Dell.
  • Build an IT Infrastructure That Delivers the Future
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • eWEEK Quick LInks

     
    Close this advertisement