The Web Hacking Incidents Database 2009 Bi-Annual Report
by Breach Security

> View this White Paper now

Published on: 08/03/2009
Type of content: White Paper
Length: 6
Price: FREE

Overview
The web hacking incident database (WHID) is a project dedicated to maintaining a list of web application-related security incidents. The WHID's purpose is to serve as a tool for raising awareness of the web application security problem and provide information for statistical analysis of web application security incidents. Unlike other resources covering website security, which focus on the technical aspect of the incident, the WHID focuses on the impact of the attack. To be included in WHID an incident must be publicly reported, be associated with web application security vulnerabilities and have an identified outcome.


An analysis of recent web hacking incidents performed by Breach Security Labs shows that Web 2.0 sites are becoming a premier target for hackers. Based on analysis of recent 'web hacking incidents of importance,' Breach Security Labs found that:


  • The first half of 2009 showed a steep rise in attacks against Web 2.0 sites. This is the most targeted vertical market with 19% of the incidents.
  • Organizations have not implemented proper web application logging mechanisms and thus are unable to conduct proper incident response to identify and correct vulnerabilities.
  • Attack vectors exploiting Web 2.0 features such as user-contributed content were commonly employed.


Check out this brief report to learn more about recent web hacking incidents and Web 2.0 vulnerabilities.

> View this White Paper now

Solution Center

Innovations in operating system virtualization and server hardware permanently changed the footprint, architecture, and operations of data centers. As such, these innovations have also had a significant impact on how auditors must... More...

May 24, 2011

Most enterprise network perimeters are protected by firewalls that block unsolicited network-based attacks. Most enterprise workstations have antivirus protection for widespread and well-known exploits. And most enterprise mail... More...

May 18, 2011
Other content by this company
The Good, Bad and Necessary: The Complete Guide to PCI 6.6 Success by Breach Security
This resource provides IT security professionals with the information needed to understand PCI compliance and specifically, one of the standard's latest requirements, 6.6. In addition, the paper offer tips for successful PCI 6.6 compliance and highlights...