Date: 2nd February 2012
February 2nd 2012 - Two thirds of web applications tested by security consultants at Context Information Security in 2011 were found to be at risk from cross-site scripting and nearly one in five applications risked attacks by experienced SQL injections, according to the new Context Web Application Vulnerability report published today. The research also found that web applications developed for government, financial services and law and insurance sectors had the greatest increase in vulnerabilities. The findings come from penetration tests carried out on almost 600 hundred custom-built web applications. In total, Context discovered some 8,000 vulnerabilities , reflecting an increase in the average number of different security issues affecting each application from 12.5 to 13.5 between 2010 and 2011.
Server misconfiguration and information-leakage topped the list of vulnerability categories that also included authentication, session management and authorisation weaknesses along with encryption vulnerabilities. The only exception to the upward trend was input validation weaknesses, most likely due to the increased use of frameworks that offer built-in input validation security features.
“While the number of vulnerabilities identified in applications from 2010 and 2011 has not increased greatly, it does indicate that developers are continuing to make the same mistakes and are still not addressing web app security sufficiently,” says Michael Jordon, research and development manager at Context.
Web applications built for the Government sector were found to contain the highest number of vulnerabilities in 2011 and while the financial services sector had one of the lowest counts in 2010, this changed in 2011 with an average increase of roughly 1.5 vulnerabilities per web application tested. The law and insurance sector also saw similar results, seeing an average increase of roughly 2.5 vulnerabilities per web application penetration test in the same period.
“While some of the vulnerability categories such as server configuration and information leakage saw bigger rises, more serious cross-scripting and SQL injections present the biggest and potentially most damaging threats to web applications,” says Context’s Jordon. “Hopefully this document will provide help as a source of guidance, allowing developers and security professionals to prioritise and focus their web application security efforts in 2012. It is certainly clear that penetration testing before allowing a web application to go live is more relevant and essential than ever.”
The full Web Application Vulnerability Statistics Report for 2010-2011 can be downloaded at: http://www.contextis.com/research/white-papers/WebApplicationVulnerabilityStatistics2010-2011/
Context Information Security is an independent security consultancy specialising in both technical security and information assurance services. Founded in 1998, the company’s client base has grown steadily based on the value of its product-agnostic, holistic approach and tailored services combined with the independence, integrity and technical skills of its consultants. Context is ideally placed to work with clients worldwide with offices in the UK, Australia and Germany and its client base includes some of the most prestigious blue chip companies in the world, as well as government organisations. As best security experts need to bring a broad portfolio of skills to the job, Context staff offer extensive business experience as well as technical expertise to deliver effective and practical solutions, advice and support. Context reports always communicate findings and recommendations in plain terms at a business level as well as in the form of an in-depth technical report.
Peter Rennison / Allie Andrews
Tel: + 44 (0)1442 245030 / 07831 208109
Email: pr[at]prpr[dot]co.uk / allie[at]prpr[dot]co.uk