SBC's Web hosting, I asked Caleb Sima from SPI Dynamics, a Web application and security assessment software firm, to give me some insights about breaking into Web sites. Caleb has a pretty cool job: He gets paid to do that, in the process demonstrating the need for tools such as his employer sells as well as the various weaknesses of people's sites. When he visited me at CMP last fall, he was inside our own Web site within a minute or so, reading stuff that he shouldn't have had access to. Fortunately, our Web folks have tightened things up, but you may not be so lucky.">
---
Email this article   Print article 

Anatomy of a Hack

By David Strom, CRN
May 01, 2003    11:30 AM ET

After my last column on problems with SBC's Web hosting, I asked Caleb Sima from SPI Dynamics, a Web application and security assessment software firm, to give me some insights about breaking into Web sites. Caleb has a pretty cool job: He gets paid to do that, in the process demonstrating the need for tools such as his employer sells as well as the various weaknesses of people's sites. When he visited me at CMP last fall, he was inside our own Web site within a minute or so, reading stuff that he shouldn't have had access to. Fortunately, our Web folks have tightened things up, but you may not be so lucky.

I asked Caleb to give me an idea to find these vulnerabilities so quickly, and he came up with a few suggestions. If you understand how Web servers work and how they have directory structures and input forms just like your computer on your desktop, you can get pretty far -- even without much other specialized knowledge. To give you a flavor of this, I submit his prescription for locating a Web application attack vulnerability called cross-site scripting.

Cross-site scripting occurs when dynamically generated Web pages display input that is not properly validated. This allows an attacker to embed malicious JavaScript code into the generated page and execute the script on the machine of any user that views that site. Cross-site scripting has some far-reaching implications, and can impact any site that allows users to enter data. You see this on search engines, in error message screens, in forms and Web message boards, among other places. (You can read more about this at SPI Dynamics' site.

Here are the steps to see if your Web applications are vulnerable to this attack:

Step 1: Open any Web site in a browser, and look for places on the site that accept user input, such as a search form or some kind of login page. Enter the word test in the search box and send this to the Web server.

Step 2: Look for the Web server to respond back with a page similar to something like "Your search for 'test' did not find any items" or "invalid login test." If the word "test" appears in the results page, you are in luck.

Step 3: To test for cross-site scripting, input the string "" text in this source code, then the Web server is vulnerable to cross-site scripting.

If these steps don't make much sense to you, not to worry. You can still get some mileage, particularly when you are in the throes of picking a hosting provider. I suggest that you might want to send them this column and see what kind of response you get from them before you give them your business. If you get no response or a canned response, then you probably should go elsewhere. You could also send this column to your IT department. If they don't understand what I am talking about here, then you might want to bring that to the attention of your CEO and find out why.

There are plenty of other Web site vulnerabilities, as I mentioned in my last column. Hopefully this will get you motivated to seek them out, either by using SPI Dyanmics' product called WebInspect or someone else's, and by being more diligent about what applications you allow access to your Web content.

To continue reading this article, please download the CRN Tablet Edition app from the iPad App store.

SHARE THIS ARTICLE

More Channel Programs

Recent Articles

SP500: CSC Sales Dip, ePlus Opens HP Cloud Center

News at several of CRN's top solution providers made headlines this week, including CSC's declining sales and ePlus' cloud computing center.

Scenes From HTG Summit: VARs Helping VARs

Scenes from Heartland Tech Groups HTG Summit in Dallas brought hundreds of solution providers and VARs together to improve their businesses.

Five Companies That Came To Win This Week

For the week ending May 18, CRN looks at five companies that brought their 'A' game and made moves to beat out competitors.

  More Slide Shows




Related Videos
Loading...