Dropped here by your search engine? Use the same keyword in the google box below to search this site.
Google
 
Web This Site


HTTP attacks: Strategies for prevention

To run a Web site, your Web server must at least have port 80 open to process HTTP requests for Web pages. Unfortunately, attackers can modify or manipulate these requests to cause the server problems or to trick it into revealing valuable information. By using an HTTP request, an attacker has a legitimate path to your Web server and therefore can easily bypass firewalls and other security measures to initiate an attack.

There are two common HTTP attacks. One involves sending a long URL to a Web server with the goal of triggering a buffer overflow. The other attack is the SQL injection, which is the process of sending appended SQL commands to a URL to gain access to the backend database. Attackers often use forms to perform these attacks, as they both look to exploit poorly-written applications using unexpected, user-submitted data to initiate the attack. This means all user input data needs to be checked before being sent to another process. For example, if input data is used to build a Web page or is retrieved from a database, it must be checked before being published to ensure that any erroneous data is removed and the code runs correctly.

To prevent these types of attack, your organization's application security strategy should include the following: HTTP attacks: Strategies for prevention



More News



You are browsing the old version of "The Network Security. Org", Please
click here to visit the
new version.


Categories


RSS feed



server uptime monitor service




Warning: main(ad_network_213.php) [function.main]: failed to open stream: No such file or directory in /home/thenetw/public_html/news/View.php on line 282

Warning: main(ad_network_213.php) [function.main]: failed to open stream: No such file or directory in /home/thenetw/public_html/news/View.php on line 282

Warning: main(ad_network_213.php) [function.main]: failed to open stream: No such file or directory in /home/thenetw/public_html/news/View.php on line 282

Warning: main() [function.include]: Failed opening 'ad_network_213.php' for inclusion (include_path='.:/usr/lib/php:/usr/local/lib/php:../:../../:../../../:../../../../') in /home/thenetw/public_html/news/View.php on line 282