Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 9th September 2012, 01:38 PM
mmix Offline
Registered User
 
Join Date: Aug 2009
Posts: 761
linuxfirefox
Why Are Web Applications a Security Risk?

http://www.esecurityplanet.com/trend...rity-risk.html

Quote:
OS Security

Web applications can be hosted on multiple types of operating systems, including Linux and Microsoft Windows. According to Kandek, both Windows and Linux have their share of security concerns.

On Linux, SELinux provides a form of mandatory access control that can lock down applications. While that can be helpful for thwarting system level attacks, SELinux might not help if all the application is trying to do is get at data, Kandek noted.

"I see SELinux as good security infrastructure measure, and it helps a lot for people that are trying to take control of the machine that the application runs on," Kandek said.

In addition, PHP on Linux has a reputation for being an easy development language, meaning it may also be easy to write insecure code.

Older Microsoft technologies often had issues with ASP pages, Kandek said.
Sophisticated Web Attacks

From a big picture perspective, Kandek worries about the challenge of facing attacks from more sophisticated adversaries. In the fight against more advanced threats, it's imperative to take a holistic look at the attack surface and have sophisticated log analysis capabilities.

"So if you have your infrastructure hardened and your applications are well developed, then it would make sense to invest in a team that looks through the logs and tries to find patterns in there," Kandek said. "The tools are becoming available in that area, but I don't think they are easy to use yet and they require trained users.
Reply With Quote
  #2  
Old 9th September 2012, 02:10 PM
jpollard Offline
Registered User
 
Join Date: Aug 2009
Location: Waldorf, Maryland
Posts: 6,150
linuxfirefox
Re: Why Are Web Applications a Security Risk?

Mostly because those implementing the application don't know how to do it securely.
Reply With Quote
Reply

Tags
applications, risk, security, web

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Fedora Package site a security risk? hadrons123 Fedora Focus 11 3rd February 2012 10:52 PM
GNOME Security - A Remix of the Fedora Security Spin for Security Auditing sullivanmatt Fedora Spins & Remixes 0 31st May 2010 06:48 AM
Security risk of an unencrypted /boot partition? zackf Security and Privacy 5 10th April 2009 03:07 PM
Google Analytics security risk Evil_Bert Wibble 4 23rd November 2008 11:59 PM


Current GMT-time: 20:23 (Wednesday, 19-06-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat