Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
5 habits of web application hackers, and what businesses can do
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Business
  • 5 habits of web application hackers, and what businesses can do

5 habits of web application hackers, and what businesses can do

FP Staff • July 21, 2015, 16:02:11 IST
Whatsapp Facebook Twitter

Begin with gauging risk level and allot appropriate budget to web application security.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
5 habits of web application hackers, and what businesses can do

Despite making huge investments in IT security, large corporations across the world seem to be losing out to the new generation of cyber attackers. These modern day hackers are smarter, more innovative and have the capabilities to cause severe damage. Indusface has identified five notorious habits of web application hackers that can help you understand their strategies and devise smarter ways to counter them. According to Ashish Tandon, Chairman and CEO at Indusface, “If you have to prevent a hacker, you need to think like him. You have to test the security system just the way a real hacker would exploit them. And that’s where our ‘Five habits of web application hackers’ guide will help you understand their strategy better and learn from them to protect websites.” [caption id=“attachment_2143235” align=“alignleft” width=“380” class=" “] ![Thinkstock](https://images.firstpost.com/wp-content/uploads/2015/03/CybersecurityThinkstcok.jpg) Thinkstock[/caption] Habit 1: Finding Dark Motivation                                                                                                    According to results from the “Cyber crime Survey Report 2014,” 58% attacks happen for financial gains. Malicious damage, competitor grudge, and ethical reasons are some of the other popular motivators to cyber crimes. While online business websites are at highest risk of hacking, public sector isn’t safer either. Last year alone 155 .GOV and . NIC domains were hacked. A majority of these attacks came from neighboring country IPs. Countermeasure: Begin with gauging risk level and allot appropriate budget to web application security. Risks levels are critical for organisation with considerable online reputations and business credibility. Government and banking websites are also lucrative options for hackers around the world. Habit 2: Detecting Weaknesses                                                                                                    Detecting weaknesses or vulnerabilities in web application architecture is the first step for any hacker. It helps him analyse if a certain website is exploitable. A few years ago, the vulnerability-finding process had to be performed manually, but now there are dozens of open source scanners that look for basic vulnerabilities like Cross Site Scripting (XSS), Command execution detection CRLF Injection, SEL Injection and Xpath Injection, Weak .htaccess configuration. Countermeasure: The only smarter way to stay one-step ahead of the hackers is to detect vulnerabilities with an even smarter web application scanner. IndusGuard Web not only looks for OWASP and WASC listed vulnerabilities but also monitors for malware, blacklisting, and defacement attempts. Habit 3: Analysing Logical Weaknesses  Modern apps are continuously changing with new vectors coming in and you can never really predict that a hacker might find handy. While automated programs can find basic vulnerabilities, it requires an analytical human mind to look for logical weaknesses. These are vulnerabilities within business logic of an application and are limited by a definition or scope. The logic flaws could creep into commands related to monetary transactions, timeout of sessions or any other aspect of business processes. Unfortunately, most companies do not even know about them unless there is a monetary leakage. Countermeasure: Business logic flaws can only detected and mended by people who understand how such exploitations work. Manual penetration testing from application security experts is the best way to find such vulnerabilities before hackers. Habit 4: Exploiting Weaknesses                                                                                                                    It has been estimated that businesses lose annually $3.8 million annually to cyber exploitations. In fact, in the past few months, large online song portal and taxi-for-hire websites have been hacked using vulnerabilities like SQL Injection. Countermeasure: After vulnerability detection, patching application source code is not always possible for many reasons. For continuous protection, web application firewall is a feasible solution that not only prevents attacks but also provides data on attack attempts. It helps learn more about techniques that attackers use and then framing better policies to detect and protect web applications. Habit 5: All-Out Service Denial                                                                                       Distributed denial-of-service (DDoS) is an exploitation that all web applications are vulnerable to. Under a DDoS attack, users are unable to access the websiteas the server is busy processing requests from bots before it crashes completely. In fact, there have been reports of DDoS attacks lasting for weeks, costing millions for companies. Hackers often ask for ransom in lieu of stopping such attacks. In other scenarios, they just want to disrupt performance out of grudge or rivalry. Countermeasure: Distributed denial-of-service attacks can only be stopped with constant monitoring. Managed security experts have to look for attack patterns based on malicious IPs, machine fingerprints, and bot signature and create custom rules to block them and prevent DDoS attack before it can cause any harm          

Tags
hackers DDOS Indusface
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Impact Shorts

Tata Harrier EV vs Mahindra XEV 9e: Design and road presence compared

Tata Harrier EV vs Mahindra XEV 9e: Design and road presence compared

The Tata Harrier EV and Mahindra XEV 9e are new electric SUVs in India. The Harrier EV has a modern, familiar design, while the XEV 9e features a bold, striking look. They cater to different preferences: the Harrier EV for subtle elegance and the XEV 9e for expressive ruggedness.

More Impact Shorts

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV