Disclosing PC Vulnerability

IT security revolves around the concept of vulnerability: the attacker wants to find and exploit it, while your aim is to ensure that it doesn't exist. Unfortunately, while the former is child's play, the latter is harder than it may seem.

Provided By:

IT security revolves around the concept of vulnerability: the attacker wants to find and exploit it, while your aim is to ensure that it doesn't exist. Unfortunately, while the former is child's play, the latter is harder than it may seem. As Lawson explains: "All software has faults; this is an immutable fact about code written by humans. It's critically important computer systems are kept up to date, as the updates fix the bugs that could lead to a compromise by a hacker. Microsoft has made this incredibly easy with the Automatic Updates tool. Ensure this tool is running to download updates automatically. Corporate environments should test all updates prior to deployment to ensure the update doesn't affect business functions."

The Microsoft Baseline Security Analyzer (www.microsoft.com/technet/security/tools/mbsahome.mspx) is another easy-to-use tool designed for the IT professional that can help small and medium-sized businesses to determine their security state in accordance with Microsoft security recommendations.

But what about when you move away from your computer and the vulnerabilities of the OS, and look towards your website instead? Fogerty recommends two distinct approaches: web-server and web-application testing. "With web-server testing you're testing the underlying web server (IIS, Apache) to make sure it's patched and in a hardened configuration. Run free tools like Nikto or Nessus to check for vulnerabilities," he says. Both are available to members of Hackerwhacker as mentioned earlier.

"With web-app testing, you are looking at the application that sits on the web server. This is usually a custom application and could be susceptible to SQL Injection, Cross Site Scripting (XSS) and Cross Site Request Forgery (CSRF) vulnerabilities if the developers have not used 'defensive programming'; that is, not validating input from the client before acting on it," Fogerty adds. "There are plenty of free web-app testing proxy tools that act as a middle-man between the client and server. You can then insert 'malicious' data into the HTTP stream to see if the web app fails to deal with it." Try Achilles (www.mavensecurity.com/achilles), Burp (www.portswigger.net/proxy) or Paros (www.parosproxy.org/download.shtml) for starters.


" target="_self">10. Rattle your router


Hack it yourself

Author: Davey Winder

9. Disclose your vulnerabilities

Regional Articles
- Disclosing PC Vulnerability Alabama
- Disclosing PC Vulnerability Alaska
- Disclosing PC Vulnerability Arizona
- Disclosing PC Vulnerability Arkansas
- Disclosing PC Vulnerability California
- Disclosing PC Vulnerability Colorado
- Disclosing PC Vulnerability Connecticut
- Disclosing PC Vulnerability DC
- Disclosing PC Vulnerability Delaware
- Disclosing PC Vulnerability Florida
- Disclosing PC Vulnerability Georgia
- Disclosing PC Vulnerability Hawaii
- Disclosing PC Vulnerability Idaho
- Disclosing PC Vulnerability Illinois
- Disclosing PC Vulnerability Indiana
- Disclosing PC Vulnerability Iowa
- Disclosing PC Vulnerability Kansas
- Disclosing PC Vulnerability Kentucky
- Disclosing PC Vulnerability Louisiana
- Disclosing PC Vulnerability Maine
- Disclosing PC Vulnerability Maryland
- Disclosing PC Vulnerability Massachusetts
- Disclosing PC Vulnerability Michigan
- Disclosing PC Vulnerability Minnesota
- Disclosing PC Vulnerability Mississippi
- Disclosing PC Vulnerability Missouri
- Disclosing PC Vulnerability Montana
- Disclosing PC Vulnerability Nebraska
- Disclosing PC Vulnerability Nevada
- Disclosing PC Vulnerability New Hampshire
- Disclosing PC Vulnerability New Jersey
- Disclosing PC Vulnerability New Mexico
- Disclosing PC Vulnerability New York
- Disclosing PC Vulnerability North Carolina
- Disclosing PC Vulnerability North Dakota
- Disclosing PC Vulnerability Ohio
- Disclosing PC Vulnerability Oklahoma
- Disclosing PC Vulnerability Oregon
- Disclosing PC Vulnerability Pennsylvania
- Disclosing PC Vulnerability Rhode Island
- Disclosing PC Vulnerability South Carolina
- Disclosing PC Vulnerability South Dakota
- Disclosing PC Vulnerability Tennessee
- Disclosing PC Vulnerability Texas
- Disclosing PC Vulnerability Utah
- Disclosing PC Vulnerability Vermont
- Disclosing PC Vulnerability Virginia
- Disclosing PC Vulnerability Washington
- Disclosing PC Vulnerability West Virginia
- Disclosing PC Vulnerability Wisconsin
- Disclosing PC Vulnerability Wyoming

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History