Has your site got the 3 basic security measures?


In recent weeks, attacks on ...
sites such as Yahoo and Ebay have brought home a very pressing point - site ... Anywhere you have a ...
page, you could be open to attacks In recent weeks, attacks on prominent sites such as Yahoo and Ebay have brought home a very pressing point - site security. Anywhere you have a dynamically-generated page, you could be open to attacks where malicious HTML is embedded into your pages.
Your pages could be rewritten to substitute your customers' names with "Dummy." Or, credit card information could be intercepted and sent to a secret depository for later use. What can we do about this?There are many methods by which a hacker may attackor take control of a site.
I am focusing this discussionon attacks that come via form input. That is, anywhere youhave input coming in from your web user, e.g.
a registrationform, user login or even a search on your site. Scripts could be sent to your server by entering some maliciouscode in your input fields.
The following are stepsyou can take to minimise the risk of this happening.These measures will not make your site hacker-proof (no site can be if a hacker really has it in for you), but it can make it less of an easy target. Step 1: Place character limits on your inputs You do this by adding the "maxlength" attribute into your text input tags e.g.
The example above restricts the user to a 15 character input for that field. The "" and "" tags alone will take 17 characters so the smaller you limit your "maxlength" attribute to, the harder it will be to include rogue codes in your inputs.
Of course, you must ensure that you impose a suitable limit so that actual input from your valid users will not be excluded. Step 2: Filtering your data All data received from your site should be filtered, you can either filter your data when it comes into your server as user input, or when it goes out as results for your user's browser.
Whether you should filter input or output, depends on your site and its requirements, there is a good discussion on this at http://www.cert.org ech_tips/malicious_code_mitigation.html/ . Filters can be written in any language, here is an example in Perl : # This function checks the input, $firstname, for the following symbols ;?*/'&$!#()[]{}:"' # and tells the user to re-enter his/her firstname if any of the symbols is found if($firstname =~ /([;?*/'&$!#()[]{}:'"])/) { print p('Invalid input found, please use only alphanumerical input.
Please re-enter yourFIRSTNAME'); } You can see this script at work on our site : http://www.payingads.com/freesignup.html . Step 3: Setting the character encoding Some HTML editors already set this while it creates a page, but those of you who have older HTML editors or like me, like to code the page from scratch will need to include the following line in our HTML pages: It should go as high as possible on your webpage, I normally place it just after the tag, before the tag.
This META tag tells the browser to use the "ISO-8859-1" character set, which is suitable for most Western European languages, rather than let the browser choose it's own character encoding, which may or may not be ISO-8859-1. Why is it important to explicitly set it? The character encoding basically tells browsers how to display a particular character.
For example, in the ISO-8859-1character set, "A" represents the letter "A" while "©" represents the copyright symbol "©" (You can try this out by typing A or © in a html file then call it up on a browser). Some character sets, have more than one representation for special characters such as "", so your filter program may not toss out all the representations of the character you have asked it to exclude.
So when it serves a new page back to the browser, the browser, because it has not been told what encoding to use, can still read the malicious script intact.So there you have it, 3 steps that should be incorporatedinto every website. Use them as a base to further build on.
Because every site is different, you (or the security consultantyou hire) will need to assess your site's own vulnerabilities and implement appropriate security measures. To do this you need to take into account your site's risk factor, your budget and your available resources.On a final note, I'd like to stress the importance of keepingup with the latest threats and developments in site security.
A good site for checking out security alerts is theCERT Coordination Center http://www.cert.org/nav/index.html or better yet sign up for their Security Advisory that is sent via email. Source: Free Articles from ArticlesFactory.com .

Top blog stories

A review of Idmobile.com

Idmobile.com offers both pay-as-you-go and contract plans. Pay-as-you-go plans are ideal for customers who don't want to be tied down to a long-term contract, and they can purchase bundles of data, minutes, and texts as and when they need them.

see post

A review of Idmobile.com

Idmobile.com offers both pay-as-you-go and contract plans. Pay-as-you-go plans are ideal for customers who don't want to be tied down to a long-term contract, and they can purchase bundles of data, minutes, and texts as and when they need them.

see post

AO.co: Online Shopping Made Simple

AO.co is a trusted expert in TVs, washing machines, clothes dryers and other household appliances. AO.com is one of the largest retailers in the UK and it specializes in electronics, clothes and home furniture.

see post

For our people.

At Three, we believe phones are good. They just make life better. Easier. And more fun. But we all need to find a balance that works for us. Our mission is to help our customers use their phones to live their best lives.

see post

We make your life easier

We make your life easier Since 1992, we’ve been helping customers get the best deal on their dream phone. We firmly believe in giving you the highest quality, for the lowest price. That’s why we work with three of the UK’s leading networks to do all the haggling for you,...

see post

FOUR BRANDS BECOME ONE. CURRYS.

Currys PLC is a leading omnichannel retailer of technology products and services, operating through 800+ stores and 16 websites in seven countries.

see post

Halfords - Quicker, Easier, and Convenient.

At Halfords, we're all about the journey. With more than 700 stores with over 10,000 colleagues, we're the UK's leading retailer of automotive and cycling products. We are also the leading operator in MOT, tyres, car servicing and car repairs - pleasing more than 750,000 customers every year.

see post

FOUR BRANDS BECOME ONE. CURRYS.

Currys PLC is a leading omnichannel retailer of technology products and services, operating through 800+ stores and 16 websites in seven countries.

see post

Sky - Epic. Endless. Entertainment.

It's important to us that everyone gets great customer service and can enjoy our products, no matter their level of sight. So, if you're blind, partially sighted or struggle to see or read the screen, we’ve a range of features to help you get the most from our products and...

see post

Nasty Gal - We exist for the “girl in progress”.

Look iconic, without the hassle— using Nasty Gal discount codes, you can shop your favorite pieces for way less by simply entering one of our promotional codes (of your choice) at the checkout. From delivery offers, to promo deals, we keep ‘em coming, so you always have the offer you...

see post

Digital Publishing From Past to Now

The Covid-19 has caused the school and universities to shut down around the world creating a major issue in Learning and Education. As this virus spreads through the interaction and if social distanci... The Covid-19 has caused the school and universities to shut down around the world creating a major...

see post

Why it’s Important to Manage Your Holiday Calendars?

A printable calendar 2021 is a prominent online platform where you download printable calendars of your choice. These calendars can be customized as per our client requirement with photo, text, logo, or any other image. If you are thinking of planning a dream vacation tour with family and kids but...

see post

5 Tips to become successful in business and in life


In my opinion, philosophies in business can be applied in life and vice versa. People have to realize that successful business owners didn't acquire their wealth by sheer luck. They think and act differently that the rest. Source: Free Articles from ArticlesFactory.com

Satin Nightgowns - Ladies Sleepwear Guide


Satin nightgowns are a glamorous ladies sleepwear option with so much more appeal than their intimate apparel cousin, the cotton nightgown. Silky satin is a soft and rich fabric with luxurious appeal that has won the hearts of lingerie fans everywhere. Rich satin nightgowns are a glamorous sleepwear choice compared...

Nursing Nightgown - What New Mothers Need To Know About Ladies Sleepwear


A nursing nightgown is a must have lingerie drawer basic for new mothers. This popular type of nightgown is specially designed for breastfeeding moms, and is highly recommended as it makes things a lot easier and more comfortable for both the new mother and her baby. A nursing nightgown is...

Green Choices: Lessons From Jim Simcoe, An Eco-Consultant


Think. Act. Speak. Living green can be summed up in these three words. Greening up your life isn’t just about changing your light bulbs. It’s how you think, what actions you take, and who you infl... Think. Act. Speak. Living green can be summed up in these three words. Greening...

A Primer On The Cotton Nightgown


The fantastic selection of ladies sleepwear has never been as tempting or affordable as it is today. Discover which cotton nightgown fits you best Since almost the beginning of time, a great ladies sleepwear basic has been the cotton nightgown. Cotton is a natural fabric that is well known for...

Hints and Tips for the Sony Reader


Many people prefer the Sony reader to any other make of e-reader, but they often don't know how to resolve some of the problems they might come across.  Here are 12 tips to help you resolve some of the more common problems, and allow you to make better use of...

HDTV - Things to Consider Before Buying HDTV


With all new HDTV being announced in the tv market, all of them claim to have advanced technology features which encourage you to get another tv although you already have one. However, buying an HDTV is a long term investment, there are several important things you need to think about...

4 Green Remodeling Tips from an Eco-Consultant


“Everybody wants to be green.”   It’s sexy, it’s cool, and it’s socially responsible being green. Unfortunately it can also be paradoxical and elusive. Is it green to lay down bamboo floo... “Everybody wants to be green.”   It’s sexy, it’s cool, and it’s socially responsible being green. Unfortunately it can also...

7 Ways To Green Your Company


Many large businesses and corporations have started funding and promoting greener ways and strategies. Take, for example, Wal-Mart’s funding of the first heavy-duty diesel hybrid 18-wheelers or... Many large businesses and corporations have started funding and promoting greener ways and strategies. Take, for example, Wal-Mart’s funding of the first heavy-duty...

Selecting a Wedding Photographer.


You've got the names of lots of local wedding photographers but which one do you trust to shoot the biggest event of your life?  In this article I'll help you choose your dream wedding photographer and highlight a few of the pitfalls you will want to avoid. Source: Free Articles...

Search topic

Selecting a Wedding Photographer.

You've got the names of lots of local wedding photographers but which one do you trust to shoot the biggest event of your life?  In this article I'll help you choose your dream wedding photographer and highlight a few of the pitfalls you will want to avoid. Source: Free Articles...

Learn more