Strategic SEO services
that produce results

searchengineoptimisation.com will take your
results one way. Up.

Musings About Web Site Security

I have come to the realisation that I spend an incredible amount of time on the web. My work is all about the web; at home I visit websites for leisure; even when I’m out and about I use my smartphone to check my e-mails and compare high street prices. I’ve often wondered about how safe I am from malicious websites but my recent musings have been about how safe websites are from me (well, us, the end-user).

In recent months I’ve come across more and more sites that have become comprised with malware, phishing scams and other defacements. Most recently I’ve come across a site that has been hacked more than once and each time the defacement was to add a hidden link farm. All of this has prompted me to think about web site security.

social engineering hack

If only we had alerts in real life

I come from a security conscious background and, as you can probably tell, I also think a lot. Here are some of my more coherent musings and ideas about website vulnerabilities.

  1. It is sad but true that the weakest link is often the squishy human link. Social engineering, is a classic example of a vulnerability, this is the manipulation of people to get access to information. The text-book example would be, someone calling you and tells you they’re “Bob from the IT department” and they need your web server password to apply a patch.
  2. There’s a rule I live by while I’m wearing my developer-hat, any input needs to be validated, verified and sanitized. Not necessarily in that order. Any time a website takes an input; that is a potential point-of-entry (PoE) for a malicious user. Inputs can include form submission, cookies, sessions and URI. The most common hacks using this PoE are SQL Code Injection and privilege elevation.
  3. Everyone knows that systems have defaults and common user names and passwords are an open secret. There’s a good chance that any hacker will know them too, so please stop using “admin” and “passw0rd1” for your administrator account. This not only applies for user accounts but anything else that uses default or common names.
  4. The key is to restrict access to only those that need it. If a database only needs to be accessed by the web-server, restrict access to only that server. This can be considered in the design stage of a web sites’ architecture with having a firm distinction between the presentation and data layers.

I hope this post has given you something to think about, I couldn’t cover everything in this blog but I covered the points that were most coherent.

This entry was posted on Wednesday, September 8th, 2010 at 11:53 am. You can follow any responses to this entry through the RSS feed.

About the author:

Posted by Ray.

Link to us

If you want to link to this blog, copy and paste the following HTML code to your website.

Leave a Reply


Get In Touch

Get in touch today for Free SEO Analysis...


Blog Categories

SEO Proposal & Quote

Enter your details below for a no obligation
SEO Proposal and Quote!

Featured Client

The Image Group UK

The Image Group specialise in Exhibition Stands / Displays and Canvas Printing

Our Twitter Feed


Follow us on Facebook

Email Sign-Up

Enter your details to receive SEO industry tips & news by email.

Client Login

Three easy ways to make SEO content sparkle

Posted on: 03/02 in SEO Strategy

Any your search engine optimization company will advise that good content is a way to get ahead in today's internet. The search engines have...more.

Wikipedia pages: still SEO tools?

Posted on: 01/02 in Online Reputation Management

There was a time when Wikipedia pages were seen as a useful tool for SEO. They fit in nicely with link building strategies, and they were gr...more.

How can I get .edu links?

Posted on: 27/01 in SEO Strategy

Many SEO experts sing the praises of .edu links. These links, coming from academic institutions, tend to carry a fair amount of weight with ...more.

Communicate with Video

Posted on: 30/12 in Online Reputation Management

There are a growing number of website owners that are using video as a means of communication on their sites. Using video can be an effectiv...more.

Ways to Promote Your Blog

Posted on: 27/12 in SEO Services

If you have an online business then setting up a blog on your website can help your SEO efforts no end. It can be a great medium for allowin...more.

Three Ways You Can Allow Your Blog to Self Destruct

Posted on: 24/12 in Online Reputation Management

If you want to create a successful group blog as part of your search engine optimisation then you’ll need to invest some blood, sweat ...more.

XML Sitemap | Sitemap | © | Copyright 2009-2010 SearchEngineOptimisation.co.uk | Blog RSS Feed | Article RSS Feed | Video Sitemap