please don't copy from anywhere just your own words.
WEB APPLICATION ATTACK SCENARIO
Web Application Attack Scenario
Jermaine West
SEC 420 Perimeter Defense Technique
Professor: Dr. Jerry "Dr. G" Gideon
Strayer University
September 8, 2017
In today’s generation, technology has shaped the way for the future. Information systems have made it possible for people to process, store and disseminate information to support decision making, coordination, control, analysis, and virtualization in any organization. Web applications and data servers are the face of these big businesses. Hacking has been very consistent in the last ten years. Vulnerabilities and threats seem to be very common nowadays. The need for penetration testing, training and ethical hackers can help to mitigate some of these issues but not all.
There are some common vulnerabilities associated with Web applications. Remote code execution, SQL injection, Format string, Cross Site Scripting and Username enumeration are among some of the common ones but there are quite a few not mentioned (Siddharth & Doshi, 2006). The Remote code execution is an attack on a system to gain access to desired information. SQL injection is also a technique allows hackers to gain access to sensitive information from a database. This attack can result in a total system compromise. The Format string vulnerability is a result of the end users performing certain commands that result in attackers gaining access to format tokens and memory on an infrastructure. The success of Cross scripting attack requires end users to access a URL and the hacker puts something malicious on the victim’s browser. Username enumeration is a type of attack that exploits the individual’s username. Attackers have access to try different usernames in an attempt to gain access. The greatest area of vulnerability and potential for damage of such data systems are the actual end user. "End user failure to follow policies and procedures" and "general carelessness" was cited as the top examples of human error. Human error accounts for 52 percent of the root cause of security breaches, according to a new study from CompTIA, which surveyed individuals from hundreds of companies in the U.S. Despite 52 percent of respondents naming human error as the leading contributor to security breaches, only 30 percent of respondents in the study cited "human error among general staff" as a serious concern, and only 27 percent cited "human error among IT staff" as a serious concern (Greenberg, 2015).
In the recent Equifax attack, the possibility of a SQL injection could be great. On September 8th 2017, Equifax says a giant cyber security breach compromised the personal information of as many as 143 million Americans almost half the country. Cyber criminals have accessed sensitive information including names, social security numbers, birth dates, addresses, and the numbers of some driver's licenses. Additionally, Equifax said that credit card numbers for about 209,000 U.S. customers were exposed, as was "personal identifying information" on roughly 182,000 U.S. customers involved in credit report disputes. Residents in the U.K. and Canada were also impacted (O'Brien, 2017). Here is how it happens. SQL has the feature of an extended stored procedure call, which allows any system level command to be executed via the MS SQL server such as adding a user. The error messages displayed by the MS SQL server reveal more information than a comparable MySQL server. While MS SQL server is not especially prone to a SQL injection attacks, there are security measures which should be implemented to make it secure and not allow the SQL server to give out critical system information. To avoid this from happening, users should always use customized databases with the bare minimum required privileges required to perform the assigned task (Siddharth & Doshi, 2006).
End users are the biggest threat to their own organization without even knowing. The Human error alone is responsible for over half of cyber-attacks to include Phishing and the Trojan horse. These threats normally depend on the discipline and the value of their training. Many employees do things to breach confidentiality, Integrity and authentication. IT professionals and enterprise security teams must monitor and hold their employees to high standard while maintaining competence and compliance (Turner, 2015).
Network security is an important aspect as technology continues to grow. Security is the responsibility of all employees and should never be taken for granted. There should always be policies and guidelines based on the relevance of the enterprise. There should be an effective network security plan that outlines protocols, and factors of vulnerabilities. There should be a disaster recovery plan in place. Penetration testing should be incorporated as well as training. Hackers are more advanced each day so ethical hackers need to ahead of the game.
References
Casad, J. (2011). Sams Teach Yourself TCP/IP in 24 Hours
Greenberg, A. (2015) Human error cited as leading contributor to breaches, study shows
O’Brien, S. (2017) Giant Equifax data breach: 143 million people could be affected
Siddharth, S. & Doshi, P (2006) Five common Web application vulnerabilities
Turner, M. (2015) The Human Element of Cyber security
1