<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>FireBlog &#124; FireHost &#187; Prevent Web Application Security Breach</title>
	<atom:link href="http://www.fireblog.com/tag/prevent-web-application-security-breach/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.fireblog.com</link>
	<description>Secure Hosting Blog</description>
	<lastBuildDate>Thu, 29 Jul 2010 14:23:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Save This List: How to Help Prevent a Web Application Security Breach</title>
		<link>http://www.fireblog.com/save-this-list-how-to-help-prevent-a-web-application-security-breach/</link>
		<comments>http://www.fireblog.com/save-this-list-how-to-help-prevent-a-web-application-security-breach/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 13:00:21 +0000</pubDate>
		<dc:creator>FireHost Evangelist</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[eCommerce Cybercrime Holiday 2009]]></category>
		<category><![CDATA[Online Shopping Safety 2009]]></category>
		<category><![CDATA[Prevent Web Application Security Breach]]></category>

		<guid isPermaLink="false">http://www.fireblog.com/?p=2712</guid>
		<description><![CDATA[Many entrepreneurs have preconceptions about their place in the cybercrime world, and their thoughts generally fall into one of two trains of thought. 1) If large organizations like Sears can easily fall prey to cybercrime, it shouldn’t be a challenge at all to steal from my small business. 2) My company is too small to hold value for hackers, and I’m safe because it wouldn’t be worth their time. Today’s discussion takes a deeper look into preventing cyber crime at small and medium sized businesses. ]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2967" title="CSA_07" src="http://www.fireblog.com/wp-content/uploads/2010/01/CSA_07.png" alt="CSA_07" width="161" height="80" />In a previous <a href="http://www.fireblog.com/save-this-list-what-ecommerce-site-owners-should-do-in-the-event-of-a-security-breach/" target="_blank">post</a>, we provided information you&#8217;ll need to know immediately if your website is successfully hacked. It included recommendations on how and when to:</p>
<p><strong>Step 1</strong> Announce and assess the breach<br />
<strong>Step 2</strong> Conduct a deeper investigation<br />
<strong>Step 3</strong> Notify affected individuals and organizations and begin remediation<br />
<strong>Step 4</strong> Re-launch<br />
<strong>Step 5</strong> Communicate the resolution publicly and to affected parties<br />
<strong>Step 6</strong> Take steps to remediate vulnerabilities and prevent a future breach</p>
<p>Today’s discussion takes a deeper look into step six, preventing cyber crime at small and medium sized businesses. The truth is that security measures in place at most SMBs are &#8220;easy pickings&#8221; for hackers, and there is a booming community of C2C (criminal to criminal) interactions focused solely on stealing customer data from SMBs that conduct business online. The same way you work every day to develop new, enticing products and easier ways for your customers to shop, cyber theft &#8220;shop owners&#8221; fuel this sub <a href="http://www.symantec.com/about/news/release/article.jsp?prid=20081123_01" target="_blank">economy</a> by devising faster, easier, and more effective methods by which to steal your company&#8217;s valuable data.</p>
<p>Preventing data leakage takes an ongoing, concerted effort, so it&#8217;s important that you take proactive control over your immediate environment. Here&#8217;s how:</p>
<p><span id="more-2712"></span><strong>Only run software you need. </strong>Thoroughly review all third party applications before introducing them to your environment. Only install third party applications if they are absolutely necessary. Remove all inactive programs at once. Paring down your list of installed programs alleviates your susceptibility to any known or future security threats they may pose.</p>
<p><strong>Stop ignoring those updates. </strong>Install every software update, and do it quickly. Addressing security vulnerabilities is a top priority of software patches, so don&#8217;t get versions behind.</p>
<p><strong>S = More Secure</strong>. Traditional FTP connections are insecure. Look for “SSH” and “SFTP” connections as they are in an encrypted format and are the minimum standard for eCommerce Web site administration.</p>
<p><strong>Manage change. </strong>Terminate access credentials for former website administrators and employees immediately after (and sometimes before) they exit the company. Open logins create an extremely popular data leakage point. Implementing strict, consistent, change management protocols will reduce the chances your website is compromised by a password breach.</p>
<p><strong>Check configurations and permissions. </strong>Regularly check that server configurations and file permissions are set correctly, and that there are no open permissions on directories.</p>
<p><strong>Cheaply outsourced labor could cost you. </strong>Do you really want to outsource your livelihood to the lowest bidder? Websites require ongoing maintenance, bug fixes, and enhancements, and working closely with a local developer that you can meet in person might be the best solution in the long run.<strong> </strong></p>
<p><strong>Hire a hacker. </strong>Hire a hacker to try and penetrate your environment to find its vulnerabilities. I’m serious.</p>
<p><strong>Achieve PCI Compliance if you conduct eCommerce. </strong>The payment Card Industry has devised a succinct <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">list</a> of requirements to which every organization must adhere if they accept credit cards as a form of payment.</p>
<p><strong>Vulnerability audits. </strong>Have professionals perform regular <a href="http://www.firehost.com/secure-hosting/vulnerability-audit" target="_blank">vulnerability audits</a>. We recommend monthly or quarterly (at minimum). Vulnerability audits can identify weak logins, data leakage from forms, SQL injection vulnerabilities, DDoS activity, spam relaying, order manipulation, admin control panel tampering, and more.</p>
<p><strong> </strong></p>
<p>Hackers pose a real threat to SMBs, and they find value in stealing customer records, even from the “one-man shops” out there. Give these preventative measures the same priority as the way your site looks and works. Afterall, an ounce of prevention…well, you know the saying.</p>
<p><em>A version of this article was featured in <a href="http://entrepreneur.venturebeat.com/2009/12/16/keeping-hackers-away-from-your-customer-data/" target="_blank">VentureBeat</a> on December 16, 2009.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.fireblog.com/save-this-list-how-to-help-prevent-a-web-application-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
