Skip Links

Network World

  • Social Web 
  • Email 
  • Close

NT OBJECTives tests your Web apps for vulnerabilities

A reminder that Web apps could be your security setup's weakest link
Technology Executive Alert By Linda Musthaler , Network World , 08/15/2005
Musthaler
Sign up for this newsletter now!

Linda Musthaler's CIO-level look at the latest networking technologies and their benefits and pitfalls.

  • Share/Email
  • Comment
  • Print

Chances are your security team has devoted a lot of thought, effort and money to security issues in the past year or two. You've plugged holes in the operating systems. You've done virus and spyware scanning. You've implemented security on the network and at the perimeter. But have you given consideration to your Web applications, which could allow a hacker entry into your network via a Web browser? Such applications could prove to be the weakest link.

For most organizations, Web applications drive the usefulness of the Internet.  Whether for internal or external use, interactive Web apps allow us to collect and exchange information that drives business. We need these applications, yet poorly designed apps can put the organization at risk. 

This is the hole that NT OBJECTives (NTO) intends to fill. NTO has developed technology to help identify programmatic vulnerabilities, as well as to advise you on how to reduce your risks.

NTOSpider http://www.ntobjectives.com/products/ntospider.php is a Web application vulnerability scanner that assesses your network in a completely automated fashion. It generates graphical reports that identify application vulnerabilities and exposure risks, and ranks the priority of threats.  NTOSpider also can perform an advanced analysis of your site structure, content and configuration to identify inherent exposure to future or emerging threats. 

This "application threat modeling" analysis looks at the common attack points and yields a list of vulnerabilities that need to be fixed. The program assumes that a developer has limited knowledge about application security and provides step-by-step instructions for remediation of the problem areas.

Now I'm not a Web application developer and I don't pretend to speak their language. That's why I recommend that developers look at the NTOSpider data sheet http://www.ntobjectives.com/datasheets/NTOSpiderDatasheet.pdf to determine its usefulness for themselves.  However, I can see the immense benefits of using a tool like NTOSpider, if for no other reason than to verify that applications have no vulnerabilities that are leaving the back door open to attack.

Beyond the assessment tools, NTO also offers consulting services and developer training and education by security experts, including Mike Shema, a man considered to be one of the foremost experts in the area of Web application security. He is highly regarded for his books "The Anti-Hacker Toolkit," a collection of tools and techniques for security administrators to secure and defend enterprise networks, as well as "Hacking Exposed: Web Applications" and "Hack Notes: Web Application Security."

Linda Musthaler is a principal analyst with Essential Solutions Corporation.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.