Contributor

Exposing 30 million IDs is a good reason for web application defense

Opinion
Oct 13, 20082 mins

MI5Networks, Nir Zuk of Palo Alto Networks, and Shlomo Kramer of Imperva.  All of them are industry veterans and all of them are developing products to address the inability of standard network security gear to address web application attacks. just announced Big Oops in Deutsche Telekom’s web portal is a case in point. From reading the report I surmise that they exposed the entire database of 30 million subscribers.  If a hacker had stumbled on the problem they could have sucked down those identities, including bank account info, in minutes.  One truism in exposing web applications is that stuff happens. No matter how well you analyze your code, test your applications, and scan on a regular basis you can still have mis-configurations that expose critical data.  

I had conversations lately with three CEO’s of web application defense companies:  Doug Camplejohn of

The

Of the three I talked to Imperva’s products are the best suited for addressing this kind of issue.  Usually deployed inline, Imperva’s web application firewall can detect and block the activity needed to grab a database such as in DT’s recent blunder.  

Deploying a web application firewall would have been preferable to having to announce the blunder.

Thanks to Martin McKeay for the tip on this story. 

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author