
A further 33 per cent of websites contain critical vulnerabilities that are widely known and actively exploited by hackers, according to NTA Monitor's Annual Web Application Security Report 2007.
The report analysed data gathered from web application security tests undertaken on behalf of a variety of organisations during 2006, including financial institutions, legal practices, universities and local government bodies.
Roy Hills, technical director at NTA Monitor, said: "Web applications are accessible 24/7 and control sensitive data such as customer details, credit card numbers and proprietary corporate data.
"An ever increasing number of people are using the internet for personal business such as banking, bill payments and shopping, and as a core part of their working lives in terms of remote working and resource sharing.
"It is high time that organisations took greater steps towards protecting these revenue generating and efficiency enabling systems."
As the number, size and complexity of web applications increases, so does the risk exposure, Hills warned.
The research shows that attackers focusing on web application security problems are actively developing tools and techniques to exploit the flaws.
NTA Monitor has made three key recommendations that organisations can follow to reduce their risk:
- An account lockout mechanism should be in place to lock out accounts permanently or temporarily, to help prevent attackers from being able to brute force user accounts
- Meta characters such as single quotes, double quotes and semicolons should be disallowed in order to minimise the threat of SQL injection attacks, which are a high risk vulnerability
- In order to help protect against keystroke loggers, the mouse and keyboard should both be used during log-in processes. For instance, users should be asked to use drop-down boxes or radio buttons as well as keying in details