|
 |
 |
Web Application Vulnerability Statistics of 2012 by Sam White
 |
|
|
Web Application Vulnerability Statistics of 2012 |
|
|
|
Computers
|
 |
Web Application Vulnerability Statistics of 2012 With years of experience and valuable insights from our expert security team, we thought of conducting a study to discover the prevailing critical website security trends. So, this report is based on our original research on more than 5000 tests covering 300+ customers distributed globally. How was the study done? The study was conducted on the vulnerability data of web applications tested by us in 2012. In total more than 5000 application vulnerability from 300+ customers has been considered as part of the sample data. Our study comprised of 25% apps from Asia, 25% apps from Europe & 40% apps from USA. Key Findings of our Study • 99% of the Apps tested had at least 1 vulnerability • 82% of the web application had at least 1 High/Critical Vulnerability • 90% of hacking incidents were not publicly reported • We observed very low correlation between Security and Compliance (Correlation Coefficient: 0.2). This once again proves that compliance and security is not synonymous. • Average number of vulnerability per website: 35. The details of analysis of vulnerability by density are available here. • 30% of the hacked organizations knew the vulnerability (for which they got hacked) beforehand • USA and Europe Applications had lower vulnerability density than that of APAC • #1 Vulnerability: Cross site scripting (61%). You can access the graph and the distribution of other vulnerabilities here. • #1 Secure vertical: Banking. The vulnerability density in the application by vertical is available in the full report which can be downloaded for free. • #1 Vulnerable Vertical: Retail • Business Logic Flaws were the most neglected vulnerabilities We observed the business logic vulnerabilities as the most overlooked and with the highest business impact. Most of the organizations do not have a process to discover and eliminate business logic flaws. • Weak Password Recovery. • Abusing Discount logic or coupons. • Denial of service using Business Logic. • Price manipulation • OTP (One time Password) bypass Note: We observed that the average Number of vulnerability per website as 35 which is significantly lower than other industry reports. One of the reasons could be that we remove all false positives (Zero False Positive Guarantee) which other tools don’t. Another possible reason is that we report vulnerability based on Root cause analysis and do not count the number of resulting manifestations due to this one single vulnerability. Hence the reported number is low against some very high numbers projected by other tools.
Related Articles -
Web application security, penetration testing, vulnerability testing,
|
Rate This Article |
|
 |
|
Do you Agree or Disagree? Have a Comment? POST IT!
Reader Opinions |
|
 |
|
|
|
 |
 |
 |
Author Login |
|
 |
Advertiser Login
ADVERTISE HERE NOW!
Limited Time $60 Offer!
90 Days-1.5 Million Views

 |
 |
LAURA JEEVES
At LeadGenerators, we specialise in content-led Online Marketing Strategies for our clients in the t...more
|
 |
 |
 |
 |
STEPHEN BYE
Stephen Bye is a fiction writer. His most recent novels are a 5-book “The Developer” series which be...more
|
 |
 |
 |
 |
LEVAL AINAH
I am an internet marketer and also an educator. My goal is to help others who are looking to improve...more
|
 |
 |
 |
 |
TIM FAY
After 60-plus years of living, I am just trying to pass down some of the information that I have lea...more
|
 |
 |
 |
 |
GENE MYERS
Author of four books and two screenplays; frequent magazine contributor. I have four other books "in...more
|
 |
 |
 |
 |
ADRIAN JOELE
I have been involved in nutrition and weight management for over 12 years and I like to share my kn...more
|
 |
 |
 |
 |
MICHAEL BRESCIANI
Rev Bresciani is the author of two Christian books. One book is an important and concisely written b...more
|
 |
 |
 |
 |
PAUL PHILIPS
For more articles, blog messages & videos and a free e-book download go to www.NewParadigm.ws your p...more
|
 |
 |
 |
 |
ALEX BELSEY
I am the editor of QUAY Magazine, a B2B publication based in the South West of the UK. I am also the...more
|
 |
 |
|