Posted in

3 Common Web Application Attacks – And How to Defeat Them

Today’s businesses rely on the internet as a key facilitator of operations. It’s how they sell their products. It’s how they market themselves. It’s even how they communicate with customers and provide post-sale services. But it’s also one of their biggest sources of risk.

The reason for that is simple. The internet‘s a dangerous place that’s filled with bad actors looking to exploit vulnerable sites and platforms for monetary gain. And the recent pandemic has only expanded the size of the threat. The result is that businesses – especially small ones – must take immediate steps to protect their internet-facing operations. And that means securing their websites, applications, and data.

To do that, businesses must understand the types of threats they’re likely to face and how they can defend themselves. To help, here are the three most common types of web application attacks and how to defeat them.

Injection Attacks

According to IBM‘s X-Force cybersecurity unit, injection attacks are by far the most common type of attack on web-facing applications and networks. The reason for that is the fact that multiple platforms and technologies are vulnerable to that attack vector. But the most dangerous among them are SQL injection attacks.

In a SQL injection attack, an attacker attempts to gain privileged access to a SQL database by altering an ordinary query sent by a web application. For example, they may try to hijack a web form input to send a modified database call in its place. And if the application doesn’t know to reject such a malformed input, the attack will succeed, and the attacker could exfiltrate whatever data they wish. It’s how some of the biggest data thefts in recent years happened.

It is possible, though, to defend against SQL injection attacks. There are four principal ways to accomplish it:

  • Using prepared statements and variable binding – A method of specifying query intent that can reject unexpected data inputs
  • Input validation with an allowed list – A method that checks SQL command inputs and rejects any unexpected characters or data
  • Stored procedures and queries – A method that stores all permissible database procedures and queries inside the database itself and rejects any external command modifications
  • User input escapes – A method that utilizes database-specific character escapes to validate user input while rejecting input without the proper escape sequence

Distributed Denial of Service Attacks

Another common web application attack is known as a distributed denial of service (DDoS) attack. It’s a method hackers use to disable web applications by flooding them with concurrent requests until they no longer have the resources to respond. The most notable instance of this kind of attack happened back in 2016 when an attacker managed to disable the global DNS provider Dyn – effectively halting access to the internet itself for millions of users.

The trouble with DDoS attacks is that they operate under the assumption that no web application has unlimited resources. And that’s a situation that no business – no matter how large – can remedy. So, the only real defense against them is mitigation. There are two major ways to handle it.

The first is to deploy a web application firewall (WAF) that can detect malicious traffic and reject it before it reaches its target. But, that won’t necessarily keep the web application running because of bandwidth limitations. The best way to solve that problem is to use a content delivery network (CDN) as a way of scaling up capacity and eliminating the application’s main server as a possible single point of failure.

There are a variety of cloud solutions that combine WAF and CDN functionality that work well as a defense against DDoS attacks. And most of the time, all that’s necessary to use them is to alter the web application’s public DNS entries to route traffic through them. It’s a change that a business’s domain registrar can help them make with few other alterations necessary to their web application itself.

Cross-Site Scripting Attacks

The third common web application attack that businesses should guard against is called a cross-site scripting (XSS) attack. It happens when a hacker identifies vulnerable code in a web application that allows them to alter the application’s code itself, or substitute malicious code in its place. And XSS attacks are difficult to spot, often until it’s too late.

One of the most notorious examples of an XSS attack happened late in 2018 when British Airways discovered some unauthorized changes to its online booking application. With just 22 lines of code, an attacker managed to steal the identities and credit card details involved in about 380,000 transactions. Obviously, by the time the changes became apparent – it was too late to prevent that breach.

But there are a variety of tactics that businesses can use to defend their web applications from XSS attacks. The first is to minimize users’ ability to input data through forms and fields. If a form submission isn’t strictly necessary, it shouldn’t exist. And all remaining forms should use input validation and output encoding to be sure that nobody can exploit them by inputting malicious code. And finally, all modern web applications should include a properly defined content security policy to define which kinds of code are safe to run and which aren’t.

Reducing Vulnerabilities Is Essential

At the end of the day, businesses will remain engaged in a cat-and-mouse game with hackers and other malicious actors online. But, by taking away their most common avenues of attack, it is possible to stay one step ahead of the bad guys. Of course, the three types of attacks detailed here aren’t the only threats that business web applications must face. But there’s a reason they’re so common. It’s because they’re easy to execute and extremely effective. And sometimes, making yourself the least appealing target is the best way to stay safe, after all.

 

My primary focus is a fusion of technology, small business, and marketing. I’m an editor, writer, marketing consultant and guest author at several authority websites. In love with startups, latest tech trends and helping others get their ideas off the ground.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.