---
title: Beware the wild west of Web applications
description: Beware the wild west of Web applications
---

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/head-logo-2.svg "TowerWall")](https://towerwall.com/)

[![TowerWall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/towerwall-logo-white-test.svg "TowerWall")](https://towerwall.com/)

- [Our Partners](https://towerwall.com/how-we-protect-you/our-technology-partners/)
- Our Solutions 
    - - Our Cybersecurity Solutions 
                  - We operationalize infosec,  
                     building security solutions that  
                     safeguard your most critical assets.
          - - [Solutions Overview](https://towerwall.com/cybersecurity-solutions/)
                  - [Risk Assessments & Security Reviews](https://towerwall.com/cybersecurity-solutions/risk-assessments-security-reviews/)
                  - [Program & Policy Development](https://towerwall.com/cybersecurity-solutions/program-policy-development/)
                  - [Incident Response & Remediation](https://towerwall.com/cybersecurity-solutions/incident-response-remediation/)
                  - [Managed Detection & Response](https://towerwall.com/cybersecurity-solutions/managed-detection-response/)
          - - [Compliance & Privacy](https://towerwall.com/cybersecurity-solutions/compliance-privacy/)
                  - [Comprehensive Security Training](https://towerwall.com/cybersecurity-solutions/comprehensive-security-training/)
                  - [Vulnerability Protection](https://towerwall.com/cybersecurity-solutions/vulnerability-protection/)
                  - [Penetration Testing](https://towerwall.com/cybersecurity-solutions/penetration-testing/)
- Virtual Security Officers 
    - - Virtual Security Officer 
                  - Leverage the experience and  
                     security acumen of Towerwall’s  
                     on-demand security experts.
          - - [Virtual Chief Information Security Officer (VCISO)](https://towerwall.com/virtual-security-officers/virtual-chief-information-security-officer-vciso/)
                  - [Virtual Data Protection Officer (vDPO)](https://towerwall.com/virtual-security-officers/virtual-data-protection-officer-vdpo/)
                  - [Virtual Chief Privacy Officer (vCPO)](https://towerwall.com/virtual-security-officers/virtual-chief-privacy-officer-vcpo/)
- We Advise 
    - - We Advise 
                  - One-size security solutions only  
                     lead to failure.
          - Industries 
                  - [Higher Education](https://towerwall.com/industries/higher-education/)
                  - [Financial Services & Banking](https://towerwall.com/industries/financial-services-banking/)
                  - [Healthcare](https://towerwall.com/industries/healthcare/)
                  - [BioPharma & Bio-Therapeutics](https://towerwall.com/industries/biopharma-bio-therapeutics/)
                  - [Retail](https://towerwall.com/industries/retail/)
                  - [Government](https://towerwall.com/industries/government/)
                  - [Catholic Diocese](https://towerwall.com/industries/catholic-diocese-cybersecurity/)
                  - [Cannabis](https://towerwall.com/industries/cannabis/)
                  - [Small Business](https://towerwall.com/industries/small-business/)
                  - [Enterprise](https://towerwall.com/industries/enterprise/)
          - Trends & Threats 
                  - [Remote Workforce](https://towerwall.com/trends-threats/remote-workforce/)
                  - [Vendor Questionnaire](https://towerwall.com/trends-threats/vendor-questionnaire/)
                  - [HIPAA](https://towerwall.com/trends-threats/hipaa/)
                  - [Ransomware](https://towerwall.com/trends-threats/ransomware/)
                  - [GDPR](https://towerwall.com/trends-threats/gdpr/)
                  - [Cloud Security](https://towerwall.com/trends-threats/cloud-security/)
                  - [Phishing](https://towerwall.com/trends-threats/phishing/)
                  - [Cybersecurity Insurance](https://towerwall.com/trends-threats/cybersecurity-insurance/)
- [Resources](https://towerwall.com/resources/) 
    - - Resources 
                  - Our latest insights, events,  
                     and tools to keep you safe.
          - - [Insights](https://towerwall.com/resources/?resources_category=MTU%3D&focusarea=0&industries=0&search=)
                  - [Webinars](https://towerwall.com/resources/?resources_category=MTg%3D&focusarea=0&industries=0&search=)
                  - [Whitepapers](https://towerwall.com/resources/?resources_category=MTY%3D&focusarea=0&industries=0&search=)
                  - [View All](https://towerwall.com/resources/)
- [Company](https://towerwall.com/company/) 
    - - Our Company 
                  - We are the industry’s leading cybersecurity preparedness partner.
          - - [Who We Are](https://towerwall.com/company/)
                  - [Our Team](https://towerwall.com/company/our-team/)
                  - [Our Approach](https://towerwall.com/our-approach/)
                  - [Our Values](https://towerwall.com/company/our-values/)
          - - [Awards & Recognition](https://towerwall.com/company/awards-recognition/)
                  - [Certifications & Affiliations](https://towerwall.com/company/certifications-affiliations/)
                  - [Community Involvement](https://towerwall.com/company/community-involvement/)
                  - [Careers](https://towerwall.com/company/careers/)
                  - [Contact Us](https://towerwall.com/company/contact-us/)

Topics  Security Partners, network security, Security Services, security software, Web Storage, Data Security, Security Regulations, Security Threat, Security Program, Information Security, web server, Application Security, Security, Cloud Security, Web Application Firewall, security policy, penetration testing, information security tips, Compliance, Web Browser, web users, cannabis, cybersecurity, Enterprise

# Beware the wild west of Web applications

[By Michelle Drolet](https://blog.towerwall.com/author/towerwall2020)

[Read More](https://blog.towerwall.com/author/towerwall2020)

 2 Minute Read

May 02, 2012

Web applications – particularly those facilitating collaboration and communication – are a boon to sales, marketing and productivity. Teams work together more effectively, salespeople enjoy better leads and marketing tools and customer service reps can more closely connect with those they serve.  
 All of these gains, though, come at a cost: risk. By their very nature, Web applications circumvent many enterprise security controls. They are designed to enable communication, not security. A paper by Sophos reported one new Web threat every 4.5 seconds. Its researchers found an average of 19,000 new malicious URLs daily in the first half of 2011; with 80 percent of those URLs pointing to legitimate sites that had been hacked or otherwise compromised.  
 Recent data from the Open Source Vulnerability Database (OSVD) shows that the number of new vulnerabilities disclosed decreased significantly during the first half of 2011. At first glance, this may appear as good news. But hold on. It’s not the number of vulnerabilities, but the number of disclosures of new vulnerabilities that has decreased. A distinction without a difference? Unfortunately, no.  
 Despite the decrease in disclosures of new vulnerabilities, websites of organizations of all types and sizes are still teeming with existing vulnerabilities, and remain open to potentially devastating attacks.  
 Worse yet, OSVD data show an increase in Web application attacks. According to HP DVLabs, the number of attacks on Web applications is “Ten times the number of vulnerabilities being reported.”  
 Sophos’ mid-2011 security threat report stated, “Two of the most common and effective attack methods used are cross-site scripting and SQL injection.”  The bad guys even sell packaged exploit toolkits – complete with how-to user guides – enabling the least technical of cybercrooks to get up to speed on doing no good.  
 Attackers don’t need to develop new Web-based attack methods, yet many have been added to the arsenal in recent years – in part to take advantage of the larger attack surface.  
 Among the newer methods are SEO poisonings, drive-by hits, malware hidden by URL shorteners, and countless scams that make use of social network “oversharing” – or simply the opportunities resulting from the sheer number of active users (witness Facebook’s 800 million fans). Even the least effective hacker can be successful when targeting such a huge number of potential victims.  
 The Web is also a haven for geo-political attacks. Two recent examples include “hacktivism,” illustrated by the cascade of Denial of Service attacks related to WikiLeaks – and cyber-warfare, or the use of IT attacks to wage war between nation-states. Cyber-warfare is behind the release of Stuxnet, considered the first malware to include a programmable logic controller and aimed directly at taking down several of Iran’s nuclear power plants in 2010. Still active, Symantec noted that 60 percent of the world’s infected computers are in Iran. Kaspersky and F-Secure also studied the worm and concluded that its sophistication could only be the work of nation-states. (Israel and the US are not above suspicion.) Your average bear web app need not worry about Stuxnet.  
 Small wonder that Iran is closing down Internet access to the entire country, starting with blocking Google, Yahoo and Hotmail, and replacing it with a government controlled intranet. “All internet service providers must only provide national internet by August 2012,”said Reza Taghipour, Iran’s Communication Minister, who also cited its case for doing so as wanting “to provide clean and filtered internet services to the county.” Good luck!  
 In its study on Web apps, Sophos also reported that 19,000 web sites were newly infected each day, and that over 80 percent of the malicious URLs examined turned out to be those of legitimate organizations whose websites had been hacked.  
 Do you know whether your organization’s Web applications contain easy-to-exploit vulnerabilities? Probably not, but if you do, what can you do about it? Most likely the only way out of this mess is conducting regular, ongoing vulnerability scanning and application penetration testing.  
**By Michelle Drolet, founder and CEO, Towerwall**

[This article was recently published in Mass High Tech](http://www.masshightech.com/stories/2012/04/30/daily28-Beware-the-wild-west-of-Web-applications-.html)

#### Beware the wild west of Web applications

Back to Top

## Related Insights

### [Webinar: What are your layers of defense?](https://blog.towerwall.com/webinar-what-are-your-layers-of-defense)

 Security Partners, network security, Security Services, security software, Web Storage, Data Security, Security Regulations, Security Threat, Security Program, Information Security, web server, Application Security, Security, Cloud Security, Web Application Firewall, security policy, penetration testing, information security tips, Compliance, Web Browser, web users, cannabis, cybersecurity, Enterprise

### [Watch our latest webinar: Second Nature Security](https://blog.towerwall.com/watch-latest-webinar-second-nature-security)

 Security Partners, network security, Security Services, security software, Web Storage, Data Security, Security Regulations, Security Threat, Security Program, Information Security, web server, Application Security, Security, Cloud Security, Web Application Firewall, security policy, penetration testing, information security tips, Compliance, Web Browser, web users, cannabis, cybersecurity, Enterprise

[View All Insights](https://blog.towerwall.com)

×

## Talk with us now about:

#### Your security needs.

- ![Phone](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/phone-icon.svg "Phone")
  
  [Call 774.204.0700](tel:774.204.0700)
- ![Mail](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/mail-icon.svg "Mail")
  
  [Email Us](mailto:info@towerwall.com)

### The front line of cybersecurity.™

For over 23 years, Towerwall, a woman-owned business, has helped scores of companies safeguard their data and leverage their investment in IT with advanced information security technology solutions and services. Our experience in all facets of information security coupled with serving in the CIO/CISO/ISO roles provides a unique first-hand understanding of the security challenges organizations face daily.

### Connect

- <https://blog.towerwall.com/info@towerwall.com>
- <https://www.linkedin.com/company/towerwall-inc.?trk=pro_other_cmpy>
- <https://twitter.com/Towerwall>
- <https://www.facebook.com/Towerwall>

- [Career Opportunities](https://towerwall.com/company/careers/)
- [Contact Us](https://towerwall.com/company/contact-us/)

© Towerwall, Inc. and its licensees. All rights reserved [Privacy Policy](http://towerwall.com/privacy-policy/) Sitemap [Created by Howbridge](https://meethowbridge.com/)

[![Towerwall](https://blog.towerwall.com/hubfs/raw_assets/public/Towerwall_July2021/images/footer-logo.svg "Towerwall")](https://towerwall.com/)