---
title: Mitigating the Risks of Poor Web Programming
description: A few lines of poorly programmed code should not be the end of the defense system for any web application
image: https://email.networksgroup.com/hubfs/Blogs/programming.jpg
---

- info@networksgroup.com
- [Contact Us](https://www.networksgroup.com/contact/)

- <https://www.facebook.com/networksgroupinc/>
- <https://www.facebook.com/networksgroupinc/>
- <https://twitter.com/networksgroup>
- [mailto:info@networksgroup.com](mailto:info@networksgroup.com)

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_300-154x42.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_1500px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

<https://email.networksgroup.com/mitigating-the-risks-of-poor-web-programming#sidr>

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

# NetWorks Group Blog

# Mitigating the Risks of Poor Web Programming

Posted by [NetWorks Group](https://email.networksgroup.com/author/networks-group) on Jul 14, 2012 9:04:00 AM

![](https://email.networksgroup.com/hubfs/Portraits/NWG.png)

Find me on:

[Facebook](https://www.facebook.com/networksgroupinc/) [LinkedIn](https://www.linkedin.com/company/networks-group) [Twitter](https://twitter.com/networksgroup)

- [Tweet](https://twitter.com/share)

If you weren't paying attention during the early Summer months this year, you may have missed the [overwhelming rate at which web sites were being publicly compromised and mocked](http://en.wikipedia.org/wiki/LulzSec). Often, these sites were prone to compromise due to SQL injection and other common web site vulnerability avenues. Even [Barracuda Networks was compromised](http://www.internet-security.ca/internet-security-news-archives-031/barracuda-networks-servers-hacked-into-sql-injection-style.html) when apparently they took down their own security product for maintenance and were taken advantage of.

The reality is that even [large corporations](http://attrition.org/security/rant/sony_aka_sownage.html), [banks](http://www.foxbusiness.com/personal-finance/2011/06/09/citigroup-hacked-heres-what-to-do-if-are-victim/), and [public organizations](http://www.huffingtonpost.com/2011/05/30/pbs-hacked-tupac-alive_n_868673.html) aren't having their web sites developed nearly as well as you'd expect. Often, much attention is given to a company's internal infrastructure, their end-user PCs, and the network holding together operations. 

The web presence of a company may just be an afterthought, something left for the creative and marketing people to get their brand out. However, in too many cases, web sites provide people a place to store personal information, re-used passwords, and don't adequately protect that information from would-be attackers.

Considering the frequency of occurrence, the reality of insecurely programmed web applications, and a lack of due-diligence on the part of developers, other steps should be taken to ensure a few lines of code doesn't land you on the front page of a newspaper or web site.

1. Using a SQL proxy (such as [GreenSQL](http://www.greensql.com/)) can help to provide an added-layer of security in the event of code that wasn't properly protected against this all-too-common type of attack. By using GreenSQL or similar, your database queries will pass through the sanity checks of the proxy first, before actually reaching your database. This intermediary step will likely thwart any attempts to steal information from a customer database or otherwise. 
2. Deployment of a web application firewall (WAF) is a common method to help prevent not only SQL injection, but other attacks such as local file inclusion (LFI). If you're in a larger environment, you may want to take a look at [Barracuda's offering](https://www.barracuda.com/products) (just remember to keep it turned on...) or [Imperva's offering](http://www.imperva.com/products/wsc_web-application-firewall.html). If you have an Apache web server with perhaps simpler needs, [ModSecurity](http://www.modsecurity.org/) has been a long-standing free option that is quick to deploy, albeit a little challenging to tweak.
3. Browser-based vulnerability testing utilities such as those from [Security Compass](https://addons.mozilla.org/en-US/firefox/user/1792636/) allow even a novice to check a site before it gets deployed to production. This is certainly not a route to go for serious security testing of an application, but if you're a manager in charge of a programming team, it can't hurt to give their newest code a once-over with a few FireFox plugins.
4. Lastly, professional security testing tools can be utilized by a security team or other well-trained technical users to give a final vetting to web applications before the public has a shot at them. There's no shortage of these tools but a few notable ones to look at are [Core Security's CORE IMPACT Pro](http://www.coresecurity.com/core-impact-pro), [Google's Skipfish](https://code.google.com/p/skipfish/), [CIRT's Nikto2](http://www.cirt.net/nikto2), and [HP's WebInspect](http://www8.hp.com/us/en/software-solutions/software.html?compURI=1337262#.UWsHIpN32So).

Ultimately, a few lines of poorly programmed code should not be the end of the defense system for any web application (or any application, for that matter). By utilizing some or all of the above, greater insight into the efficacy of code can be determined before an attack occurs. There's no reason why one programmer should allow your entire company's user database to be stolen.

 Topics: [Ethical Hacking](https://email.networksgroup.com/topic/ethical-hacking), [Information Security](https://email.networksgroup.com/topic/information-security), [Security Architecture Review](https://email.networksgroup.com/topic/security-architecture-review), [Compliance](https://email.networksgroup.com/topic/compliance), [Penetration Testing](https://email.networksgroup.com/topic/penetration-testing)

### Subscribe to our blog!

### Stay Informed!

### Recent Posts

### Posts by Topic

- [Information Security (50)](https://email.networksgroup.com/topic/information-security)
- [Threat Management (34)](https://email.networksgroup.com/topic/threat-management)
- [Ethical Hacking (31)](https://email.networksgroup.com/topic/ethical-hacking)
- [Managed Detection & Response (25)](https://email.networksgroup.com/topic/managed-detection-response)
- [Penetration Testing (21)](https://email.networksgroup.com/topic/penetration-testing)
- [Vulnerability Management (12)](https://email.networksgroup.com/topic/vulnerability-management)
- [Compliance (11)](https://email.networksgroup.com/topic/compliance)
- [Security Monitoring (11)](https://email.networksgroup.com/topic/security-monitoring)
- [Healthcare (9)](https://email.networksgroup.com/topic/healthcare)
- [Threat Advisory (8)](https://email.networksgroup.com/topic/threat-advisory)
- [Threat Hunting (7)](https://email.networksgroup.com/topic/threat-hunting)
- [Security Architecture Review (6)](https://email.networksgroup.com/topic/security-architecture-review)
- [HIPAA (5)](https://email.networksgroup.com/topic/hipaa)
- [Device Management (4)](https://email.networksgroup.com/topic/device-management)
- [Incident Response (4)](https://email.networksgroup.com/topic/incident-response)
- [Events (1)](https://email.networksgroup.com/topic/events)
- [PCI (1)](https://email.networksgroup.com/topic/pci)

see all

###### About Us

NetWorks Group is a Managed Detection & Response (MDR) and Ethical Hacking Service provider. We help organizations detect and respond to advanced cyber security threats through a powerful combination of our proprietary threat detection platform, expertise and security tools. Our unique approach to security not only helps you stay ahead of cyber criminals but also helps you reduce cost and increase efficiency.

###### More Links

- [Home](https://www.networksgroup.com/)
- [Blog](http://blog.networksgroup.com/)
- [About](https://www.networksgroup.com/about/)

###### Contact Us

(888) 798-1012  
 info@networksgroup.com  
 www.networksgroup.com

- <https://www.facebook.com/networksgroupinc/>
- <https://www.linkedin.com/company/networks-group>
- <https://twitter.com/networksgroup>

© 2017 - NetWorks Group