{"id":5305,"date":"2019-02-27T08:51:22","date_gmt":"2019-02-27T08:51:22","guid":{"rendered":"https:\/\/www.register365.com\/blog\/?p=5305"},"modified":"2019-11-14T15:46:18","modified_gmt":"2019-11-14T15:46:18","slug":"4-vulnerabilities-to-check-in-your-website-security-test-pack","status":"publish","type":"post","link":"https:\/\/www.register365.com\/blog\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/","title":{"rendered":"4 vulnerabilities to check in your website security test pack"},"content":{"rendered":"<p>Rather than having traditional applications installed on local PCs, more and more businesses are choosing to run essential services from the cloud. This increased reliance on web applications and the ever greater volume of financial transactions being carried out online means that the security of websites is more important than ever.<\/p>\n<p>Testing your website security is, therefore, essential. It ensures that data remains confidential and that third-parties can\u2019t tamper with the functionality of the site. In testing the security of a website, there are some key areas that you need to focus on.<\/p>\n<h2>Passwords<\/h2>\n<p>The hacking of accounts using compromised credentials &#8211; either stolen in a phishing attack or due to poor practices leading to weak passwords &#8211; is one of the most common causes of data breaches. It\u2019s therefore important to make sure your website passwords can\u2019t be easily cracked.<\/p>\n<p>It\u2019s possible to find lists of common weak passwords online along with password cracking tools so you can check your site\u2019s effectiveness. You should ensure that the site enforces a policy of strong passwords &#8211; minimum length and including a mix of lowercase and capitals, numerals and special characters. You also need to ensure that usernames and passwords are stored in encrypted form so that even if they are stolen, they are difficult for a hacker to exploit.<\/p>\n<h2>URL manipulation via HTTP<\/h2>\n<p>Another key aspect of website security is the way in which information is passed between the client and the server. If an application uses HTTP GET to do this, then it\u2019s possible for a hacker to manipulate the information sent so that users can be sent to a fake version of a website for example. Testing, therefore, needs to check how requests are being sent.<\/p>\n<h2>SQL injection<\/h2>\n<p>Using SQL injection methods, a hacker can get access to information stored in an online database. This type of attack usually takes place via text boxes on the site, if the user input in a box is passed straight to a query program then it could be vulnerable to SQL injection. You can test for this by entering a single inverted comma (\u2018) in a text box &#8211; if a database error results then your application could be at risk.<\/p>\n<p>When input data is passed to an SQL query it\u2019s possible for an attacker to enter SQL commands and either gain information from the database or cause the application to crash. You can guard against this by configuring the site to reject the input of certain special characters into text boxes.<\/p>\n<h2>Cross-site scripting<\/h2>\n<p>Cross-site scripting (XSS) attacks can be used to execute a malicious piece of JavaScript code on an end user\u2019s web browser. This can be in order to steal information stored in cookies, to explore user information stored in the browser, or to divert the browser to a malicious URL. In order to prevent XSS attacks, sites should be configured not to accept HTML or script code.<\/p>\n<p>Finally, in carrying out any of these tests, it\u2019s important that they are run on development versions and not on live sites!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Rather than having traditional applications installed on local PCs, more and more businesses are choosing to run essential services from the cloud. This increased reliance on web applications and the&#8230; <a class=\"more-link\" href=\"https:\/\/www.register365.com\/blog\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/\">Read more &rarr;<\/a><\/p>\n","protected":false},"author":22,"featured_media":5181,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[],"class_list":["post-5305","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>4 vulnerabilities to check in your website security test pack<\/title>\n<meta name=\"description\" content=\"Testing your website security is essential - in testing the security of a website, there are some key areas that you need to focus on.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"4 vulnerabilities to check in your website security test pack\" \/>\n<meta property=\"og:description\" content=\"Testing your website security is essential - in testing the security of a website, there are some key areas that you need to focus on.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/\" \/>\n<meta property=\"og:site_name\" content=\"Register365 Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/register365\" \/>\n<meta property=\"article:published_time\" content=\"2019-02-27T08:51:22+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-11-14T15:46:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.register365.com\/blog\/wp-content\/uploads\/2019\/01\/Your-online-security.png\" \/>\n\t<meta property=\"og:image:width\" content=\"945\" \/>\n\t<meta property=\"og:image:height\" content=\"425\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Nathan\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nathan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/\",\"url\":\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/\",\"name\":\"4 vulnerabilities to check in your website security test pack\",\"isPartOf\":{\"@id\":\"https:\/\/www.register365.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.register365.com\/blog\/wp-content\/uploads\/2019\/01\/Your-online-security.png\",\"datePublished\":\"2019-02-27T08:51:22+00:00\",\"dateModified\":\"2019-11-14T15:46:18+00:00\",\"author\":{\"@id\":\"https:\/\/www.register365.com\/blog\/#\/schema\/person\/b8684be81b9b651f59d97f7bac864748\"},\"description\":\"Testing your website security is essential - in testing the security of a website, there are some key areas that you need to focus on.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#primaryimage\",\"url\":\"https:\/\/www.register365.com\/blog\/wp-content\/uploads\/2019\/01\/Your-online-security.png\",\"contentUrl\":\"https:\/\/www.register365.com\/blog\/wp-content\/uploads\/2019\/01\/Your-online-security.png\",\"width\":945,\"height\":425,\"caption\":\"secure website\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Register365\",\"item\":\"\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\/\/www.register365.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Security\",\"item\":\"https:\/\/www.register365.com\/blog\/category\/security\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"4 vulnerabilities to check in your website security test pack\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.register365.com\/blog\/#website\",\"url\":\"https:\/\/www.register365.com\/blog\/\",\"name\":\"Register365 Blog\",\"description\":\"Welcome to the Register365 blog! Keep up to date with our latest news and product updates, find out more about our Free Online Business Training, and share your comments with us!\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.register365.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.register365.com\/blog\/#\/schema\/person\/b8684be81b9b651f59d97f7bac864748\",\"name\":\"Nathan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.register365.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/b849f2ae94026a2583ec808f66065701dbebe5ca9a87e51fab1269f2853c4a71?s=96&d=identicon&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/b849f2ae94026a2583ec808f66065701dbebe5ca9a87e51fab1269f2853c4a71?s=96&d=identicon&r=g\",\"caption\":\"Nathan\"},\"description\":\"Nathan has been with team.blue since 2005 and has a background in Technical Support. He is passionate about helping customers find the best product for them and use it to its full potential. In his free time you'll find him on a train travelling through some beautiful countryside, or curled up on a sofa with his head in a book.\",\"url\":\"https:\/\/www.register365.com\/blog\/author\/nathan\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"4 vulnerabilities to check in your website security test pack","description":"Testing your website security is essential - in testing the security of a website, there are some key areas that you need to focus on.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/","og_locale":"en_GB","og_type":"article","og_title":"4 vulnerabilities to check in your website security test pack","og_description":"Testing your website security is essential - in testing the security of a website, there are some key areas that you need to focus on.","og_url":"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/","og_site_name":"Register365 Blog","article_publisher":"https:\/\/www.facebook.com\/register365","article_published_time":"2019-02-27T08:51:22+00:00","article_modified_time":"2019-11-14T15:46:18+00:00","og_image":[{"width":945,"height":425,"url":"https:\/\/www.register365.com\/blog\/wp-content\/uploads\/2019\/01\/Your-online-security.png","type":"image\/png"}],"author":"Nathan","twitter_misc":{"Written by":"Nathan","Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/","url":"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/","name":"4 vulnerabilities to check in your website security test pack","isPartOf":{"@id":"https:\/\/www.register365.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#primaryimage"},"image":{"@id":"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#primaryimage"},"thumbnailUrl":"https:\/\/www.register365.com\/blog\/wp-content\/uploads\/2019\/01\/Your-online-security.png","datePublished":"2019-02-27T08:51:22+00:00","dateModified":"2019-11-14T15:46:18+00:00","author":{"@id":"https:\/\/www.register365.com\/blog\/#\/schema\/person\/b8684be81b9b651f59d97f7bac864748"},"description":"Testing your website security is essential - in testing the security of a website, there are some key areas that you need to focus on.","breadcrumb":{"@id":"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#primaryimage","url":"https:\/\/www.register365.com\/blog\/wp-content\/uploads\/2019\/01\/Your-online-security.png","contentUrl":"https:\/\/www.register365.com\/blog\/wp-content\/uploads\/2019\/01\/Your-online-security.png","width":945,"height":425,"caption":"secure website"},{"@type":"BreadcrumbList","@id":"https:\/\/www.register365.com\/blog\/2019\/02\/4-vulnerabilities-to-check-in-your-website-security-test-pack\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Register365","item":"\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/www.register365.com\/blog\/"},{"@type":"ListItem","position":3,"name":"Security","item":"https:\/\/www.register365.com\/blog\/category\/security\/"},{"@type":"ListItem","position":4,"name":"4 vulnerabilities to check in your website security test pack"}]},{"@type":"WebSite","@id":"https:\/\/www.register365.com\/blog\/#website","url":"https:\/\/www.register365.com\/blog\/","name":"Register365 Blog","description":"Welcome to the Register365 blog! Keep up to date with our latest news and product updates, find out more about our Free Online Business Training, and share your comments with us!","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.register365.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.register365.com\/blog\/#\/schema\/person\/b8684be81b9b651f59d97f7bac864748","name":"Nathan","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.register365.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/b849f2ae94026a2583ec808f66065701dbebe5ca9a87e51fab1269f2853c4a71?s=96&d=identicon&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/b849f2ae94026a2583ec808f66065701dbebe5ca9a87e51fab1269f2853c4a71?s=96&d=identicon&r=g","caption":"Nathan"},"description":"Nathan has been with team.blue since 2005 and has a background in Technical Support. He is passionate about helping customers find the best product for them and use it to its full potential. In his free time you'll find him on a train travelling through some beautiful countryside, or curled up on a sofa with his head in a book.","url":"https:\/\/www.register365.com\/blog\/author\/nathan\/"}]}},"_links":{"self":[{"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/posts\/5305","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/comments?post=5305"}],"version-history":[{"count":1,"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/posts\/5305\/revisions"}],"predecessor-version":[{"id":5307,"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/posts\/5305\/revisions\/5307"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/media\/5181"}],"wp:attachment":[{"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/media?parent=5305"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/categories?post=5305"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.register365.com\/blog\/wp-json\/wp\/v2\/tags?post=5305"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}