WhiteHat: 90 percent of websites vulnerable to attack

Nine out of 10 websites have vulnerabilities open to attack, according to a new report by WhiteHat Security.

Cross-site scripting (XSS) is the No. 1 class of vulnerability, impacting three-quarters of websites, according to the company's third WhiteHat Website Security Statistics Report.

New techniques such as XSS-phishing, intranet hacking and web worms may force enterprises to re-evaluate the viability of XSS on a case-by-case basis, the company said.

The report also features a comparison of vulnerabilities across vertical markets, including the retail, health care, financial services, IT and insurance industries. While web security remains generally weak, the retail sector has performed better than other markets, according to WhiteHat.

Since the company's April report, it has seen a "noticeable increase" in XSS, information leaks, SQL injections and HTTP response splitting. The company attributes the increase to the discovery of new attack techniques and improvements in vulnerability-identification technology.

HTTP response splitting has been “a misunderstood and underestimated issue, evading most scanning technology since its discovery several years ago,” WhiteHat said in a statement. This form of web application vulnerability, caused by the failure of the application or its environment to properly sanitize input values, can be used to perform XSS attacks, cross-user defacement, web cache poisoning and other attacks.

WhiteHat called the results "startling both in the prevalence and potential consequences of HTTP response splitting exploits."

“Statistics continue to reveal recurring and emerging issues that are affecting websites across industries," said Jeremiah Grossman, WhiteHat founder and chief technology officer.

More in News

Operators again revive Pushdo botnet, use a popular tactic to stay hidden ...

Botnet operators are using a domain-generation algorithm to conceal their command-and-control center. And once they knew security researchers were on to their tricks, they got even slicker.

Mac spyware discovered on Angolan dissident's computer at Oslo Freedom Forum

Mac spyware discovered on Angolan dissident's computer at ...

Security researchers are studying an apparent new strain of Mac malware that turned up on the computer of a participant at the just-concluded Oslo Freedom Forum, an annual human rights ...

Judge in London sentences LulzSec members

Judge in London sentences LulzSec members

The sentences range from 20 to 32 months, with none of the defendants likely to serve the full time. There has been no formal request to extradite the U.K. men ...