Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

[caption id="attachment_824" align="aligncenter" width="720"]Ebay website hacked Ebay website hacked[/caption] Ecommerce websites have become a popular target for the hackers. Recent breaches on EBay, Flip kart has brought many Ecommerce website security issues. If you have an EBay account, you would probably be thinking how to protect your credential details stored over the website.

Top security issues for an Ecommerce website

1) Database security issue

SQL injection is the common attack generally made on that website which store ample amount of data. Websites like PayPal which stores credential details of the clients are more vulnerable to the SQL injection attack. Hacker's analysis web applications with diverse inquiries and extract customer details from the database.

Also SEE: VBulletin found vulnerable to SQL injection attack

2) Cross site scripting (XSS) attack

Next in the list of ecommerce website security issues is cross site scripting (XSS) attack. This attack is generally seen where web applications take untrusted data from the user and submit it over the browser. XSS can take customer details and could be used in redirection. Users are redirected to many malicious websites. XSS attack made in Ecommerce websites is generally protected by using web application firewall.

Also SEE: Authentication bypass using cookie tampering (A case study)

3.) DOS attack

Denial of service attack is made through a sudden increase in the traffic over the server. DOS attack adds extra load over the server and results into the website getting down. The attack could go on for hours and even for day. You can well imagine how big loss could it be for and Ecommerce website getting down for 1 day.

Also SEE: Easiest way to make DDOS and DOS attack

[caption id="attachment_825" align="aligncenter" width="488"]Ecommerce website EBay breached Ecommerce website EBay breached[/caption]

4) Two step authentication for Admins

The recent breach over EBay forced company to compromise over more than 50 million customer details. Hackers used social engineering with social phishing tricks to extract 60% encrypted passwords. A two-step authentication in which authentication key would be provided through email or mobile SMS would increase the security.

Also Check out

[caption id="attachment_496" align="alignleft" width="150"]Certified Network security expert Certified Network security expert[/caption] [caption id="attachment_735" align="alignleft" width="150"]Server Hardening services Server Hardening services[/caption]

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.