Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Which will Rely on to Identify Web Security Issues?
Articles

Which will Rely on to Identify Web Security Issues?

Ilia KolochenkoBy Ilia KolochenkoSeptember 7, 2015Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

With today’s security risks constantly changing, current web solutions may not be as effective as companies think. Not only do businesses have to compete with other vendors, they also face threats from cyber criminals looking to take advantage of security vulnerabilities they have failed to detect and patch.

One answer to cyber threats is continuous monitoring, which is becoming a very popular term, both among security vendors and CISOs. In a constantly changing and hostile network environment where new zero-day exploits appear  regularly, continuous monitoring of your organization’s infrastructure is essential. The main role of continuous monitoring is to keep your security team constantly aware of newly detected vulnerabilities, weaknesses, missing patches and configuration flaws that appear to be exploitable.

Various products, solutions and services exist today to assure the continuous monitoring process within both large and small organizations. However, when examining the efficiency of such solutions, businesses should initially try to understand how competitive those solutions are on the market: and not [only] against other vendors’ solutions, but with Black Hat hackers. Yes, you heard right – with Black Hats, who are also in competition when it comes to the timely and reliable detection of vulnerabilities in external infrastructure.

Jan Schreuder, partner, cybersecurity leader from PwC Switzerland, summarized the risks for businesses: “Cyber attackers operate in real time and are not waiting for organizations to complete their next vulnerability assessment or patch release cycle. Security risks are continually evolving and challenge organizations to look for ways to proactively identify, evaluate, and manage cyber risks.”

Let’s take corporate web applications as an example of competition between White Hats and Black Hats in the continuous monitoring business. Websites have become a very efficient starting point for Advanced Persistent Threats against organizations. Moreover, corporate web applications themselves can bring a great financial income to cybercriminals. A majority of web security researchers in recent years estimated that over 80 percent of websites are vulnerable, hackers could obviously not miss such a great opportunity to make easy money.

At my current work place, I have the opportunity to manage and participate in our daily practice of web penetration testing and managed vulnerability scanning. We often face compromised web applications and websites. While examining logs in order to understand how and when a system was compromised, we regularly face “continuous monitoring” by cyber gangs.

At a first glance, it’s not obvious to distinguish between various spam bots and simple hack crawlers launched by newbies, and professional scanning infrastructure implemented by Black Hats that can easily compete with major scanning vendors from Gartner’s Magic Quadrant.

I would slightly disagree that professional Black Hats use the same tools as penetration testers – they may rely on some open-source or commercial solutions (including free trials provided by many vendors), but they have the competency and money to develop their own tools “in-house” that perfectly suit their business needs that are quite different from the needs of penetration testing companies.

Server infrastructure for such monitoring can be easily purchased from VPS and cloud providers who fight among each other for new customers. Money-hungry hosting companies will often prefer to close their eyes as long as possible before suspending someone’s account. And even after suspension, hackers can easily recover their data from a [cloud] backup. Investigation of such cases is often pointless: cybercriminals have fully functional and totally anonymous payment methods.

Usually money passes via several different payment options and systems, converting mobile payments into crypto currencies, before transferring them to a pre-paid credit card obtained online with a stolen or fake ID. Simplified e-payment and money transfer systems, kindly developed by financial institutions for developing countries, is a real gift for hackers.

Let’s take a closer look at the scanning infrastructure at the disposal of cybercriminals. Like cybersecurity vendors, cyber gangs specialize in different niches. There are hacking teams in charge of continuous scanning and identification of potential victims: they crawl the Web in real-time searching for vulnerable websites with high Google Page Rank or Alexa Rating.

Hacking teams have efficient fingerprinting technologies to detect installed web applications, their modules, versions and patches. In our experience, for this purpose hackers usually take open-source software as a scanning platform base, improve its scanning and vulnerability detection algorithms, and adopt it for their needs. Often they have dozens or even hundreds of synchronized servers, forming a powerful scanning infrastructure capable of monitoring whatever they need.

An interesting feature is a regularly updated black list of domains/IPs of honeypots, security companies or law enforcement agencies – hackers tend to avoid probing them so not to expose themselves. Another interesting feature are priority lists – a list of high-priority targets (e.g. large e-commerce businesses or highly popular websites) that will be probed before others when a new zero-day is released, again – to outperform the competition.

Black Hats are very quick to detect and exploit new vulnerabilities in your system. According to the Drupal Security Team “Automated attacks began compromising Drupal 7 websites [that were not patched or updated] within hours of the announcement of the vulnerability”. Drupal clearly said that every [Drupal] website should be considered compromised unless patched within the first few hours of the vulnerability being announced. Many security vendors would envy such rapidity.

Once a vulnerable software version is detected, an alert is sent to other hacking teams specialized in exploitation (larger hacking teams can afford to perform the entire process “in-house”).

Usually exploitation is done automatically, but the exploits used are pretty advanced: hackers have different attack scenarios for different conditions and configurations (e.g. simple WAF bypass, exploitation within a chroot, insufficient permissions to create temporary files, non-standard admin panel location, older versions of MySQL, etc).

Once compromised, the victim’s application will be backdoored and sold for further exploitation on the black market. Usually, backdoors are very complicated to detect, unless you know every single file in your web root and constantly verify their checksums, but unfortunately, such systems are very rare. Moreover, complicated web applications can be backdoored via databases, allowing unprivileged users to execute arbitrary code that is silently stored in a tiny table of the DB.

Sophisticated hacking teams even patch the vulnerabilities after successful exploitation to prevent their competitors from exploiting them. Yes, there is as tough a competition among cyber gangs as there is among cyber security vendors. Mainly such patches are done via an auto-update mechanisms (if available) or through non-suspicious changes, so website owners will not question why the new vulnerability does not affect their installation. Therefore, if you see that a well-known vulnerability is not exploitable in your system – it may be a bad sign.

Yes, properly implemented continuous monitoring is not an easy task. Jan Schreuder (PwC) summarizes the challenge for businesses: “In our experience the successful implementation of a continuous monitoring program often represents a significant change to the way IT departments operate, and to be successful it requires significant commitment through leadership support, enforcement, and system owner responsibility and accountability.”

However, if you don’t want Black Hats to monitor and patch your systems for you – take the time to implement continuous monitoring correctly within your organization.

[su_box title=”About Ilia Kolochenko” style=”noise” box_color=”#336588″][short_info id=’60198′ desc=”true” all=”false”][/su_box]

Ilia Kolochenko

Ilia Kolochenko is a Swiss application security expert and entrepreneur. He started his career as a penetration tester and has 15 years of experience in security auditing and digital forensics. After serving in Swiss artillery troops in 2007, Ilia founded his first pentesting and cybersecurity consultancy High-Tech Bridge. In 2014, Frost & Sullivan named the company a leading service provider in the European pentesting market. Later Ilia invented and built the concept of the ImmuniWeb Platform, which combines the strengths of human intelligence with Machine Learning, and is now entirely dedicated to it.As a Chief Architect at ImmuniWeb, he leads our data scientists, security analysts and software engineers. Ilia holds a bachelor degree in Computer Science and Mathematics from Webster University, a Master of Legal Studies from Washington University in St. Louis and a Master of Science in Criminal Justice (Cybercrime Investigation) from Boston University. Currently, Ilia is a Doctoral student (Ph.D. in Cybersecurity Leadership) at Capitol Technology University. Ilia Kolochenko is a member of Europol Data Protection Experts Network (EDEN), a Member of GIAC Advisory Board and a Committee Member at Boston University MET CIC (Cybercrime Investigation & Cybersecurity) Center. Ilia is a certified GIAC GLEG professional (Law of Data Security & Investigations) and a Certified Information Privacy Professional (CIPP/US and CIPP/E) by IAPP.

  • Ilia Kolochenko
    Japan Hit By Another Cryptocurrency Heist – $60 Million Stolen
  • Ilia Kolochenko
    Web Application Firewall: a must-have security control or an outdated technology?
  • Ilia Kolochenko
    How to Calculate ROI and Justify your Cybersecurity Budget
  • Ilia Kolochenko
    Hackers Break into Businesses’ Websites and Apps

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}