Warning: INSERT command denied to user 'dbo290624456'@'74.208.16.205' for table 'watchdog' query: INSERT INTO watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:12:\"user warning\";s:8:\"%message\";s:378:\"INSERT command denied to user 'dbo290624456'@'74.208.16.205' for table 'captcha_sessions'\nquery: INSERT into captcha_sessions (uid, sid, ip_address, timestamp, form_id, solution, status, attempts) VALUES (0, 'e8d09e0d8f134ca4d87861402cbdf130', '38.107.179.214', 1329011076, 'comment_form', 'undefined', 0, 0)\";s:5:\"%file\";s:87:\"/homepages/30/d251750219/htdocs/tecspeak/sites/tecspeak.com/modules/captcha/captcha.inc\";s:5:\"%line\";i:92 in /homepages/30/d251750219/htdocs/tecspeak/includes/database.mysqli.inc on line 128
Coder's Top 25 Worst Bungles Enable Cyber Espionage and Cybercrime | Tecspeak.com
user warning: INSERT command denied to user 'dbo290624456'@'74.208.16.205' for table 'captcha_sessions' query: INSERT into captcha_sessions (uid, sid, ip_address, timestamp, form_id, solution, status, attempts) VALUES (0, 'e8d09e0d8f134ca4d87861402cbdf130', '38.107.179.214', 1329011076, 'comment_form', 'undefined', 0, 0) in /homepages/30/d251750219/htdocs/tecspeak/sites/tecspeak.com/modules/captcha/captcha.inc on line 92.

Coder's Top 25 Worst Bungles Enable Cyber Espionage and Cybercrime

Printer-friendly versionSend to friendPDF version

High-profile organizations Including Microsoft, the NSA, the SANS Institute and Mitre have collectively issued a list of the top 25 most dangerous programming errors which committed by software writers that result in security bugs and enable cyber espionage and cybercrime.

The list was compiled by more than 30 experts from cyber security organizations in the U.S. and other countries.

Just two of the errors alone led to more than 1.5 million web site security breaches in 2008. The report states that those breaches in turn compromised the computer of people visiting those sites, turning the computer into so-called zombie machines. "In one case in 2008, more than 1 million Web sites were penetrated and infected and made to infect visitors' computers - and those were trusted sites like the United Nations, state government and others.

Error Messages
Insecure Interaction Between Components.
the nine programming mistakes under this heading include: Improper input validation, improper encoding or escaping output, failure to preserve SQL query structure, aka SQL Injection and failure to preserve Web page structure aka cross-site scripting. In the report , nine other errors fall under Risky Resource Management, and the seven fine error have been classified as Porous Defense issues.

Some of the consequences can be very significant. For example, the 'CWE-89: Failure to Preserve SQL Query Structure, said Richard Wang, U.S. Manager at SophoLabs.

Universities should be forced to teach and test all current programmers for secure coding skills and fill their gaps using the GAIC (Global Information Assurance Certification) Secure Software Programmer Test, Paller said.

Comments

Cybercrime

Nice Post, Useful for developing Software

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <b>
  • Lines and paragraphs break automatically.
  • You may insert videos with [video:URL]

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.
Image CAPTCHA
Enter the characters shown in the image.


Warning: INSERT command denied to user 'dbo290624456'@'74.208.16.205' for table 'watchdog' query: INSERT INTO watchdog (uid, type, message, variables, severity, link, location, referer, hostname, timestamp) VALUES (0, 'php', '%message in %file on line %line.', 'a:4:{s:6:\"%error\";s:12:\"user warning\";s:8:\"%message\";s:439:\"INSERT command denied to user &#039;dbo290624456&#039;@&#039;74.208.16.205&#039; for table &#039;accesslog&#039;\nquery: INSERT INTO accesslog (title, path, url, hostname, uid, sid, timer, timestamp) values(&#039;Coder&amp;#039;s Top 25 Worst Bungles Enable Cyber Espionage and Cybercrime | Tecspeak.com&#039;, &#039;node/96&#039;, &#039;&#039;, &#039;38.107.179.214&#039;, 0, &#039;e8d09e0d8f134ca4d87861402cbdf130&#039;, 718, 1329011077)\";s:5:\"%file\";s:77:\"/homepages/30/d251750219/htdocs/tecspeak/modules/s in /homepages/30/d251750219/htdocs/tecspeak/includes/database.mysqli.inc on line 128