The Register®

Original URL: http://www.theregister.co.uk/2003/02/27/uk_ecommerce_sites_top/

UK e-commerce sites: Top 10 flaws

Basic errors

By John Leyden

Posted in Security, 27th February 2003 22:25 GMT

Free whitepaper – Out-of-box comparison between Dell, HP, and IBM blade servers

UK customer credit card details and sensitive data is at risk because of simple e-commerce flaws, according to a study published this week.

Web server flaws, poor authentication mechanisms and faulty log-out facilities are the most widespread problems, with most flaws caused by relatively basic mistakes, according to security testing outfit NTA Monitor.

The top ten most common e-commerce flaws discovered by NTA Monitor, listed in order of frequency, are:

Roy Hills, technical director, NTA Monitor, said, "Our experience shows that simple faults are worryingly common - and on a level that can be exploited even by the most unsophisticated hackers. Given that security issues are the biggest inhibitor for online buyers, we were surprised to find that companies are not sealing their defences more thoroughly."

NTA Monitor recommends that companies should enforce security policies to take account of the flaws it highlights. More detailed advice can be found here (http://www.nta-monitor.com/news/eflaws-detail.htm).

NTA Monitor's research was conducted from October 2002 to January 2003 and is based on flaws commonly discovered by NTA during security assessments of authenticated web access and e-commerce systems. Further details of the Top 10 list are available here (http://www.nta-monitor.com/news/eflaws-detail.htm). ®

Related Stories

Want to know the ten most critical web app vulnerabilities? (http://www.theregister.co.uk/content/55/28862.html)
FBI names 20 most unwanted security flaws (http://www.theregister.co.uk/content/archive/27407.html)