Home | Links | Contact Us | Press | Post a job | Bookmark
Search jobs:
Home Latest press releases Ecommerce-sites-panned-for-lack-of-security-testing


 Project Manager II - Capital Improvements
Project Manager II – Capital Improvements Flagstaff , Arizona $52,326 to $76,837 Annually, DOE ...


 Project Manager
Large, dynamic travel related services company seeks a Project Manager to join their facility in P...


 Deputy Project Manager - National Quality Monitoring Contractor Project (VBHT-6SHNXW)
Imagine working in an environment that encourages innovation while nurturing a commitment to public ...


 Manager, Program Control
Since our founding in 1982, Orbital has pioneered new classes of rockets, satellites and other ...


 CSPD Instrument Tech Ld
Overview : This is a lead tech position with in CSPD. Evening position hours are 2:30pm - 11:00pm, 4...


 Project Coordinator
Project Coordinators needed!!!   Are you interested in working as a Project Coordinator for a F...


 Supply Chain Data Analyst
Contract position available with a major aerospace client located in Tempe, AZ. Candidate will ...


 Project Manager IS
Job Description Major Responsibilities: - Reporting to the Director PMO and Data Warehouse. The P...


 Enterprise Ntwk Analyst Sr
Overview : Banner Health, Arizona's largest healthcare provider has a full time opportunity for an ...


 Project Manager
DataLink Software Consultants is actively seeking a PROJECT MANAGER in the Phoenix area.   D...


 Ecommerce sites panned for lack of security testing

Despite a series of high-profile online security blunders at leading retailers such as Argos and B&Q in recent years, companies selling online are still failing to train staff to look for bugs and glitches which could betray customer details or give rise to fraud.
While sophisticated hackers might always find a way into a system, many companies, such as the two mentioned above, are guilty of some basic failings which would have been discovered within minutes of penetration testing, according to a leading expert.
Dan Newman has been running one of the most popular certified ethical hacking courses for three years at the UK-based Training Camp and says he's not seen a single student from an ecommerce company put forward to attend, while financial institutions, government departments and the military are well up on the need for penetration testing.
"We had one guy who worked for a retailer but he funded it himself because he was actually looking to move into a new job in a different sector," said Newman.
While this doesn't mean ecommerce sites have never honed their penetration-testing skills, Newman is confident he'd have seen some of them through his classroom at least, or heard of their efforts if such skills were commonly used in the online retail sector.
Newman walkedthrough a very basic 'hack' which simply involves changing cookies to access any number of customers' details on one ecommerce website. By doing so a hacker would be able to download paid-for documents from other users' accounts with one keystroke.
Newman blames a lot of the failings on the pressures of the retail environment and on developers charged with getting functionality online in time to meet demand, rather than when it is ready.
"I used to be a developer and I used to make the same mistakes they do," said Newman.
Newman said a lot of the time "they're getting things out there as quickly as they can" without regard for security.
"Some websites are just bulging at the seams," said Newman, referring to the multitude of security weaknesses just waiting to be exploited in the ecommerce sector.
Firebox.com is one online retailer happy to talk about its penetration testing. A spokeswoman for the firm confirmed it continually tests its perimeters and is pleased with the results of such vigilance.
"Our IT team regularly check all of our security and always start with anywhere there could be a potential problem and thankfully they have always been pleasantly surprised but you still have to test," said the spokeswoman. "This is our business and if shoppers are going to feel confident shopping online then security is our bread and butter."
But others aren't so responsible and put too much faith in partners and third parties, said Newman.
"I feel bad for a lot of companies who buy products from vendors who know nothing of security," added Newman. But just because e-tailers deal with a third party vendor doesn't abdicate responsibility for carrying out their own thorough penetration testing.
Ecommerce sites are facing stricter regulation in the wake of serious security failings.


Related jobs
  Physical Therapist/Physical Therapist Assistant
Sports Rehabilitation of Alabama Providing Excellence in Sports & Industrial Orthopaedic Rehabilitation Great opportunity to work in a fast paced, progressive ...
  Rehabilitation Clinic Managers Needed (Inpatient or Outpatient Rehab-Manager Experience Considered)
Candidates must be either U.S Citizens or have a valid Green Card for consideration, no exceptions. **It is our strict company policy that all communication is ...
  Clinical Director (Physical Therapy)
CLINICAL DIRECTOR (PHYSICAL THERAPY) iMPact Business Group provides strategic staffing solutions to clients in the Information Technology, Accounting/Finance and H...
  Physical Therapist-ALABAMA Flex Hrs, Sign-on Bonus, Relocation$
Title: Physical Therapist Location: Birmingham, Alabama   Description: Our client in Jasper, AL has an immediate opening for a Physical Therapist (PT). This ...
  Director of Healthcare Rehabilitation ( Fortune 500 Corporation's Location in Birmingham, AL )
Candidates must be either U.S Citizens or have a valid Green Card for consideration, no exceptions. **It is our strict company policy that all communication is ...
  Physical Therapist
About the Opportunity We are currently recruiting a Physical Therapist in Mobile, Alabama. This position offers an exciting opportunity to join a team of dedicated ...
  SPEECH LANGUAGE PATHOLOGIST/SPEECH LANGUAGE PATHOLGIST ASSISTANT
SPEECH LANGUAGE PATHOLOGIST     Children’s Rehab & Therapy Services, Inc. (CRTS) has Full-time and part time positions available for a Speech Language P...
  Rehab Program Manager
Rehab Program Manager Join our fun IN-HOUSE rehab team at Cedar Crest Health & Rehabilitation Center in , Montgomery , Alabama .   Our quality-focused facility ...
  Physical Therapists or Physical Therapist Assistants
Practice your passion in therapy with our fun and friendly IN-HOUSE rehab teams in Montgomery and Selma , Alabama .   Our quality-focused nursing & rehab facilities ...
  Occupational Therapist/OTR/OT
SunDance Rehabilitation is looking for a full-time Occupational Therapist for two skilled nursing facilities in Fayetteville and Ardmore.  Have the peace of mind ...

Related press releases
Small businesses miss out on e-filing incentive
Small businesses don't know they could pick up on a tax-free payment from the government for filing their employers' annual return online. If they file their return on...
IT industry to take on 3 Peaks Challenge for charity
The UK IT industry is being urged to sign up for a 3 Peaks Challenge in aid of CARE International. The event, sponsored by Vanco and will see teams scale the three highe...
5 years ago... Ford offers staff '$5 per month' PCs
2/4/2000: Ford Motor Company is offering all its US employees the chance to own a PC with internet access and a colour printer for a nominal fee of $5 per month. Accor...
CEOs, CIOs share buying decisions at SMEs
For smaller businesses, corporate management - including CEOs, COOs, CFOs and owners - takes a hands-on approach when it comes to procuring IT goods and services. Corp...
UK contractor rates plummet
The second half of 2004 has seen average hourly rates for contractors fall and a furthering of the divide which sets London and the South-East apart from the rest of the ...
ID cards won't comply with data protection laws
The UK's data protection watchdog has again hit out at the government's ID card scheme, claiming it is not compliant with data protection laws. Information Commissione...
IT insurance fraudster jailed
A former Lloyds of London insurance consultant who scammed IT businesses into buying worthless policy cover using forged documents has been jailed for two-and-a-half year...
Surprise paper trail costs taxpayer extra ?145m
The Criminal Records Bureau (CRB) - set up in 2002 to help employers vet staff wanting to work with children or vulnerable adults - has seen its cost soar from a planned ...
Bosses 'too trusting' of outsourcer's security
CEOs aren't taking the care that they should with their customers' data when they outsource, according to a new survey of senior management. The Ernst & Young Global I...
Jeeves the butler disappears from web
Internet butler Jeeves - the star of eponymous search engine Ask Jeeves - has gone missing, leaving many to wonder where he's gone and when or if he will be back. Othe...
0.004

Archive: All jobs - Links - Job Search Engines - Medical Encyclopedia



Copyright (c)2006 Efbfweb.org/jobs - All rights reserved