Home | Links | Contact Us | Press | Post a job | Bookmark
Search jobs:
Home Latest press releases Ecommerce-sites-panned-for-lack-of-security-testing


 Safety Engineer
Major Responsibilities: The Safety Engineer will be responsibile for coordinating and leading ...


 Service Technician - Forklift
Forklift service mechanic needed for Dothan branch of Toyota Materials Handling. Minimum 3 yrs. ...


 Service Manager (or start as Assistant with growth to SM)
Management opportunity in the growing field of Yacht Service; ideal candidate would have - · &...


 Development Director
JOB SUMMARY:   Plans, develops, implements, administers, evaluates, and monitors an aggressive ...


 Medical Sales-Women's Health-Obstetrical Services
    MRI Atlanta Peachtree North 3235 S. Cherokee Lane, Suite 1210 Woodstock, GA 30188 &...


 Inventory Specialist - Brewton, Alabama
DXP Enterprises, Inc. ( DXPE ) is a leading products and services distributor that adds value and ...


 Onsite Manager - Brewton, Alabama
DXP is a market leader in the distribution of capital equipment, technical services, MROP products ...


 Onsite Order Specialist - Brewton, Alabama
DXP Enterprises, Inc. ( DXPE ) is a leading products and services distributor that adds value and ...


 Sawmill Supervisor
Tired of city living? Ready for fresh air and green grass? Lumber company located in Pine Hill, AL ...


 DOD Acquisition Manager
We provide engineering and technical services in the areas of systems engineering and analysis, ...


 Ecommerce sites panned for lack of security testing

Despite a series of high-profile online security blunders at leading retailers such as Argos and B&Q in recent years, companies selling online are still failing to train staff to look for bugs and glitches which could betray customer details or give rise to fraud.
While sophisticated hackers might always find a way into a system, many companies, such as the two mentioned above, are guilty of some basic failings which would have been discovered within minutes of penetration testing, according to a leading expert.
Dan Newman has been running one of the most popular certified ethical hacking courses for three years at the UK-based Training Camp and says he's not seen a single student from an ecommerce company put forward to attend, while financial institutions, government departments and the military are well up on the need for penetration testing.
"We had one guy who worked for a retailer but he funded it himself because he was actually looking to move into a new job in a different sector," said Newman.
While this doesn't mean ecommerce sites have never honed their penetration-testing skills, Newman is confident he'd have seen some of them through his classroom at least, or heard of their efforts if such skills were commonly used in the online retail sector.
Newman walkedthrough a very basic 'hack' which simply involves changing cookies to access any number of customers' details on one ecommerce website. By doing so a hacker would be able to download paid-for documents from other users' accounts with one keystroke.
Newman blames a lot of the failings on the pressures of the retail environment and on developers charged with getting functionality online in time to meet demand, rather than when it is ready.
"I used to be a developer and I used to make the same mistakes they do," said Newman.
Newman said a lot of the time "they're getting things out there as quickly as they can" without regard for security.
"Some websites are just bulging at the seams," said Newman, referring to the multitude of security weaknesses just waiting to be exploited in the ecommerce sector.
Firebox.com is one online retailer happy to talk about its penetration testing. A spokeswoman for the firm confirmed it continually tests its perimeters and is pleased with the results of such vigilance.
"Our IT team regularly check all of our security and always start with anywhere there could be a potential problem and thankfully they have always been pleasantly surprised but you still have to test," said the spokeswoman. "This is our business and if shoppers are going to feel confident shopping online then security is our bread and butter."
But others aren't so responsible and put too much faith in partners and third parties, said Newman.
"I feel bad for a lot of companies who buy products from vendors who know nothing of security," added Newman. But just because e-tailers deal with a third party vendor doesn't abdicate responsibility for carrying out their own thorough penetration testing.
Ecommerce sites are facing stricter regulation in the wake of serious security failings.


Related jobs
  District Manager
About the Company Headquartered in Sanford, North Carolina, The Pantry, Inc. is the leading independently operated convenience store chain in the southeastern United S...
  Store Manager
About the Company Headquartered in Sanford, North Carolina, The Pantry, Inc. is the leading independently operated convenience store chain in the southeastern United S...
  Retail Managers in Training
  RadioShack has excellent career opportunities available for individuals who display a high energy level, self-motivation and the desire to succeed. The Assistant M...
  Inventory Manager - Anniston, Alabama
SEEKING HIGHLY MOTIVATED, CUSTOMER DRIVEN INVENTORY MANAGERS!   WIS International is one of ht largest inventory service providers in the world.  We ...
  ACCOUNT MANAGER
Are you looking for a career? At Rent-ACenter we don't just promise a career, we give you the tools to make it happen. Need proof? - 90% of our Store Managers are hired ...
  Sunglass Hut – Sales Associate
Organization Description: You know them. You love them. Now join the team that brings them to the world. At Sunglass Hut, a member of the Luxottica Retail family, we ...
  Merchandise manager
Small, fast growing retail chain needs person to visit stores and make improvements. Will assist General Manager in making merchandising/marketing/personnel changes. W...
  Salon Manager - Oxford, AL
Job Description: JCPENNEY SALON MANAGER - OXFORD, AL JCPenney, The Leading Authority in Hair Color, is looking for a talented SALON MANAGER for the salon in our OXFORD, A...
  NEEDED: ENTRY LEVEL RETAIL SKILLS TO HELP US GROW! MAKE UP TO $40K - $100K+ A MONTH!
Want to Create an Extra Income Stream? Do You Have Entry Level Retail Skills?? Put your Skills to use and make up to $24k+ a MONTH!! I will get straight to the point - ...
  Job Fair
MANAGEMENT HIRING EVENT JOIN THE LEADER TAKE A LOOK AT OUR NUMBERS AND SEE WHY YOU WANT TO EXPLORE BEING WITH BED BATH & BEYOND   Debt Free; Increase in Sales from $...

Related press releases
Summit attempts to keep the Net international
A research centre at Harvard University is offering itself as a venue for last-ditch attempts to preserve the international nature of the Internet. The summit, schedul...
UK's first computer hacking degree launched
A degree course in computer hacking has been launched by a Scottish university in response to industry demand for IT security experts. The University of Abertay in Dun...
Mexico sells itself as 'nearshore' outsourcing hub for US
While Europe looks to India as its offshoring destination of choice, Mexico has launched an initiative to promote itself to the US as a 'nearshoring' destination that's s...
IT chiefs look to the internet - and their kids - for inspiration
Leading financial sector IT bosses have admitted to looking not at each other or even at rival organisations for inspiration when it comes to innovation - rather they are...
Egypt touts itself as next offshore outsourcing hot-spot
Egypt is making a pitch to be the next offshore outsourcing hot-spot, claiming that its foreign language skills and low labour costs put the country in a strong position ...
Massachusetts appoints new CIO
Massachusetts has named a permanent chief information officer, who will be in charge of carrying out the state's OpenDocument policy. The administration of Governor Mi...
Former HP CEO dies at 64
Lew Platt, the man who ran HP for several years and engineered the spin-off of Agilent Technologies, died on Thursday of a brain aneurism. He was 64. Since 2003, Platt...
Amazon under fire for desecrated Koran
A Muslim group has demanded a public apology from online bookseller Amazon.com for its part in delivering a used copy of the Koran with the words "Death to all Muslims" s...
Another Tiger leaker settles with Apple
Apple Computer has reached a settlement with a second man it had accused of leaking prerelease versions of Mac OS X Tiger onto the internet. An Apple representative co...
Stolen laptop puts 98,000 at risk of ID theft
The University of California at Berkeley is warning more than 98,000 people that the theft of a laptop from its graduate school admissions office has exposed their person...
0.914

Archive: All jobs - Links

Copyright (c)2006 Efbfweb.org/jobs - All rights reserved

Wordpress Themes | Credit Consolidation | Web Master | Credit Consolidation | Nutritional Supplements