7
www.pcsafety.in [email protected] SS 14 th Do Startups Need to Worry about Sec Or Why Will Anyone Hack My Ser

Startups Security

Embed Size (px)

DESCRIPTION

Why should startups take care about security or answer to the question who will hack my server.

Citation preview

Page 1: Startups Security

www.pcsafety.in [email protected] SS 14th June 2008

Do Startups Need to Worry about Security ?

Or Why Will Anyone Hack My Servers ?

Page 2: Startups Security

www.pcsafety.in [email protected] SS 14th June 2008

Do Startups Need to Worry about Security ?

YES, and here is why. Three recent headlines

Web infection attacks more than 100,000 pages [ theregister.co.uk on 24th April 2008 ]

Drive-by download attack compromises 500,000 websites

[ channelregister.co.uk on 13th May 2008 ] Hackers 'seeding' legitimate websites. A 220% increase in

Web-based malware [ vunet.com on 9th June 2008]

Page 3: Startups Security

www.pcsafety.in [email protected] SS 14th June 2008

But how is this relevant to my startup ?

Do you have a web application as your interface to the end user?

Are you letting your users add content to the web app ?

Are you trusting your users to be always benign ?

Would you want to serve malware unknowingly ?

Do your developers understand XSS, CSRF & SQL injection ?

Do Startups Need to Worry about Security ?

Page 4: Startups Security

www.pcsafety.in [email protected] SS 14th June 2008

For bandwidth to host and serve malware.

To add one line of extra code to download trojans.

To use your site as a conduit while performing other attacks.

Because on the web bad guys trade hosting space as currency.

Because some script kiddie is learning how to do all this

Why Will Anyone Hack My Servers ?

Page 5: Startups Security

www.pcsafety.in [email protected] SS 14th June 2008

Educate developers to follow secure coding principals.

Add security testing as an integral part of app testing.

Making sure the testing covers OWASP Top 10 vulnerabilities.

So what exactly can we do about this ?

Page 6: Startups Security

www.pcsafety.in [email protected] SS 14th June 2008

But why, what is the point ?

Loosing trust on line can be a death knell for a startup.

Legally you are responsible for what is on your website.

Keeping yourself secure makes good business sense anyway

Page 7: Startups Security

www.pcsafety.in [email protected] SS 14th June 2008

Been working on Info Sec domain for the past 3 years.

Worked with CDAC Bangalore securing their web and email

servers.

Bootstrapped End Point Security and IDS teams for StillSecure

Flying Solo from 1st of July to help companies with Info Security

You have any questions about security come talk to me.

So what is my angle ? Why am I telling youall this ?

BLOG / WEBSITEwww.pcsafety.in [email protected]