Upload
akash-mahajan
View
2.590
Download
0
Embed Size (px)
DESCRIPTION
Why should startups take care about security or answer to the question who will hack my server.
Citation preview
www.pcsafety.in [email protected] SS 14th June 2008
Do Startups Need to Worry about Security ?
Or Why Will Anyone Hack My Servers ?
www.pcsafety.in [email protected] SS 14th June 2008
Do Startups Need to Worry about Security ?
YES, and here is why. Three recent headlines
Web infection attacks more than 100,000 pages [ theregister.co.uk on 24th April 2008 ]
Drive-by download attack compromises 500,000 websites
[ channelregister.co.uk on 13th May 2008 ] Hackers 'seeding' legitimate websites. A 220% increase in
Web-based malware [ vunet.com on 9th June 2008]
www.pcsafety.in [email protected] SS 14th June 2008
But how is this relevant to my startup ?
Do you have a web application as your interface to the end user?
Are you letting your users add content to the web app ?
Are you trusting your users to be always benign ?
Would you want to serve malware unknowingly ?
Do your developers understand XSS, CSRF & SQL injection ?
Do Startups Need to Worry about Security ?
www.pcsafety.in [email protected] SS 14th June 2008
For bandwidth to host and serve malware.
To add one line of extra code to download trojans.
To use your site as a conduit while performing other attacks.
Because on the web bad guys trade hosting space as currency.
Because some script kiddie is learning how to do all this
Why Will Anyone Hack My Servers ?
www.pcsafety.in [email protected] SS 14th June 2008
Educate developers to follow secure coding principals.
Add security testing as an integral part of app testing.
Making sure the testing covers OWASP Top 10 vulnerabilities.
So what exactly can we do about this ?
www.pcsafety.in [email protected] SS 14th June 2008
But why, what is the point ?
Loosing trust on line can be a death knell for a startup.
Legally you are responsible for what is on your website.
Keeping yourself secure makes good business sense anyway
www.pcsafety.in [email protected] SS 14th June 2008
Been working on Info Sec domain for the past 3 years.
Worked with CDAC Bangalore securing their web and email
servers.
Bootstrapped End Point Security and IDS teams for StillSecure
Flying Solo from 1st of July to help companies with Info Security
You have any questions about security come talk to me.
So what is my angle ? Why am I telling youall this ?
BLOG / WEBSITEwww.pcsafety.in [email protected]