Whitehat Security has just released its 2013 Website Security Statistics Report. The study is based on vulnerability data collected from tens of thousands of websites belonging to over 650 companies or organizations.
It turns out that, last year, the average number of vulnerabilities present on the websites we see around us dropped to 56. In the previous year, each page was found to contain at least 79 vulnerabilities.
Of all the websites the security firm checked, 86% contained at least one serious vulnerability. 61% of the vulnerabilities had been addressed, but only 18% of the websites had been vulnerable for less than 30 days.
In terms of the time it takes to address vulnerabilities, Whitehat found that, on average, a company needs around 193 days after first notification.
Although the overall number of vulnerabilities has decreased, websites from IT and energy companies were found to be more vulnerable compared to previous years. In fact, last year, industrial websites had the highest number of security vulnerabilities per website, with 114 vulnerabilities.
Interestingly, the fewest errors were found on government websites and on bank websites.
WhiteHat provides a definition of the concept of “serious vulnerabilities”
[quote]“those in which an attacker could take control over all, or some part, of the website, compromise user accounts on the system, access sensitive data, violate compliance requirements, and possibly make headline news.”[/quote]
The report shows that the information leakage vulnerabilities found on 55% of websites were common. The “classic” method of cross-site scripting (XSS), plagues 53% of the websites tested. The table is completed by spoofing (33%), cross-site request forgery (26%), brute force (26%) and fingerprinting (23%).
“This data shows that many organizations have not taken their software security seriously. It is obvious that organizations are in a “wait-until-something-goes-wrong” phase,” said Jeremiah Grossman, co-founder and CTO of Whitehat Security.
The full report is available for download here (registration required).
