Symantec: Given the vast amount of work that is done online today, websites are a prime target for cybercriminals. Although the methods used in online attacks are relatively well-known, protecting against threats remains elusive for many companies and they tend to settle for it. The complexity of the internet, combined with its poor infrastructure, makes many websites vulnerable and the threat is constantly increasing.
According to the latest Symantec Internet Security Threat Report, there were 6,787 vulnerabilities in 2013, compared to 5,291 in 2012. Even more alarming is the fact that one in eight websites had critical, unpatched, known vulnerabilities, with 67% of websites used to distribute malware that appears to be genuine/legitimate.
Over the past few years, the volume of malware on the Internet has increased dramatically, and this is due to the use of automation and exploit kits.

Hackers use ready-made software containing a wide range of malware and exploit kits to carry out automated “drive-by” attacks, spreading malware and reaching unsuspecting users. With exploit kits, cybercriminals can easily improve their attacks and try multiple hacking tactics to exploit identified vulnerabilities.
The high prevalence of these tools is evident in the average number of malicious websites blocked on a daily basis. The increasing popularity of exploit kits used on the Internet not only creates fertile ground for hackers to attack, but also raises the bar for companies to protect their infrastructure.
Today, any website can be compromised by cybercriminals and used to attack your data. Below are five of the most common attack methods that continue to plague many websites. Tips from "Open Web Application Security (OWASP)" for a detailed description of the methods are presented below:

1. SQL Injection
SQL injection is a code injection technique that inserts malicious SQL statements into an input field and causes information that should not be returned to the web server. As a result, the web server provides access to information that should be secure, such as usernames and passwords.
2. Cross-Site Scripting (XSS)
Cross-Site Scripting is the most widespread web application security vulnerability that occurs when an application takes untrusted data and sends it to a web browser without proper authorization. This allows attackers to execute scripts in victims' browsers when they visit a website, which can result in hijacking user sessions, vandalizing websites, or redirecting the user to malicious websites.
3. CSRF (Cross-Site Request Forgery)
A CSRF attack steals the victim's cookies and other authentication information used to log in to a vulnerable website. Once the process is complete, the attacker can control the victim's session, for example on a banking website, and gain full control over the account. However, because the website assumes that a legitimate user is logged in, it is very difficult to detect when the attack is successful.
4. Use of Components with Known Vulnerabilities
Components such as libraries, frameworks, and other software modules that have known vulnerabilities have become easy prey for attackers. However, as we saw with the recent HeartBleed virus, effective patch management and secure coding can be difficult, especially for complex web applications. Applications that use components with known vulnerabilities can undermine the application's defense mechanisms and allow a range of potential attacks to occur.
5. Man in the Middle
A man-in-the-middle attack interferes with the communication between two systems. For example, in an HTTP transaction, the target is the TCP connection between a client and a server. In some cases, we have seen websites transfer sensitive information without strong enough encryption.
These common web vulnerabilities exist largely due to a lack of protection in the web application code itself. In theory, this means that vulnerabilities can be prevented by implementing best practices in the Software Development Life Cycle (SDLC). However, the pace of change and the demanding nature of evolving business requirements means that many organizations struggle to implement security in their SDLC until it is too late.
For many businesses, security is still reactive and is often implemented after the attacker has already done the damage. Symantec recommends that businesses leverage security in the development process, so that it is designed into the web application from the beginning. The cost of a potentially slow development process to create secure code outweighs the risks of waiting until it is revealed that you have been the victim of a sophisticated campaign targeting your sensitive data.
In addition, it is recommended that both the development and production environments be jointly monitored for any external threats. Most of the common attacks have known IDS/IPS signatures, making them easy for Symantec Managed Security Services to detect and alert and take action for a quick remediation.

