We have been testing for several common compromises on actual sites during our web crawling efforts for our search engine. A staggering 5% of all sites we crawl have had problems with injections, redirects, poorly constructed permissions leaving directories open and most commonly fully search-able directory structures.
The number of insecure sites is staggering.
|