The Web Application Security Consortium (WASC) is pleased to announce the WASC Web Application Security Statistics Project 2007. This initiative is a collaborative industry wide effort to pool together sanitized website vulnerability data and to gain a better understanding about the web application vulnerability landscape. We ascertain which classes of attacks are the most prevalent regardless of the methodology used to identify them. Industry statistics such as those compiled by Mitre CVE project provide valuable insight into the types of vulnerabilities discovered in open source and commercial applications, this project tries to be the equivalent for custom web applications. There is also a PDF available for download.
Topics
Tags
- Announcements (85)
- Articles (51)
- Blue Team (2)
- Books (1)
- Browsers (77)
- Buzzwords (30)
- Commentary (44)
- Compliance (9)
- Cryptography (17)
- CSRF (32)
- Defense (80)
- Demo (2)
- Development (88)
- Events (33)
- Flash (13)
- Forensics (15)
- Funny (96)
- Incidents (213)
- IndustryNews (387)
- Interviews (15)
- Metrics (17)
- Off Topic (29)
- Papers (19)
- Purple Team (1)
- Rant (49)
- Red Team (2)
- Research (166)
- Reviews (17)
- SDL (50)
- Security Tools (113)
- SEO (15)
- Site News (21)
- Surveys (7)
- Tools (29)
- Uncategorized (87)
- Vendors (37)
- Vulns (169)
- WASC (48)
- Web Application Firewalls (18)
- Worms (32)
- XSS (84)
WASC Announcement: 2007 Web Application Security Statistics Published
Favorite Links
- Security Templates (New)
- The Web Application Security Consortium
- QA Security
- The Web Security Mailing List
- Romain Gaucher’s Blog
- Jeremiah Grossman’s Blog
Popular Pages
WASC Threat Classification
- Abuse of Functionality
- Application Misconfiguration
- Brute Force Attack
- Content Spoofing
- Credential/Session Prediction
- Denial of Service
- Directory Indexing
- Information Leakage
- Remote File Inclusion Attack
- Routing Detour Attack
- SOAP Array Abuse
- XML Attribute Blowup
- XML Injection
- XML External Entity Attack