In the early days of the commercial web, there were enough vulnerabilities in web servers and operating systems that black hats could easily exploit these infrastructural elements. However, as things progressed, software developers began hardening these components against attack. Eventually, this caused attackers to shift their focus towards web-based applications, especially those using dynamic scripting, such as PHP. In the first of two articles exploring attacks on web applications, David Watson, leader of the UK Honeynet Project, explores the evolution of web based attacks, charting how we reached our current point. He also examines how the constant drive towards new functionality hindered the security process as companies attempted to cram new features into products at the expense of secure development. Web browsers, web servers and HTTP were relative latecomers to the underlying infrastructure of the embryonic internet. They began life between 1989 and 1992 as simple tools for sharing static content between servers and clients using hyperlinks. Their ease of use, combined with the development of extensions to support dynamic content, helped to make web interfaces commonplace. Web application development became increasingly rapid and often included application code to extend core service functionality. This was at odds to the standard approach of other relatively mature network services.
No takes yet. Share an insight, caveat, or question.
David Watson (2007) studied this question.