SlideShare a Scribd company logo
www.pcsafety.in   [email_address]   SS 14 th  June 2008 Do Startups Need to Worry about Security ? Or Why Will Anyone Hack My Servers ?
www.pcsafety.in   [email_address]   SS 14 th  June 2008 Do Startups Need to Worry about Security ? YES, and here is why. Three recent headlines Web infection attacks more than  100,000  pages  [ theregister.co.uk on 24 th  April 2008 ] Drive-by download attack compromises  500,000  websites  [ channelregister.co.uk on 13 th  May 2008 ] Hackers 'seeding' legitimate websites. A  220%  increase in Web-based malware  [ vunet.com on 9th June 2008]
www.pcsafety.in  akash@pcsafety.in  SS 14 th  June 2008 But how is this relevant to my startup ? Do you have a web application as your interface to the end user? Are you letting your users add content to the web app ?  Are you trusting your users to be always benign ?  Would you want to serve malware unknowingly ?  Do your developers understand XSS, CSRF & SQL injection ? Do Startups Need to Worry about Security ?
www.pcsafety.in  akash@pcsafety.in  SS 14 th  June 2008 For bandwidth to host and serve malware. To add one line of extra code to download trojans. To use your site as a conduit while performing other attacks. Because on the web bad guys trade hosting space as currency. Because some script kiddie is learning how to do all this Why Will Anyone Hack My Servers ?
www.pcsafety.in  akash@pcsafety.in  SS 14 th  June 2008 Educate developers to follow secure coding principals.  Add security testing as an integral part of app testing.  Making sure the testing covers  OWASP Top 10  vulnerabilities. So what exactly can we do about this ?
www.pcsafety.in  akash@pcsafety.in  SS 14 th  June 2008 But why, what is the point ?  Loosing trust on line can be a death knell for a startup. Legally you are responsible for what is on your website.  Keeping yourself secure makes good business sense anyway
www.pcsafety.in  akash@pcsafety.in  SS 14 th  June 2008 Been working on Info Sec domain for the past 3 years.  Worked with CDAC Bangalore securing their web and email servers. Bootstrapped End Point Security and IDS teams for StillSecure Flying Solo from 1 st  of July to help companies with Info Security You have any questions about security come talk to me.  So what is my angle ? Why am I telling you all this ?  BLOG / WEBSITE www.pcsafety.in [email_address]

More Related Content

PPTX
Fitsec-remote work and cyber security
PDF
Introduction To Web security
PPTX
University Innovation, Licensing, Commercialization, Entrepreneurship
PDF
unSEXY Conf 2013: Ainsley Braun, Tinfoil
PDF
"10 Tips To Keep Cybercriminals Out While Coronavirus Keeps You In" Infographic
PDF
10 Tips to Keep Criminals Out
PDF
WordPress News - March 2017
Fitsec-remote work and cyber security
Introduction To Web security
University Innovation, Licensing, Commercialization, Entrepreneurship
unSEXY Conf 2013: Ainsley Braun, Tinfoil
"10 Tips To Keep Cybercriminals Out While Coronavirus Keeps You In" Infographic
10 Tips to Keep Criminals Out
WordPress News - March 2017

What's hot (9)

PDF
ITAM AUS 2017 Harnessing the power of SAM Intelligence for Cyber Security
PPTX
D3TLV17- Keeping it Safe
PPTX
D3LDN17 - Keynote
PPTX
Kludges and PHP. Why Should You Use a WAF?
PPTX
Sucuri Webinar: How To Know For Sure You Can Trust A Plugin
PPTX
D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application La...
PDF
BGA Eğitim Kataloğu
PDF
Secure Your Asses
PDF
WordPress News - May 2018
ITAM AUS 2017 Harnessing the power of SAM Intelligence for Cyber Security
D3TLV17- Keeping it Safe
D3LDN17 - Keynote
Kludges and PHP. Why Should You Use a WAF?
Sucuri Webinar: How To Know For Sure You Can Trust A Plugin
D3TLV17- The Incapsula WAF: Your Best Line of Denfense Against Application La...
BGA Eğitim Kataloğu
Secure Your Asses
WordPress News - May 2018
Ad

Viewers also liked (17)

PPTX
Hybrid Cloud Computing - Seccurity Aspects and Challanges
PDF
App sec in the time of docker containers
PPTX
What is cloud ?
PPTX
Security in the cloud Workshop HSTC 2014
PPTX
Cloud Security Issues 1.04.10
PPTX
AWS Survival Guide
PPTX
Security Issues in Cloud Computing
PPTX
Burp Suite Starter
PPT
Security Issues of Cloud Computing
PDF
Cloud Security - Security Aspects of Cloud Computing
PPTX
DevOOPS: Attacks and Defenses for DevOps Toolchains
PPTX
Cloud computing security issues and challenges
PPTX
Cloud Computing Security
PPTX
Cloud security and security architecture
PDF
Time based CAPTCHA protected SQL injection through SOAP-webservice
PDF
The Secret Life of a Bug Bounty Hunter – Frans Rosén @ Security Fest 2016
PDF
Build Features, Not Apps
Hybrid Cloud Computing - Seccurity Aspects and Challanges
App sec in the time of docker containers
What is cloud ?
Security in the cloud Workshop HSTC 2014
Cloud Security Issues 1.04.10
AWS Survival Guide
Security Issues in Cloud Computing
Burp Suite Starter
Security Issues of Cloud Computing
Cloud Security - Security Aspects of Cloud Computing
DevOOPS: Attacks and Defenses for DevOps Toolchains
Cloud computing security issues and challenges
Cloud Computing Security
Cloud security and security architecture
Time based CAPTCHA protected SQL injection through SOAP-webservice
The Secret Life of a Bug Bounty Hunter – Frans Rosén @ Security Fest 2016
Build Features, Not Apps
Ad

Similar to Startups Security (20)

PDF
Ab cs of software security
PPTX
Security Minded - Ransomware Awareness
PPT
Web Application Hacking 2004
PPTX
Spiceworld 2011 - AppRiver breakout session
PPTX
Network Security
PPTX
Top Application Security Trends of 2012
PDF
Forthright Security Lunch and Learn - Ransomware Focus 2
PPT
Ethical Hacking - Introduction to Computer Security
PPT
Introduction To Computer Security
PPT
Ethical Hacking - Introduction to Computer Security
PDF
DWP-Cybersecurity-2023.pdf
PDF
F5 Hero Asset - Inside the head of a Hacker Final
PDF
Identifying a Compromised WordPress Site
PPTX
Application Security: What do we need to know?
PPTX
Word camp orange county 2012 enduser security
PPT
01-intro-thompson.ppt
PPT
Computer and Network Security
PPT
01-intro-thompson.ppt
PPT
01-intro-thompson.ppt
PDF
Data security best practices for risk awareness and mitigation
Ab cs of software security
Security Minded - Ransomware Awareness
Web Application Hacking 2004
Spiceworld 2011 - AppRiver breakout session
Network Security
Top Application Security Trends of 2012
Forthright Security Lunch and Learn - Ransomware Focus 2
Ethical Hacking - Introduction to Computer Security
Introduction To Computer Security
Ethical Hacking - Introduction to Computer Security
DWP-Cybersecurity-2023.pdf
F5 Hero Asset - Inside the head of a Hacker Final
Identifying a Compromised WordPress Site
Application Security: What do we need to know?
Word camp orange county 2012 enduser security
01-intro-thompson.ppt
Computer and Network Security
01-intro-thompson.ppt
01-intro-thompson.ppt
Data security best practices for risk awareness and mitigation

More from Akash Mahajan (15)

PDF
On Writing Well - A talk given at WinjaBlogs Session
PPTX
Venom vulnerability Overview and a basic demo
ODP
INCOMPLETE - OUTLINE for RootConf 2014 - The little-servcie-which-wasn't-there
PPTX
The real incident of stealing a droid app+data
PPTX
Believe It Or Not SSL Attacks
PPTX
I haz your mouse clicks and key strokes
PPTX
Hackers versus Developers and Secure Web Programming
PPTX
Secure HTTP Headers c0c0n 2011 Akash Mahajan
PPTX
Php security
PPTX
Secure passwords-theory-and-practice
PDF
Top 10 web application security risks akash mahajan
PDF
Web application security
PPTX
Web application security
PPTX
Web application security
PPTX
Secure Programming In Php
On Writing Well - A talk given at WinjaBlogs Session
Venom vulnerability Overview and a basic demo
INCOMPLETE - OUTLINE for RootConf 2014 - The little-servcie-which-wasn't-there
The real incident of stealing a droid app+data
Believe It Or Not SSL Attacks
I haz your mouse clicks and key strokes
Hackers versus Developers and Secure Web Programming
Secure HTTP Headers c0c0n 2011 Akash Mahajan
Php security
Secure passwords-theory-and-practice
Top 10 web application security risks akash mahajan
Web application security
Web application security
Web application security
Secure Programming In Php

Recently uploaded (20)

PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Electronic commerce courselecture one. Pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
KodekX | Application Modernization Development
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PDF
cuic standard and advanced reporting.pdf
PPTX
Big Data Technologies - Introduction.pptx
PPT
Teaching material agriculture food technology
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
Review of recent advances in non-invasive hemoglobin estimation
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Electronic commerce courselecture one. Pdf
“AI and Expert System Decision Support & Business Intelligence Systems”
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Dropbox Q2 2025 Financial Results & Investor Presentation
KodekX | Application Modernization Development
Advanced methodologies resolving dimensionality complications for autism neur...
Reach Out and Touch Someone: Haptics and Empathic Computing
cuic standard and advanced reporting.pdf
Big Data Technologies - Introduction.pptx
Teaching material agriculture food technology
The Rise and Fall of 3GPP – Time for a Sabbatical?
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
The AUB Centre for AI in Media Proposal.docx
Spectral efficient network and resource selection model in 5G networks
Unlocking AI with Model Context Protocol (MCP)
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Digital-Transformation-Roadmap-for-Companies.pptx

Startups Security

  • 1. www.pcsafety.in [email_address] SS 14 th June 2008 Do Startups Need to Worry about Security ? Or Why Will Anyone Hack My Servers ?
  • 2. www.pcsafety.in [email_address] SS 14 th June 2008 Do Startups Need to Worry about Security ? YES, and here is why. Three recent headlines Web infection attacks more than 100,000 pages [ theregister.co.uk on 24 th April 2008 ] Drive-by download attack compromises 500,000 websites [ channelregister.co.uk on 13 th May 2008 ] Hackers 'seeding' legitimate websites. A 220% increase in Web-based malware [ vunet.com on 9th June 2008]
  • 3. www.pcsafety.in akash@pcsafety.in SS 14 th June 2008 But how is this relevant to my startup ? Do you have a web application as your interface to the end user? Are you letting your users add content to the web app ? Are you trusting your users to be always benign ? Would you want to serve malware unknowingly ? Do your developers understand XSS, CSRF & SQL injection ? Do Startups Need to Worry about Security ?
  • 4. www.pcsafety.in akash@pcsafety.in SS 14 th June 2008 For bandwidth to host and serve malware. To add one line of extra code to download trojans. To use your site as a conduit while performing other attacks. Because on the web bad guys trade hosting space as currency. Because some script kiddie is learning how to do all this Why Will Anyone Hack My Servers ?
  • 5. www.pcsafety.in akash@pcsafety.in SS 14 th June 2008 Educate developers to follow secure coding principals. Add security testing as an integral part of app testing. Making sure the testing covers OWASP Top 10 vulnerabilities. So what exactly can we do about this ?
  • 6. www.pcsafety.in akash@pcsafety.in SS 14 th June 2008 But why, what is the point ? Loosing trust on line can be a death knell for a startup. Legally you are responsible for what is on your website. Keeping yourself secure makes good business sense anyway
  • 7. www.pcsafety.in akash@pcsafety.in SS 14 th June 2008 Been working on Info Sec domain for the past 3 years. Worked with CDAC Bangalore securing their web and email servers. Bootstrapped End Point Security and IDS teams for StillSecure Flying Solo from 1 st of July to help companies with Info Security You have any questions about security come talk to me. So what is my angle ? Why am I telling you all this ? BLOG / WEBSITE www.pcsafety.in [email_address]