Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 101 guests and 1 member online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Web Applicationsarrow Red flags for a website's security?
EH-Net
May 26, 2012, 09:10:22 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Red flags for a website's security?  (Read 1610 times)
0 Members and 2 Guests are viewing this topic.
concerned82
Newbie
*
Offline Offline

Posts: 1


View Profile
« on: January 16, 2012, 05:49:03 PM »

okay, I'm not a security guru or anything. i'm just an end user, so sorry if i'm posting to the wrong area, but i'm hoping you guys can help.

the state of nebraska made me register on their website neworks.nebraska.gov inorder to get my unemployment, but the things makes me nervous. i have to provide all my personal info and work history and soc # and everything a id thief would love, and the the scares me! i mean i'm on it and i'm thinking it isn't the best site and not even close to what i would expect from a bank or cc company!

am i crazy? is this site as bad as it looks? please tell me i'm being paranoid.
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1831


View Profile WWW
« Reply #1 on: January 17, 2012, 08:36:22 AM »

Seems fine. The IP belongs to the state, they have a current SSL certificate, and they are running IIS 7.5. As long as you were in the SSL session (and it was to their server) your information should have been okay in transit. What they do with it on their end, who knows.
Logged
3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #2 on: January 17, 2012, 09:04:35 AM »

Site looks fine, but its ok to be concerned since it is your data.  Like BillV mentioned, what they do with it after is what you might be more concerned with.  You can always call and ask them how they secure your data in their systems because you are a concerned tax payer and all Cheesy
Logged

Certs: GCWN
MaXe
Hero Member
*****
Offline Offline

Posts: 507


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #3 on: January 17, 2012, 10:16:43 PM »

As long as they're storing it right, that the transit of data is in order (which it should be according to the other comments), and if the actual website is secure, then you have nothing to worry about  Smiley
Logged

I'm an InterN0T'er
nytfox
Newbie
*
Offline Offline

Posts: 20



View Profile
« Reply #4 on: January 29, 2012, 01:27:01 AM »

I wouldn't worry about your data getting stolen while your transmuting from your machine to their servers , but make sure your machine isn't infect by RATS , Keyloggers , Stealers , Botnets etc ... and I dont think they will make you submit your information online unless the application and backend database's are secure . I didn't actually visit the site . but if the application is secure you got nothing to worry about
Logged

Unlike others I love NULLS
http://treasuresec.com
MaXe
Hero Member
*****
Offline Offline

Posts: 507


I've just upgraded myself to a cyborg muahahaa!!1


View Profile WWW
« Reply #5 on: January 30, 2012, 06:31:09 AM »

... and I dont think they will make you submit your information online unless the application and backend database's are secure .

Did you see the recent Stratfor leak? Their servers were supposed to be secure  Grin
Logged

I'm an InterN0T'er
3xban
Sr. Member
****
Offline Offline

Posts: 373


View Profile
« Reply #6 on: January 30, 2012, 09:29:21 AM »

There are two types of businesses/organizations out there, those who have been breached and those who know they have been breached Tongue
Logged

Certs: GCWN
nytfox
Newbie
*
Offline Offline

Posts: 20



View Profile
« Reply #7 on: January 30, 2012, 11:29:58 PM »

... and I dont think they will make you submit your information online unless the application and backend database's are secure .

Did you see the recent Stratfor leak? Their servers were supposed to be secure  Grin

blame the hackers Tongue . MaXe good point tho . even how much we think a system is secure their is always a point hidden to exploit . its just matter of time some one finds it
Logged

Unlike others I love NULLS
http://treasuresec.com
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.07 seconds with 20 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge: Build Security Skills to Protect & Defend

els_130x200fixed2.gif
eLearnSecurity Student Course Now Live!
5% Off with Code
ELS-EH-5

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: EHN_Connect Including SANS Security West 2012 & SANSFIRE 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.