ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Public

Application hardening tips

Paul by Paul
May 31, 2014
in Public, Security, Tutorials
Reading Time: 1 min read
application hardening
Share on FacebookShare on Twitter

When a exploit has been discovered in an operating system or program the vendor pushes a patch or upgrade that eliminates the vulnerability. “Hardening” is the act of proactively protecting your server and minimizing damage if or when a zero-day attack impacts your server.

You might also like

Silent OS 3.0 for Blackphone Completely revamped

Exploit Kit activity on a steep decline since April

EasyDoc malware infects Macs and routes through TOR

What you will need to focus on are the points listed below:

  • Assume all installed applications are flawed—don’t rely on the security programmed into them.
  • Physically remove from the system all applications not being used.
  • Use firewalls, content filters and OS user authentication features to restrict access to the application, and provide access only to those who absolutely must have it.
  • Update all applications to the latest patches when security bulletins are released.
  • Internally developed applications need to be code-reviewed for security weaknesses. Consider an external security review for critical applications.
  • Externally facing Web applications are high-risk applications because they are a bridge between the outside world and internal customer databases. Be sure to add code that can block or otherwise safely deal with all of the following hostile inputs: missing page parameters, parameters that are unusually long, parameters will nulls or hexadecimal encoding, parameters with Web browser script blocks (which are used to create server-side scripting attacks), and parameters with quotes and semicolons (likely attempts to send hostile SQL commands through to the database).
  • If possible, write applications in languages that run in virtual machines–such as Java, Visual Basic .Net or C#–because they provide an extra layer of security protection. Avoid C and C++ because they make it easy to write applications that allow buffer overflow attacks.
Tags: applicationHardeningpreventiontutorial
Previous Post

Arizona DHS Security Site breached and defaced

Next Post

Malware on a steep Incline during first quarter

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Silent OS 3.0 for Blackphone Completely revamped

Silent OS 3.0 for Blackphone Completely revamped

July 24, 2016 - Updated on May 17, 2022
Exploit Kit activity on a steep decline since April

Exploit Kit activity on a steep decline since April

July 12, 2016

EasyDoc malware infects Macs and routes through TOR

July 6, 2016

Hummer malware infecting androids earns $3.5 Million a week

July 6, 2016 - Updated on May 17, 2022

Healthcare sector hit by advanced worms, infects MRI and x-ray machines

July 1, 2016

FBI in possession of 411 Million facial recognition photos

June 18, 2016

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.