More Than Just Code: Securing Web Applications with Support from Qualys
Ready to Transform Your Payroll & HR Management?
Talk directly with our payroll & HR specialist — No commitment required.
Experience with Qualys
- During the development of a web application, developers typically prioritise ensuring that the application functions correctly, includes all necessary features, and delivers an optimal user experience. Every line of code is written to meet user needs. However, one critical aspect that's often overlooked during the early development phase is application security.
- This was the experience of PT. Widya Presisi Solusi (WPS). As the application neared its public launch, management recognized the importance of user trust in their services. Ensuring the application was free from cybersecurity threats became a clear priority. As part of internal policy, no application is launched before being thoroughly assessed for security vulnerabilities by the IT Security team.
- To enhance security, it was also necessary to use a platform capable of identifying misconfigurations that could potentially expose vulnerabilities.
- The IT Security team performed scans using Qualys Web Application Scanning (WAS). The scan results served as crucial feedback for the development team, highlighting several critical security vulnerabilities that required immediate attention.
Introducing Qualys
- Qualys offers a range of security tools, including vulnerability scanning, digital asset monitoring, and integrated risk management. Since it's cloud-based, there is no need to install additional software—everything can be accessed through a web browser. This ease of use, combined with powerful insights, made it a perfect fit for WPS's needs.
Findings from Qualys
- The security scan revealed 11 confirmed vulnerabilities, categorized into two major types: Path Disclosure (4 findings) and Information Disclosure (7 findings). These vulnerabilities were identified using the Qualys scanning solution, providing clear insights into potential security flaws that malicious actors could exploit.
The IT Security and Development teams prioritized vulnerabilities rated as High and Medium severity. Here are three key examples:
a. 150004 – Predictable Resource Location via Forced Browsing (Level: Medium)
This vulnerability arises when directories or files can be accessed without proper authorization. Attackers may use forced browsing to reach sensitive or hidden files.
Impact: Exposure of internal data, system configurations, or even executable files.
b. 150049 – Weak Credentials Vulnerability (Level: High)
Using weak or default credentials makes it easy for unauthorized parties to gain access.
Impact: Potential account takeover or unauthorized access to internal systems.
c. 150123 – Cookie Does Not Contain the "HTTPOnly" Attribute (Level: Medium)
Cookies without the HTTPOnly attribute can be accessed via JavaScript, making them vulnerable to cross-site scripting (XSS) attacks.
Impact: Session theft and user impersonation.
After the development team addressed and patched the vulnerabilities one by one, the IT Security team re-scanned the application. The results were promising:
The previously high-risk vulnerabilities had been reduced to low severity. While two issues remained, they no longer posed a significant threat, thanks to the nine resolved vulnerabilities.
Conclusion
- Overall, using Qualys has been a highly beneficial experience in safeguarding our web application. The platform offers deep insights into system security, along with actionable steps for remediation. For anyone serious about strengthening their digital security, Qualys is a reliable and comprehensive solution worth considering.
- The reports generated by Qualys provide detailed explanations for each finding, complete with technical context to help developers understand the root causes. From threat identification to severity grading, everything is clearly and systematically presented.
- This experience demonstrated that a collaborative approach between developers and IT Security, backed by the right tools like Qualys, is essential for building applications that are not only functional but also secure and ready for public use.
Related Articles
Explore more insights and updates from Widya Presisi Solusi
Achieving ISO 27001 certificate & surveillance ISO 9001
During the last three months, we have proof that we commit to implement the ISO 9001...
Business Process Improvement
In 2008, we assisted a client which wanted to make SOP (Standard Operating Procedures...
Benefits of a Specialized Learning Management System (LMS) in Payroll
Benefits of a Specialized Learning Management System (LMS) in Payroll