Why web servers create security issues
It's important to understand that web applications and servers are not inherently secure. The fact is that they were never designed to be secure – they were designed for functionality and to provide a service. The responsibility for making them safe rests with us, as system administrators, coders, and security professionals.
This is why attackers turn their attention to web servers and web application-level attacks – because a web server that hosts web applications is accessible from anywhere over the internet. This makes web servers an attractive target. Poorly configured web servers can create vulnerabilities in even the most carefully designed firewall systems. Attackers can exploit poorly configured web servers with known vulnerabilities to compromise the security of web applications. Furthermore, web servers with known vulnerabilities can harm the security of an organization, even if the web applications they host are...