Welcome!

Linux Containers Authors: Larry Alton, Cloud Best Practices Network, Elizabeth White, Carmen Gonzalez, Liz McMillan

News Feed Item

Real Studio Web Edition-Powered Website Thrives Against Major Hack Attempt; Proves Unprecedented Security Protection for Web Apps

Real Software, creator of award-winning cross-platform web and desktop app development tools, prides itself on the revolutionary new visual way to make web apps using Real Studio, but also has demonstrated high security for web apps. Targeted attacks and data theft are changing web security. According to this study from HP’s Application Security Center, for every known web app, seven out of ten times there is at least one SQL injection flaw that is just waiting to be discovered by a hacker.

Bob Keeney, a longtime Real Studio developer, and CEO of BKeeney Software, a consulting, training and custom software development company, was recently victim to a website hack attempt. It unfortunately brought down his entire website, except the section he had created as a web application using Real Studio Web Edition.

Bob’s website was using an older version of the popular CMS, Joomla. When he first started offering Real Studio video training, he was relying upon several Joomla components that would stop working if they updated to a newer version. A little more than a year ago, Bob converted the Real Studio training section of the website to a Real Studio web app.

"We were down for about 24 hours after the hack, as we had to spend some time formatting new webpages, rearranging links and uploading it to get the site back up and running," detailed Keeney. "We believe the hacker was able to upload a PHP file through a flaw in Joomla, which executed a variety of commands that rewrote many of the PHP files, so it could execute arbitrary commands and reinfect itself again if we didn’t eradicate all of the infected files."

“Our main website would not load and it also took down our bug tracking system, which also uses PHP,” continued Keeney. “Our Real Studio video training app functioned perfectly, however. In fact, we even had several people sign up for subscriptions and many were watching videos even though the rest of the website was down.”

“At Real Software, we take web security very seriously in the Real Studio web application framework,” commented Geoff Perlman, Real Software Founder and CEO. “Because web apps are accessible to any number of online users, the security of web apps is paramount.”

“Most traditional web development languages are interpreted, meaning your web app is a set of files on a server,” continued Perlman. “If someone gains access to that server, they gain access to your source code. Real Studio compiles your web project to binary code so your source code is not stored on the server. In order for someone to alter your application they would have to be very familiar with x86 assembly code and be willing to spend an extremely long time tracing through that code. This is, at the least, an order of magnitude far more difficult than hacking any other web technology source code.”

The Open Web Application Security Project (OWASP) provides information on web application security and recently posted a list of the top 10 web application security issues. Though a few of these issues require the developer to be more diligent, most cannot be used to hack into a web application created with Real Studio.

SQL injection attacks and cross-site scripting remain the most common forms of web app hack attempts. Real Studio provides developers with prepared statement support for database access. This takes the values to be used in a query and sends them separately to the database server so that it can determine if the values are valid or contain SQL. Web applications created with Real Studio can’t be hacked with cross-site scripting because all data sent to the browser is automatically escaped. As a result, the user cannot inject HTML into a page. Also, because the developer doesn't work in HTML or JavaScript, theres no way for the developer to accidentally create this security breach.

Using Real Studio to make web apps is truly unique as you do not need to know numerous web technologies, like HTML, CSS, JavaScript, AJAX, PHP or Java. Instead, Real Studio provides a completely visual, drag and drop interface builder that saves hours of time compared to coding HTML and CSS by hand. Its high-level, object-oriented language allows you to focus on your application’s logic using a single language.

BKeeney’s website receives several thousand website visits per month. In the year that the Web Edition training area has been running it has served up over 3,100 hours of streaming video to about 800 Real Studio users.

About Real Studio Real Studio is a full-featured cross-platform software development tool suited to creating a wide range of applications, from utilities to enterprise-class applications. Real Studio Personal Edition for Windows, Linux or Mac OS X is priced at $99 and is geared for hobbyists and students. Real Studio Professional Edition, required for cross-platform compilation is $299. Real Studio Enterprise Edition, made for full-time developers, is priced at $995 and offers the ability to develop and deploy on Mac OS X, Windows, Linux, and the web. Real Studio Web Edition, the fastest and easiest way to create and deploy web applications, is available for $599.

About Real Software Real Software provides Real Studio, a cross-platform web, desktop, and console development tool. Real Software was founded in 1996 and is based in Austin, Texas. For more information visit www.realsoftware.com or call 866.825.2114.

More Stories By Business Wire

Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

@ThingsExpo Stories
With major technology companies and startups seriously embracing IoT strategies, now is the perfect time to attend @ThingsExpo 2016 in New York. Learn what is going on, contribute to the discussions, and ensure that your enterprise is as "IoT-Ready" as it can be! Internet of @ThingsExpo, taking place June 6-8, 2017, at the Javits Center in New York City, New York, is co-located with 20th Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry p...
"LinearHub provides smart video conferencing, which is the Roundee service, and we archive all the video conferences and we also provide the transcript," stated Sunghyuk Kim, CEO of LinearHub, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Internet of @ThingsExpo, taking place June 6-8, 2017 at the Javits Center in New York City, New York, is co-located with the 20th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @ThingsExpo New York Call for Papers is now open.
"There's a growing demand from users for things to be faster. When you think about all the transactions or interactions users will have with your product and everything that is between those transactions and interactions - what drives us at Catchpoint Systems is the idea to measure that and to analyze it," explained Leo Vasiliou, Director of Web Performance Engineering at Catchpoint Systems, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York Ci...
The 20th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held June 6-8, 2017, at the Javits Center in New York City, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Containers, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal ...
WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web communications world. The 6th WebRTC Summit continues our tradition of delivering the latest and greatest presentations within the world of WebRTC. Topics include voice calling, video chat, P2P file sharing, and use cases that have already leveraged the power and convenience of WebRTC.
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
Discover top technologies and tools all under one roof at April 24–28, 2017, at the Westin San Diego in San Diego, CA. Explore the Mobile Dev + Test and IoT Dev + Test Expo and enjoy all of these unique opportunities: The latest solutions, technologies, and tools in mobile or IoT software development and testing. Meet one-on-one with representatives from some of today's most innovative organizations
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at Cloud Expo, Ed Featherston, a director and senior enterprise architect at Collaborative Consulting, discussed the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
"A lot of times people will come to us and have a very diverse set of requirements or very customized need and we'll help them to implement it in a fashion that you can't just buy off of the shelf," explained Nick Rose, CTO of Enzu, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
The WebRTC Summit New York, to be held June 6-8, 2017, at the Javits Center in New York City, NY, announces that its Call for Papers is now open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 20th International Cloud Expo and @ThingsExpo. WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web co...
In 2014, Amazon announced a new form of compute called Lambda. We didn't know it at the time, but this represented a fundamental shift in what we expect from cloud computing. Now, all of the major cloud computing vendors want to take part in this disruptive technology. In his session at 20th Cloud Expo, John Jelinek IV, a web developer at Linux Academy, will discuss why major players like AWS, Microsoft Azure, IBM Bluemix, and Google Cloud Platform are all trying to sidestep VMs and containers...
Buzzword alert: Microservices and IoT at a DevOps conference? What could possibly go wrong? In this Power Panel at DevOps Summit, moderated by Jason Bloomberg, the leading expert on architecting agility for the enterprise and president of Intellyx, panelists peeled away the buzz and discuss the important architectural principles behind implementing IoT solutions for the enterprise. As remote IoT devices and sensors become increasingly intelligent, they become part of our distributed cloud enviro...
SYS-CON Events announced today that MobiDev, a client-oriented software development company, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MobiDev is a software company that develops and delivers turn-key mobile apps, websites, web services, and complex softw...
WebRTC is about the data channel as much as about video and audio conferencing. However, basically all commercial WebRTC applications have been built with a focus on audio and video. The handling of “data” has been limited to text chat and file download – all other data sharing seems to end with screensharing. What is holding back a more intensive use of peer-to-peer data? In her session at @ThingsExpo, Dr Silvia Pfeiffer, WebRTC Applications Team Lead at National ICT Australia, looked at differ...
Fact is, enterprises have significant legacy voice infrastructure that’s costly to replace with pure IP solutions. How can we bring this analog infrastructure into our shiny new cloud applications? There are proven methods to bind both legacy voice applications and traditional PSTN audio into cloud-based applications and services at a carrier scale. Some of the most successful implementations leverage WebRTC, WebSockets, SIP and other open source technologies. In his session at @ThingsExpo, Da...
Growth hacking is common for startups to make unheard-of progress in building their business. Career Hacks can help Geek Girls and those who support them (yes, that's you too, Dad!) to excel in this typically male-dominated world. Get ready to learn the facts: Is there a bias against women in the tech / developer communities? Why are women 50% of the workforce, but hold only 24% of the STEM or IT positions? Some beginnings of what to do about it! In her Day 2 Keynote at 17th Cloud Expo, Sandy Ca...
SYS-CON Media announced today that @WebRTCSummit Blog, the largest WebRTC resource in the world, has been launched. @WebRTCSummit Blog offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. @WebRTCSummit Blog can be bookmarked ▸ Here @WebRTCSummit conference site can be bookmarked ▸ Here
Manufacturers are embracing the Industrial Internet the same way consumers are leveraging Fitbits – to improve overall health and wellness. Both can provide consistent measurement, visibility, and suggest performance improvements customized to help reach goals. Fitbit users can view real-time data and make adjustments to increase their activity. In his session at @ThingsExpo, Mark Bernardo Professional Services Leader, Americas, at GE Digital, discussed how leveraging the Industrial Internet and...