Welcome!

Open Source Cloud Authors: William Schmarzo, Elizabeth White, Yeshim Deniz, Pat Romanski, Greg Schulz

News Feed Item

Real Studio Web Edition-Powered Website Thrives Against Major Hack Attempt; Proves Unprecedented Security Protection for Web Apps

Real Software, creator of award-winning cross-platform web and desktop app development tools, prides itself on the revolutionary new visual way to make web apps using Real Studio, but also has demonstrated high security for web apps. Targeted attacks and data theft are changing web security. According to this study from HP’s Application Security Center, for every known web app, seven out of ten times there is at least one SQL injection flaw that is just waiting to be discovered by a hacker.

Bob Keeney, a longtime Real Studio developer, and CEO of BKeeney Software, a consulting, training and custom software development company, was recently victim to a website hack attempt. It unfortunately brought down his entire website, except the section he had created as a web application using Real Studio Web Edition.

Bob’s website was using an older version of the popular CMS, Joomla. When he first started offering Real Studio video training, he was relying upon several Joomla components that would stop working if they updated to a newer version. A little more than a year ago, Bob converted the Real Studio training section of the website to a Real Studio web app.

"We were down for about 24 hours after the hack, as we had to spend some time formatting new webpages, rearranging links and uploading it to get the site back up and running," detailed Keeney. "We believe the hacker was able to upload a PHP file through a flaw in Joomla, which executed a variety of commands that rewrote many of the PHP files, so it could execute arbitrary commands and reinfect itself again if we didn’t eradicate all of the infected files."

“Our main website would not load and it also took down our bug tracking system, which also uses PHP,” continued Keeney. “Our Real Studio video training app functioned perfectly, however. In fact, we even had several people sign up for subscriptions and many were watching videos even though the rest of the website was down.”

“At Real Software, we take web security very seriously in the Real Studio web application framework,” commented Geoff Perlman, Real Software Founder and CEO. “Because web apps are accessible to any number of online users, the security of web apps is paramount.”

“Most traditional web development languages are interpreted, meaning your web app is a set of files on a server,” continued Perlman. “If someone gains access to that server, they gain access to your source code. Real Studio compiles your web project to binary code so your source code is not stored on the server. In order for someone to alter your application they would have to be very familiar with x86 assembly code and be willing to spend an extremely long time tracing through that code. This is, at the least, an order of magnitude far more difficult than hacking any other web technology source code.”

The Open Web Application Security Project (OWASP) provides information on web application security and recently posted a list of the top 10 web application security issues. Though a few of these issues require the developer to be more diligent, most cannot be used to hack into a web application created with Real Studio.

SQL injection attacks and cross-site scripting remain the most common forms of web app hack attempts. Real Studio provides developers with prepared statement support for database access. This takes the values to be used in a query and sends them separately to the database server so that it can determine if the values are valid or contain SQL. Web applications created with Real Studio can’t be hacked with cross-site scripting because all data sent to the browser is automatically escaped. As a result, the user cannot inject HTML into a page. Also, because the developer doesn't work in HTML or JavaScript, theres no way for the developer to accidentally create this security breach.

Using Real Studio to make web apps is truly unique as you do not need to know numerous web technologies, like HTML, CSS, JavaScript, AJAX, PHP or Java. Instead, Real Studio provides a completely visual, drag and drop interface builder that saves hours of time compared to coding HTML and CSS by hand. Its high-level, object-oriented language allows you to focus on your application’s logic using a single language.

BKeeney’s website receives several thousand website visits per month. In the year that the Web Edition training area has been running it has served up over 3,100 hours of streaming video to about 800 Real Studio users.

About Real Studio Real Studio is a full-featured cross-platform software development tool suited to creating a wide range of applications, from utilities to enterprise-class applications. Real Studio Personal Edition for Windows, Linux or Mac OS X is priced at $99 and is geared for hobbyists and students. Real Studio Professional Edition, required for cross-platform compilation is $299. Real Studio Enterprise Edition, made for full-time developers, is priced at $995 and offers the ability to develop and deploy on Mac OS X, Windows, Linux, and the web. Real Studio Web Edition, the fastest and easiest way to create and deploy web applications, is available for $599.

About Real Software Real Software provides Real Studio, a cross-platform web, desktop, and console development tool. Real Software was founded in 1996 and is based in Austin, Texas. For more information visit www.realsoftware.com or call 866.825.2114.

More Stories By Business Wire

Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

@ThingsExpo Stories
DevOps at Cloud Expo – being held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real r...
SYS-CON Events announced today that Systena America will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Systena Group has been in business for various software development and verification in Japan, US, ASEAN, and China by utilizing the knowledge we gained from all types of device development for various industries including smartphones (Android/iOS), wireless communication, security technology and IoT serv...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend @CloudExpo | @ThingsExpo, June 6-8, 2017, at the Javits Center in New York City, NY and October 31 - November 2, 2017, Santa Clara Convention Center, CA. Learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
SYS-CON Events announced today that Super Micro Computer, Inc., a global leader in compute, storage and networking technologies, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Supermicro (NASDAQ: SMCI), the leading innovator in high-performance, high-efficiency server technology, is a premier provider of advanced server Building Block Solutions® for Data Center, Cloud Computing, Enterprise IT, Hadoop/...
In his keynote at @ThingsExpo, Chris Matthieu, Director of IoT Engineering at Citrix and co-founder and CTO of Octoblu, focused on building an IoT platform and company. He provided a behind-the-scenes look at Octoblu’s platform, business, and pivots along the way (including the Citrix acquisition of Octoblu).
SYS-CON Events announced today that CollabNet, a global leader in enterprise software development, release automation and DevOps solutions, will be a Bronze Sponsor of SYS-CON's 20th International Cloud Expo®, taking place from June 6-8, 2017, at the Javits Center in New York City, NY. CollabNet offers a broad range of solutions with the mission of helping modern organizations deliver quality software at speed. The company’s latest innovation, the DevOps Lifecycle Manager (DLM), supports Value S...
A strange thing is happening along the way to the Internet of Things, namely far too many devices to work with and manage. It has become clear that we'll need much higher efficiency user experiences that can allow us to more easily and scalably work with the thousands of devices that will soon be in each of our lives. Enter the conversational interface revolution, combining bots we can literally talk with, gesture to, and even direct with our thoughts, with embedded artificial intelligence, whic...
SYS-CON Events announced today that Peak 10, Inc., a national IT infrastructure and cloud services provider, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Peak 10 provides reliable, tailored data center and network services, cloud and managed services. Its solutions are designed to scale and adapt to customers’ changing business needs, enabling them to lower costs, improve performance and focus intern...
The 21st International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Digital Transformation, Machine Learning and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding busin...
SYS-CON Events announced today that Enzu will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Enzu’s mission is to be the leading provider of enterprise cloud solutions worldwide. Enzu enables online businesses to use its IT infrastructure to their competitive ad...
Everywhere we turn in our industry we can find strong opinions about the direction, type and nature of cloud’s impact on computing and business. Another word that is used in every context in our industry is “hybrid.” In his session at 20th Cloud Expo, Alvaro Gonzalez, Director of Technical, Partner and Field Marketing at Peak 10, will use a combination of a few conceptual props and some research recently commissioned by Peak 10 to offer a real-world consideration of how the various categories of...
In his opening keynote at 20th Cloud Expo, Michael Maximilien, Research Scientist, Architect, and Engineer at IBM, will motivate why realizing the full potential of the cloud and social data requires artificial intelligence. By mixing Cloud Foundry and the rich set of Watson services, IBM's Bluemix is the best cloud operating system for enterprises today, providing rapid development and deployment of applications that can take advantage of the rich catalog of Watson services to help drive insigh...
SYS-CON Events announced today that SoftLayer, an IBM Company, has been named “Gold Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York, New York. SoftLayer, an IBM Company, provides cloud infrastructure as a service from a growing number of data centers and network points of presence around the world. SoftLayer’s customers range from Web startups to global enterprises.
Multiple data types are pouring into IoT deployments. Data is coming in small packages as well as enormous files and data streams of many sizes. Widespread use of mobile devices adds to the total. In this power panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, panelists will look at the tools and environments that are being put to use in IoT deployments, as well as the team skills a modern enterprise IT shop needs to keep things running, get a handle on all this data, and deli...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend @CloudExpo | @ThingsExpo, June 6-8, 2017, at the Javits Center in New York City, NY and October 31 - November 2, 2017, Santa Clara Convention Center, CA. Learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
Five years ago development was seen as a dead-end career, now it’s anything but – with an explosion in mobile and IoT initiatives increasing the demand for skilled engineers. But apart from having a ready supply of great coders, what constitutes true ‘DevOps Royalty’? It’ll be the ability to craft resilient architectures, supportability, security everywhere across the software lifecycle. In his keynote at @DevOpsSummit at 20th Cloud Expo, Jeffrey Scheaffer, GM and SVP, Continuous Delivery Busine...
DevOps is often described as a combination of technology and culture. Without both, DevOps isn't complete. However, applying the culture to outdated technology is a recipe for disaster; as response times grow and connections between teams are delayed by technology, the culture will die. A Nutanix Enterprise Cloud has many benefits that provide the needed base for a true DevOps paradigm.
SYS-CON Events announced today that WineSOFT will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Based in Seoul and Irvine, WineSOFT is an innovative software house focusing on internet infrastructure solutions. The venture started as a bootstrap start-up in 2010 by focusing on making the internet faster and more powerful. WineSOFT’s knowledge is based on the expertise of TCP/IP, VPN, SSL, peer-to-peer, mob...
SYS-CON Events announced today that EARP Integration will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. EARP Integration is a passionate software house. Since its inception in 2009 the company successfully delivers smart solutions for cities and factories that start their digital transformation. EARP provides bespoke solutions like, for example, advanced enterprise portals, business intelligence systems an...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @CloudExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.