Skip navigation

How secure are your systems? - A comprehensive look at security gaps and solutions

Marcus AsshauerMarcus AsshauerSenior System Engineer · synaigy

4 min read

Wie sicher sind deine Systeme?

Especially in recent years e-commerce market keeps growing, and along with it attacks on e-commerce systems become more frequent. Cyber threats are now order of day. It's crucial to understand various attack vectors and take suitable measures to protect your platform. Security gaps must be closed and smooth operation ensured. Let's identify challenges together and develop strategies to arm your e-commerce platform against ever-growing number of cyberattacks. In this blog post we want to show and classify most important attack types. 


1. Account takeover

In an account takeover, an existing user account is used by unauthorised third parties to gain access to the system. This can happen in various ways, for example through system-level access via SSH or through backend access in an application. If someone gets your login credentials for your e-mail account, they could then send e-mails in your name or access your personal data.

How does that happen?

  • Attackers can spy out your login details through phishing attacks, tricking you into entering your data on a fake website, or steal them via malware that records your keystrokes.

  • Using brute-force attacks, attackers try numerous password combinations until they find the right one.

2. Credit card stuffing

With credit card stuffing, stolen credit card data is tested automatically on various e-commerce platforms to find out which cards are still valid. Attackers could try stolen credit card data on an online shop page to find out whether the card still works, and then make purchases in your name.

3. Netzwerkbasierter DDoS (Denial of Service)

One of the best-known methods is a DDoS attack. Here, the system is overloaded by a flood of network packets. It's comparable to your phone ringing non-stop with thousands of calls at once. This means no normal call can get through anymore. Applied to technology, it means a server receives so many requests that it can no longer respond and crashes.

4. Application DDoS (Denial of Service)

Here, a website or application is overloaded by many simultaneous requests, causing it to become very slow or crash completely. One example would be a website repeatedly loading complex, data-intensive pages until it no longer functions properly.

5. Logic exploitation

In this type of attack, criminals exploit weaknesses in the way software works. This includes, for example, someone managing to complete a purchase in an online shop without paying. 

6. Catalog stealing

Catalogues and product descriptions are a valuable asset for retailers and manufacturers and are a cost driver in their creation. Retailers invest a lot of money and time in creating this data. If it is then scraped by third parties, that is a loss for the creator of the catalogue. 

7. Price monitoring

In price monitoring, competitors' product pages are automatically accessed in a targeted way to query prices. This information can then be used to adjust your own prices and thereby undercut a competitor's offer price. 

8. Testing for vulnerabilities and known exploits

In this type of attack, e-commerce environments are queried with calls and manipulated parameters with the aim of exploiting known exploits or vulnerable software components. One example is injecting malicious commands into a database via an input field on a website.

9. Scalping

These are people who buy up products in bulk in order to resell them at higher prices on other platforms afterwards. A well-known example is the PlayStation 5, which was in short supply at launch. Here, individual customers bought up many consoles and then resold them at inflated prices on online marketplaces.

How can you protect yourself against it?

What all these attack scenarios have in common is that they can be traced in log files, giving a first approach to mitigation. For account takeover, for example, you can limit the number of login attempts or, better still, use 2FA. DDoS attacks are best blocked on upstream systems, such as a CDN and reverse proxies. Especially for network DDoS, you depend on support from the hosting provider or a CDN provider.

Catalogue theft, price monitoring or scalping can be detected and thus blocked through unusual calls and patterns in calls. Credit card stuffing can be detected via logs from the payment service provider or the interface to the payment service provider. Scanning for vulnerabilities and exploiting them is likewise detectable through the nature and pattern of the calls. While DDoS, scalping, price monitoring and catalogue theft tend to be targeted attacks, the remaining attacks generally occur across all web systems and are, in principle, equally dangerous for everyone.

Our solution

We use suitable measures for each of our clients to protect e-commerce environments. Here we rely on a combination of 4 providers.

We rely on OVHcloud's built-in DDoS protection and supplement it with the web application firewall from OGOSecurity, and on the hosted systems with AppSec. On top of that, Crowdsec enables log analysis, which is highly adaptable thanks to the flexibility of self-written log patterns and countermeasures.

If you have questions about protecting your e-commerce system, talk to us directly.

Subscribe to the blog now and never miss any news

✔️free of charge ✔️weekly news ✔️expert knowledge

Please accept the corresponding cookies to view this embedded content.