메뉴 건너뛰기




Volumn 36, Issue 1, 2011, Pages 20-34

Web vulnerability study of online pharmacy sites

Author keywords

N Stalker; online pharmacies; Security; web applications

Indexed keywords

DRUG;

EID: 79954561890     PISSN: 17538157     EISSN: 17538165     Source Type: Journal    
DOI: 10.3109/17538157.2010.520418     Document Type: Article
Times cited : (14)

References (39)
  • 2
    • 79960731964 scopus 로고    scopus 로고
    • Cenzic [Internet], Available from:, (accessed 28 February 2010)
    • Cenzic [Internet]. Web Application Security Trends Report Q3-Q4, 2008. Available from: http://www.cenzic. com/downloads/Cenzic-AppSecTrends-Q3-Q4-2008. pdf (accessed 28 February 2010).
    • (2008) Web Application Security Trends Report Q3-Q4
  • 3
    • 79960726053 scopus 로고    scopus 로고
    • Open Web Application Security Project (OWASP) [Internet], Available from:, (accessed 1 February 2010)
    • Open Web Application Security Project (OWASP) [Internet]. Top 10 2007. Available from: http:// www.owasp.org/index.php/Top-10-2007#Introduction (accessed 1 February 2010).
    • (2007) Top 10
  • 4
    • 84870259303 scopus 로고    scopus 로고
    • SANS Institute [Internet], Available from:, (accessed 27 December
    • SANS Institute [Internet]. SANS Top-20 2007 Security Risks (2007 Annual Update). Available from: http:// www.sans.org/top20/#s1 (accessed 27 December 2009).
    • (2009) SANS Top-20 2007 Security Risks (2007 Annual Update)
  • 5
    • 79960733247 scopus 로고    scopus 로고
    • Online pharmacy risks rising
    • [Internet], Available from:, accessed 7 February 2010)
    • Claburn T. [Internet]. Online pharmacy risks rising. Information Week. Available from: http://www.informationweek. com/news/internet/security/ showArticle.jhtml?articleID=210200864 (accessed 7 February 2010).
    • Information Week
    • Claburn, T.1
  • 6
    • 79960730405 scopus 로고    scopus 로고
    • PharmacyChecker.com [Internet], Available from:, (accessed 27 February
    • PharmacyChecker.com [Internet]. Online prescription drug searches surge 34% over past twelve months. Available from: http://www.pharmacychecker.com/ news/online-drug-searches-surge-040609.asp (accessed 27 February 2010).
    • (2010) Online Prescription Drug Searches Surge 34% Over Past Twelve Months
  • 7
    • 12844263093 scopus 로고    scopus 로고
    • U.S. Census Bureau News [Internet], U.S. Census Bureau. Available from:, accessed 3 March
    • U.S. Census Bureau News [Internet]. Income, poverty, and health insurance coverage in the United States: 2007. U.S. Census Bureau. Available from: http://www.census.gov/prod/2008pubs/p60-235.pdf (accessed 3 March 2010).
    • (2010) Income, Poverty, and Health Insurance Coverage in the United States: 2007
  • 8
    • 79960718652 scopus 로고    scopus 로고
    • CBC News [Internet], Available from:, accessed 27 February
    • CBC News [Internet]. Prescription drugs: more business for Canadia online pharmacies? Available from: http:// www.cbc.ca/health/story/2009/02/27/f- onlinedrugs.html (accessed 27 February 2010).
    • (2010) Prescription Drugs: More Business for Canadia Online Pharmacies?
  • 9
    • 33646374115 scopus 로고    scopus 로고
    • Quality drivers for e-pharmaceuticals system management: A theoretical framework
    • Cook D, Joseph J, Morton R. Quality drivers for e-pharmaceuticals system management: A theoretical framework. International Journal of Electronic Business 2004;2:174-192.
    • (2004) International Journal of Electronic Business , vol.2 , pp. 174-192
    • Cook, D.1    Joseph, J.2    Morton, R.3
  • 10
    • 24944490530 scopus 로고    scopus 로고
    • A comparison of brand-name drug prices between Canadian-based Internet pharmacies and major U.S. drug chain pharmacies
    • Quon B, Firszt R, Eisenberg M. A comparison of brand-name drug prices between Canadian-based Internet pharmacies and major U.S. drug chain pharmacies. Annals of Internal Medicine 2005;143:397-403.
    • (2005) Annals of Internal Medicine , vol.143 , pp. 397-403
    • Quon, B.1    Firszt, R.2    Eisenberg, M.3
  • 12
    • 79960737593 scopus 로고    scopus 로고
    • Internet pharmacy consumer safeguards
    • March 27, Available from:, accessed 27 February 2010)
    • Hubbard WK. Internet pharmacy consumer safeguards. FDCH Congressional Testimony, March 27, 2003. Available from: http://www.hhs.gov/asl/testify/ t040318.html (accessed 27 February 2010).
    • (2003) FDCH Congressional Testimony
    • Hubbard, W.K.1
  • 14
    • 79960730172 scopus 로고    scopus 로고
    • U.S. Federal Trade Commission (FTC) [Internet]., Available from:, (accessed 27 February
    • U.S. Federal Trade Commission (FTC) [Internet]. Health breach notification rule. Available from: http:// www.ftc.gov/os/2009/04/ R911002healthbreach.pdf (accessed 27 February 2010).
    • (2010) Health Breach Notification Rule
  • 15
    • 79960734679 scopus 로고    scopus 로고
    • Online pharmacy Brandjacking: Buyer beware
    • [Internet], Available from: Accessed 20 February 2010)
    • Mello J. [Internet]. Online pharmacy Brandjacking: buyer beware. E-Commerce Times. Available from: http:// www.ecommercetimes.com/rsstory/58999. html?wlc=1243690944 (accessed 20 February 2010).
    • E-Commerce Times
    • Mello, J.1
  • 16
    • 79960718651 scopus 로고    scopus 로고
    • National Association of Boards of Pharmacy (NABP) [Internet], Available from:, (accessed 7 March
    • National Association of Boards of Pharmacy (NABP) [Internet]. NABP findings underscore dangers of purchasing prescription medicine online and from foreign sources. Available from: http://www.nabp.net/news/ nabp-findings- underscore-dangers-of-purchasing-prescription-medicine-online-and-from-foreign- sources/ (accessed 7 March 2010).
    • (2010) NABP Findings Underscore Dangers of Purchasing Prescription Medicine Online and from Foreign Sources
  • 17
    • 33847010583 scopus 로고    scopus 로고
    • Breaching the Security of the Kaiser Permanente Internet Patient Portal: The Organizational Foundations of Information Security
    • DOI 10.1197/jamia.M2195, PII S1067502706002751
    • Collmann J, Cooper T. Breaching the security of the Kaiser permanente Internet patient portal: The organizational foundations of information security. Journal of the American Medical Informatics Association 2007;14:239-243. (Pubitemid 46275492)
    • (2007) Journal of the American Medical Informatics Association , vol.14 , Issue.2 , pp. 239-243
    • Collmann, J.1    Cooper, T.2
  • 18
    • 79960703454 scopus 로고    scopus 로고
    • Office of the Privacy Commissioner of Canada [Internet]. PIPEDA case summary #2005-310, Available from:, (accessed 7 March
    • Office of the Privacy Commissioner of Canada [Internet]. PIPEDA case summary #2005-310, Commissioner initiated complaints against Internet pharmacies. Available from: http://www.priv.gc.ca/cf-dc/2005/310-2005 0525-e.cfm (accessed 7 March 2010).
    • (2010) Commissioner Initiated Complaints Against Internet Pharmacies
  • 19
    • 79960746262 scopus 로고    scopus 로고
    • IBM [Internet]., Available from, accessed 26 February
    • IBM [Internet]. Rational AppScan. Available from: http://www-01.ibm.com/ software/awdtools/appscan/standard/ features/?S-CMP=rnav&S-CMP=rnav (accessed 26 February 2010).
    • (2010) Rational AppScan
  • 20
    • 79960746506 scopus 로고    scopus 로고
    • IBM [Internet], Available from:, (accessed 26 February
    • IBM [Internet]. Trial: rational AppScan. Available from: http://www.ibm.com/developerworks/downloads/r/ appscan/learn.html?S-TACT= 105AGX28&S-CMP=TRIALS (accessed 26 February 2010).
    • (2010) Trial: Rational AppScan
  • 21
    • 79960706246 scopus 로고    scopus 로고
    • Tenable Network Security [Internet]., Available from:, accessed 7 March
    • Tenable Network Security [Internet]. Nessus vulnerability scanner features. Available from: http://www. tenablesecurity.com/nessus/features/ (accessed 7 March 2010).
    • (2010) Nessus Vulnerability Scanner Features
  • 22
    • 79960723923 scopus 로고    scopus 로고
    • eEye Digital Security [Internet], Available from:, (accessed 12 March
    • eEye Digital Security [Internet]. Retina network security scanner. Available from: http://www.eeye.com/html/ products/retina/specs/index.html (accessed 12 March 2010).
    • (2010) Retina Network Security Scanner
  • 23
    • 79960744414 scopus 로고    scopus 로고
    • Advanced Research Corporation [Internet]., Available from:, accessed 27 February
    • Advanced Research Corporation [Internet]. Security auditor's research assistant. Available from: http://wwwarc. com/sara/ (accessed 27 February 2010).
    • (2010) Security Auditor's Research Assistant
  • 24
    • 79960703260 scopus 로고    scopus 로고
    • N-Stalker [Internet]., Available from:, accessed 28 January
    • N-Stalker [Internet]. N-Stalker Free Edition. Available from: http://nstalker.com/products/free (accessed 28 January 2010).
    • (2010) N-Stalker Free Edition
  • 25
    • 79960731718 scopus 로고    scopus 로고
    • N-Stalker [Internet]., Available from:, accessed 28 January
    • N-Stalker [Internet]. N-Stalker Security Checks. Available from: http://nstalker.com/products/security-checks (accessed 28 January 2010).
    • (2010) N-Stalker Security Checks
  • 26
    • 79960709004 scopus 로고    scopus 로고
    • [Internet]., Los Angeles CA: Proceedings of ApacheCon, Available from, accessed 15 January 2010)
    • Cox M. [Internet]. Apache Security Secrets: Revealed. Los Angeles, CA: Proceedings of ApacheCon 2002. Available from: http://www.awe.com/mark/talks/ tu04-handout.pdf (accessed 15 January 2010).
    • (2002) Apache Security Secrets: Revealed
    • Cox, M.1
  • 28
    • 79960727446 scopus 로고    scopus 로고
    • W3C [Internet], Available from:, (accessed 17 January
    • W3C [Internet]. RFC 2616: Hypertext Transfer Protocol - HTTP/1.1. Available from: http://www.w3.org/ Protocols/rfc2616/rfc2616.html (accessed 17 January 2010).
    • (2010) RFC 2616: Hypertext Transfer Protocol - HTTP/1.1
  • 29
    • 79960713075 scopus 로고    scopus 로고
    • SANS Institute [Internet], Available from:, accessed 24 February
    • SANS Institute [Internet]. SANS Top-20 2007 - Cross Site Scripting. Available from: http://www.owasp.org/ index.php/Top-10-2007-A1 (accessed 24 February 2010).
    • (2010) SANS Top-20 2007 - Cross Site Scripting
  • 30
    • 79960708007 scopus 로고    scopus 로고
    • SANS Institute [Internet] Available from:, accessed 24 February
    • SANS Institute [Internet]. SANS Top-20 2007 - Injection Flaws. Available from: http://www.owasp.org/ index.php/Top-10-2007-A2 (accessed 24 February 2010).
    • (2010) SANS Top-20 2007 - Injection Flaws
  • 31
    • 79960721186 scopus 로고    scopus 로고
    • SANS Institute [Internet], Available from:, accessed 24 February
    • SANS Institute [Internet]. Buffer Overflow. Available from: http://www.owasp.org/index.php/Buffer-Overflow (accessed 24 February 2010).
    • (2010) Buffer Overflow
  • 32
    • 70249137560 scopus 로고    scopus 로고
    • The impact of information security breaches on financial performance of the breached firms: An empirical investigation
    • Ko M, Dorantes, C. The impact of information security breaches on financial performance of the breached firms: An empirical investigation. Journal of Information Technology Management 2006;17:13-22.
    • (2006) Journal of Information Technology Management , vol.17 , pp. 13-22
    • Ko, M.1    Dorantes, C.2
  • 33
    • 79960715043 scopus 로고    scopus 로고
    • Breach costs on the up
    • [Internet]., Available from:, accessed 27 February
    • White K. [Internet]. Breach costs on the up. Computer Business Review. Available from: http:// www.cbronline.com/news/datalossmeanslostcustom-020209 (accessed 27 February 2010).
    • (2010) Computer Business Review
    • White, K.1
  • 34
    • 77954447727 scopus 로고    scopus 로고
    • IT security: Target: The web
    • Available from:, (accessed 15 February
    • Waters J. IT security: Target: The Web. T.H.E. Journal. Available from: http://thejournal.com/Articles/2009/02/01/ IT-Security-Target-The-Web.aspx (accessed 15 February 2010).
    • (2010) T.H.E Journal
    • Waters, J.1
  • 35
    • 79960710361 scopus 로고    scopus 로고
    • [Internet], SC Magazine. Available from:, accessed 6 March
    • Moscaritolo A. [Internet]. Web apps account for 80 percent of internet vulnerabilities. SC Magazine. Available from: http://www.scmagazineus.com/Web- apps-account-for-80-percent-of-internet-vulnerabilities/article/129027/ (accessed 6 March 2010).
    • (2010) Web Apps Account for 80 Percent of Internet Vulnerabilities
    • Moscaritolo, A.1
  • 36
    • 79960727947 scopus 로고    scopus 로고
    • IT security for higher education: A legal perspective
    • [Internet], Available from:, accessed 15 February
    • Salomon K, Cassat P, Thibeau B. [Internet]. IT security for higher education: A legal perspective. EDUCAUSE. Available from: http://net.educause. edu/ir/library/pdf/CSD2746.pdf (accessed 15 February 2010).
    • (2010) EDUCAUSE
    • Salomon, K.1    Cassat, P.2    Thibeau, B.3
  • 37
    • 4243195875 scopus 로고    scopus 로고
    • Trust-building measures: A review of consumer health portals
    • Luo W, Najdawi, M. Trust-building measures: A review of consumer health portals. Communications of the ACM 2004;47:109-113.
    • (2004) Communications of the ACM , vol.47 , pp. 109-113
    • Luo, W.1    Najdawi, M.2
  • 38
    • 79960730647 scopus 로고    scopus 로고
    • TRUSTe [Internet], AvailableP from:, (accessed 15 February
    • TRUSTe [Internet]. Making sense of Web site privacy and security seals. AvailableP from: http://www. truste.com/privacy-seals-and-services/consumer- privacy/Seal-Comparisons.html (accessed 15 February 2010).
    • (2010) Making Sense of Web Site Privacy and Security Seals
  • 39
    • 84984578604 scopus 로고    scopus 로고
    • OncoRx-IQ: A tool for quality assessment of online anticancer drug interactions
    • Yap K, Raaj S, Chan A. OncoRx-IQ: A tool for quality assessment of online anticancer drug interactions. International Journal for Quality in HealthCare 2010;22:93-106.
    • (2010) International Journal for Quality in HealthCare , vol.22 , pp. 93-106
    • Yap, K.1    Raaj, S.2    Chan, A.3


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.