<?xml version="1.0" encoding="UTF-8" standalone="yes"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.cenzic.com/public/" version="2.0"><!--

MyST Blogsite® RSS Web Feed | Powered by MySmartChannels™ Weblog Application Server

MyST Blogsite and MySmartChannels are services of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com and http://blogsite.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters:

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)
  enhanced=true|false (default=false)
  limit=n (default=15)
  score=none|emoticon|simple|stars|text (default=text)
  smartPoints=true|false (default=true)
  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)
  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>Cenzic SmartAttack Updates for Web Vulnerabilities | Cenzic Security Blog</title><link>http://blog.cenzic.com/public/blog/202612</link><description>Latest web application vulnerabilities integrated into the Cenzic product suite.
        &lt;p&gt;This blog features the latest vulnerabilities in web / website applications (custom, commercial, and open-source) 
        that have been integrated into the Cenzic's website security product suite on a weekly basis.  
        These web application vulnerabilities include cross site scripting, 
        buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;
    </description><atom:link type="application/rss+xml" rel="self" href="http://blog.cenzic.com/public/rss/202612?"/><language>en-us</language><copyright>Copyright (C) 2009 Cenzic, Inc--All Rights Reserved -- This channel is part of the Cenzic Security Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 01 May 2008 13:00:50 -0400</pubDate><lastBuildDate>Fri, 27 Aug 2010 15:36:27 -0400</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V6.00.0828)</generator><image><url>http://blog.cenzic.com/styles/blogsite/Cenzic/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.cenzic.com/public/blog/202612</link><title>Cenzic SmartAttack Updates for Web Vulnerabilities | Cenzic Security Blog</title><description>This blogsite contains information on all security topics ranging from web application security, security software, vulnerabilities, enterprise security, penetration testing and hacker news.</description></image>
       <category>Cross site request forgery</category><category>CSRF</category><category>Cross site Scripting</category><category>XSS</category><category>Buffer overflow</category><category>Session management</category><category>Session ID randomness</category><category>Privilege escalation</category><category>Session hijacking</category><category>SQL Injection</category>
       
       
      
    
     <item><title>Cenzic Detects a PHP Buffer Overflow Vulnerability</title><link>http://blog.cenzic.com/public/item/258843</link><description>Weekly product update – Cenzic detects a PHP Buffer Overflow Vulnerability&lt;p&gt;As of August 27, 2010 Cenzic now detects a &lt;a title="PHP Buffer Overflow Vulnerability" href="http://www.securityfocus.com/bid/42516/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PHP 'ibase_gen_id()' Function off-by-one Buffer Overflow Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 42516&lt;/strong&gt;).&amp;nbsp; PHP is prone to an off-by-one buffer-overflow vulnerability because it fails to perform boundary checks before copying user-supplied data to insufficiently sized memory buffers.&amp;nbsp;&amp;nbsp; A hacker can exploit this issue to execute arbitrary machine code in the context of the PHP process.&amp;nbsp; Failed exploit attempts will likely crash the web server, denying service to legitimate users.&amp;nbsp; &lt;strong&gt;PHP 5.3.3 is vulnerable&lt;/strong&gt;; other versions may also be affected.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/42516/info" target=%quot;_blank%quot;&gt;PHP 'ibase_gen_id()' Function off-by-one Buffer Overflow Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258843</guid><pubDate>Fri, 27 Aug 2010 15:35:06 -0400</pubDate>
        <category>buffer overflow</category><category>buffer overflow vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects a Sun Java System Denial of Service Vulnerability</title><link>http://blog.cenzic.com/public/item/258357</link><description>Weekly product update – Cenzic detects a Sun Java System Denial of Service Vulnerability &lt;p&gt;&lt;img hspace="10" alt="Cenzic SmartAttack Update for Aug 20, 2010" vspace="10" align="right" src="http://www.cenzic.com/images/blog/binary_crossword.jpg" /&gt;As of August 20, 2010 Cenzic now detects a &lt;a title="Sun Java System Web Server Admin Interface Denial of Service Vulnerability" href="http://www.securityfocus.com/bid/41389/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Sun Java System Web Server Admin Interface Denial of Service Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 41389&lt;/strong&gt;).&amp;nbsp; Sun Java System Web Server is prone to a denial-of-service vulnerability.&amp;nbsp; An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Sun Java System Web Server 7.0 Update 7 is affected; other versions may also be vulnerable.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;br /&gt;&lt;/strong&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/41389/info" target=%quot;_blank%quot;&gt;Sun JAVA System Denial of Service Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258357</guid><pubDate>Fri, 20 Aug 2010 15:32:42 -0400</pubDate>
        <category>denial of service vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Adds New SmartAttack to Its Attack Library: Unrestricted File Upload</title><link>http://blog.cenzic.com/public/item/257785</link><description>Weekly product update – Cenzic adds 107th SmartAttack: Unrestricted File Upload&lt;p&gt;&lt;img hspace="10" alt="Unrestricted File Upload" vspace="10" align="right" src="http://www.cenzic.com/images/blog/smartattack_file-upload.jpg" /&gt;As of August 13, 2010 Cenzic created a brand new SmartAttack, &lt;strong&gt;Unrestricted File Upload&lt;/strong&gt;, bringing the total attack category library to &lt;strong&gt;107&lt;/strong&gt;.&amp;nbsp; The new SmartAttack checks various flaws present in the &amp;quot;file upload&amp;quot; functionality. Presence of these flaws may result in various attacks like Cross-Site Scripting, Malware hosting, etc. &lt;/p&gt; &lt;p&gt;Along in this weekly product update, Cenzic can also detect &lt;a title="PHP Multiple Vulnerabilities" href="http://www.securityfocus.com/bid/41991/references" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PHP Multiple Vulnerabilities like Remote Code Execution, Unauthorized Access Attacks&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 41991&lt;/strong&gt;).&amp;nbsp; PHP is prone to multiple security vulnerabilities that an attacker can exploit to execute arbitrary code, crash the affected application, gain access to sensitive information, and bypass security restrictions.&amp;nbsp; Other attacks are also possible.&amp;nbsp; Versions PHP 5.3 (Prior to 5.3.3) and PHP 5.2 (Prior to 5.2.14) are affected.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/41991/references" target=%quot;_blank%quot;&gt;PHP Multiple Vulnerabilities like Remote Code Execution, Unauthorized Access Attacks&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/257785</guid><pubDate>Fri, 13 Aug 2010 14:22:36 -0400</pubDate>
        <category>php vulnerabilities</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an Apache Information Disclosure Vulnerability &amp; Updates 1 SmartAttack™</title><link>http://blog.cenzic.com/public/item/257276</link><description>Weekly product update: Cenzic detects an Apache Information Disclosure Vulnerability &amp; updates 1 SmartAttack™&lt;p&gt;As of August 6, 2010 Cenzic now detects an &lt;a title="Apache Information Disclosure Vulnerability" href="http://www.securityfocus.com/bid/42102/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 42102&lt;/strong&gt;). &amp;nbsp;Attackers can leverage this issue to gain access to sensitive information that can aid in further attacks.&amp;nbsp; Apache 2.2.9 on Unix is vulnerable.&lt;/p&gt; &lt;p&gt;We also enhanced our &lt;strong&gt;Session ID in URL SmartAttack&lt;/strong&gt; so it can detect session ids that are stored in unconventional ways (e.g. in a URL path parameter).&amp;nbsp; This enhancement enables the SmartAttack to perform more accurately.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/42102/info" target=%quot;_blank%quot;&gt;Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/257276</guid><pubDate>Fri, 06 Aug 2010 17:55:10 -0400</pubDate>
        <category>information disclosure vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>