<?xml version="1.0" encoding="UTF-8" standalone="yes"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.cenzic.com/public/" version="2.0"><!--

MyST Blogsite® RSS Web Feed | Powered by MySmartChannels™ Weblog Application Server

MyST Blogsite and MySmartChannels are services of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com and http://blogsite.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters:

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)
  enhanced=true|false (default=false)
  limit=n (default=15)
  score=none|emoticon|simple|stars|text (default=text)
  smartPoints=true|false (default=true)
  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)
  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>What's New | Cenzic Security Blog</title><link>http://blog.cenzic.com/public/blog/202621</link><description>Recent Web application security news from Cenzic</description><atom:link type="application/rss+xml" rel="self" href="http://blog.cenzic.com/public/rss/202621?"/><language>en-us</language><copyright>Copyright (C) 2009 Cenzic, Inc--All Rights Reserved -- This channel is part of the Cenzic Security Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 01 May 2008 13:00:52 -0400</pubDate><lastBuildDate>Fri, 12 Mar 2010 14:31:06 -0500</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V6.00.0828)</generator><image><url>http://blog.cenzic.com/styles/blogsite/Cenzic/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.cenzic.com/public/blog/202621</link><title>What's New | Cenzic Security Blog</title><description>This blogsite contains information on all security topics ranging from web application security, security software, vulnerabilities, enterprise security, penetration testing and hacker news.</description></image>
       <category>Session management</category><category>Web application security</category><category>Security trends</category><category>Security report</category><category>Managed security</category><category>Risk assessment software</category><category>enterprise security management</category>
       
       
      
    
     <item><title>Cenzic Detects an Apache Denial of Service Vulnerability</title><link>http://blog.cenzic.com/public/item/252347</link><description>Weekly product update – Cenzic detects an Apache Denial of Service Vulnerability &lt;p&gt;As of March 12, 2010 Cenzic now detects an &lt;a title="Apache DOS Vulnerability" href="http://www.securityfocus.com/bid/38491/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 38491&lt;/strong&gt;).&amp;nbsp; Successful exploits may allow remote attackers to cause denial-of-service conditions.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/38491/info" target=%quot;_blank%quot;&gt;Apache mod_proxy_ajp Module Incoming Request Body Denial Of Service Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/252347</guid><pubDate>Fri, 12 Mar 2010 14:29:47 -0500</pubDate>
        <category>apache vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Dan Shoemaker Featured on Application Security MythBusters Series</title><link>http://blog.cenzic.com/public/item/252153</link><description>Podcast on application security MythBusters featuring Dan Shoemaker, co-chair at the Dept. of Homeland Security and professor at Univ. of Detroit Mercy&lt;p&gt;As part of its Application Security MythBusters series, Cenzic interviewed &lt;a title="Dan Shoemaker" href="https://buildsecurityin.us-cert.gov/bsi/about_us/authors/689-BSI.html" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Dan Shoemaker&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;, Co-Chair at the Department of Homeland Security and Professor at the&amp;nbsp;University of Detroit Mercy.&amp;nbsp; When Cenzic&amp;rsquo;s Chief Marketing Officer, Mandeep Khera, asks Dan about his general observation of the state of Web application security, he answers in one word:&amp;nbsp; &lt;strong&gt;Abysmal&lt;/strong&gt;.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Dr. Shoemaker believes our nation is poised for a &lt;strong&gt;cyber security &amp;ldquo;9/11&amp;rdquo; type of attack &lt;/strong&gt;based on the insecure state of our Web applications.&amp;nbsp; And if you&amp;rsquo;ve never been hacked, it&amp;rsquo;s like your company is an innocent lamb; a big target for the hacker wolves out there.&amp;nbsp; &lt;/p&gt; &lt;p&gt;He also tells a story about a large company (to remain nameless) that got hacked with the Slammer Virus on a Friday night.&amp;nbsp; But they reacted quickly and fixed the problem by Monday morning to the tune of&amp;nbsp;$2M.&amp;nbsp; However, if the hacked would&amp;rsquo;ve occurred on a Tuesday, the costs to fix the attack&amp;nbsp;would&amp;rsquo;ve skyrocketed to $100M.&amp;nbsp; So they were &amp;ldquo;lucky&amp;rdquo; based on the timing of attack.&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Take home message:&lt;/strong&gt;&amp;nbsp; become a wolf or you&amp;rsquo;ll be quickly eaten by one.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Listen to the full 11 minute podcast today!&lt;/p&gt; &lt;p&gt;If you have any other questions or topic suggestions about the latest myths out there, send an email to:&amp;nbsp; &lt;a href="mailto:MythBusters@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;MythBusters@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://buildsecurityin.us-cert.gov/bsi/about_us/authors/689-BSI.html" target=%quot;_blank%quot;&gt;Learn more about Dan Shoemaker&lt;/a&gt;&lt;br/&gt;Learn more about this security expert&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/downloads/podcast/dan_shoemaker.mp3" target=%quot;_blank%quot;&gt;podcast&lt;/a&gt;&lt;br/&gt;podcast&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/252153</guid><pubDate>Mon, 08 Mar 2010 21:18:55 -0500</pubDate>
        <category>application security</category><category>podcast</category>
        
        
        
        
       
        <enclosure url="http://www.cenzic.com/downloads/podcast/dan_shoemaker.mp3" length="6732495" type="audio/mp3"/>
        
        
        
        
       </item><item><title>Cenzic Detects a PHP Validation Restriction-Bypass Vulnerability</title><link>http://blog.cenzic.com/public/item/252094</link><description>Weekly product update – Cenzic detects a PHP Validation Restriction-Bypass Vulnerability &lt;p&gt;As of March 5, 2010 Cenzic now detects a &lt;a title="PHP Validation Restriction-Bypass Vulnerability" href="http://www.securityfocus.com/bid/38431/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PHP 'tempnam()' 'safe_mode' Validation Restriction-Bypass Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 38431&lt;/strong&gt;).&amp;nbsp; Successful exploits allow attackers to access files in unauthorized locations or create files in any writable directory. This vulnerability is an issue in shared-hosting configurations where multiple users can create and execute arbitrary PHP script code; the 'safe_mode' restrictions are assumed to isolate users from each other.&amp;nbsp; PHP 5.2.12 and prior versions are affected.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/38431/info" target=%quot;_blank%quot;&gt;PHP Validation Restriction-Bypass Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/252094</guid><pubDate>Fri, 05 Mar 2010 12:21:58 -0500</pubDate>
        <category>PHP vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Hailstorm 6.5 Release</title><link>http://blog.cenzic.com/public/item/252066</link><description>Find out the latest features and benefits in the Cenzic Hailstorm 6.5 release&lt;p&gt;We just announced our &lt;a title="Cenzic Hailstorm 6.5 release" href="http://www.cenzic.com/pr_20100303/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;latest 6.5 release&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; on our Cenzic Hailstorm software product suite today.&amp;nbsp; &lt;/p&gt; &lt;p&gt;You can download the &lt;a title="What's New in 6.5" href="http://www.cenzic.com/downloads/Cenzic_Hailstorm_v6-5.pdf" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;&amp;ldquo;What&amp;rsquo;s New in Cenzic Hailstorm 6.5&amp;rdquo; brochure&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; to read more about the following:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;Open API enables enterprise integrations to other applications&amp;nbsp; &lt;/li&gt; &lt;li&gt;Significant web crawling improvements, which allow customers to initiate comprehensive security scans against a wider variety of Web applications built with diverse web technologies&amp;nbsp; &lt;/li&gt; &lt;li&gt;Enhanced enterprise capabilities such as asynchronous execution engines, floating licensing and logging improvements&amp;nbsp; &lt;/li&gt; &lt;li&gt;Improved user interface for easier group workflow and highlighting additional details on assessments, severity levels, and user comments &lt;/li&gt; &lt;/ul&gt; &lt;p&gt;&lt;strong&gt;Free Customer Training&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;If you are already a customer, be sure to sign up for our customer training on &lt;strong&gt;Thursday, March 18 at 11 AM Pacific&lt;/strong&gt;.&amp;nbsp; Jon Zucker, our product management guru, will walk you through all the important features.&amp;nbsp; Expect an email invite by next week.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/pr_20100303/" target=%quot;_blank%quot;&gt;Cenzic Enhances Flagship Web Security Offering For Open Integration with Enterprise Applications, Enhanced Usability and Increased Scalability&lt;/a&gt;&lt;br/&gt;Hailstorm® 6.5 Features Allow for Easier Workflow and Compatibility&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/downloads/Cenzic_Hailstorm_v6-5.pdf" target=%quot;_blank%quot;&gt;What's New in Cenzic Hailstorm 6.5&lt;/a&gt;&lt;br/&gt;Learn the latest technology updates in this collateral item&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/252066</guid><pubDate>Thu, 04 Mar 2010 16:28:17 -0500</pubDate>
        <category>Cenzic Hailstorm</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Web Application Security Trends Report</title><link>http://blog.cenzic.com/public/item/251943</link><description>Read the latest stats on the Web application security trends for the last half of 2009&lt;p&gt;&lt;img alt="Web application security trends report for last half of 2009" hspace="10" src="http://www.cenzic.com/images/blog/trends_q3-q4_2009.jpg" align="right" vspace="10" /&gt;We&amp;rsquo;re happy to announce &lt;a title="Web application security trends report for the last half of 2009" href="http://www.cenzic.com/pr_20100302/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Cenzic&amp;rsquo;s latest Web Application Security Trends Report&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; &amp;ndash; findings from Q3-Q4 2009.&lt;/p&gt; &lt;p&gt;The report, which illustrates trends among thousands of corporations, financial institutions and government agencies, incorporates findings from Cenzic&amp;rsquo;s leading-edge managed security assessment (SaaS) and research from Cenzic Intelligent Analysis (CIA) Labs. &lt;/p&gt; &lt;p&gt;Some of the key findings include:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;strong&gt;82 percent&lt;/strong&gt; of the total reported vulnerabilities affected Web technologies, such as Web servers, applications, Web browsers, Plugins and ActiveX, which is a significant increase from earlier in the year.&amp;nbsp; &lt;/li&gt; &lt;li&gt;Of Web browser vulnerabilities &lt;strong&gt;Firefox had the largest percentage&lt;/strong&gt;, at 44 percent but the browser also had the best patch ratio. Internet Explorer vulnerabilities came in at 25 percent.&amp;nbsp; &lt;/li&gt; &lt;li&gt;&lt;strong&gt;Adobe, Sun and HP&lt;/strong&gt; continue to be among the Top 10 vendors having the most severe vulnerabilities for the second half of 2009. &lt;/li&gt; &lt;/ul&gt; &lt;p&gt;To download a PDF version of the Q3-Q4 2009 Trend Report, please visit:&lt;br /&gt;&lt;a href="http://www.cenzic.com/downloads/Cenzic_AppSecTrends_Q3-Q4-2009.pdf"&gt;&lt;strong&gt;&lt;u&gt;http://www.cenzic.com/downloads/Cenzic_AppSecTrends_Q3-Q4-2009.pdf&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;For a hard copy of the full report you can also visit Cenzic at the &lt;strong&gt;RSA Conference&lt;/strong&gt; in San Francisco from March 1-5 at &lt;strong&gt;booth #2624&lt;/strong&gt;.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Mandeep Khera, CMO&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Mandeep@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Mandeep@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/pr_20100302/" target=%quot;_blank%quot;&gt;Cenzic Web Application Security Trends Report Reveals 90 Percent of Web Applications Vulnerable, Adobe One of The Most Vulnerable&lt;/a&gt;&lt;br/&gt;Social Networking Attacks, Cyber Terrorism, Assault on Banks Common Themes&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/downloads/Cenzic_AppSecTrends_Q3-Q4-2009.pdf" target=%quot;_blank%quot;&gt;Web Application Security Trends Report Q3 and Q4 2009&lt;/a&gt;&lt;br/&gt;Read the latest Web application security trends from Cenzic&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/251943</guid><pubDate>Tue, 02 Mar 2010 18:09:50 -0500</pubDate>
        <category>web application security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>RSA Conference 2010 Reception</title><link>http://blog.cenzic.com/public/item/251935</link><description>RSVP to attend the RSA Conference 2010 reception on Wednesday, March 3 at Jillians’ Bar &amp; Billiards Lounge &lt;p&gt;&lt;img alt="RSA Conference 2010 Reception" hspace="10" src="http://www.cenzic.com/images/blog/rsa_invite_2010.jpg" align="right" vspace="10" /&gt;Please join us for the &lt;a title="RSA Conference 2010 Reception" href="http://sanfrancisco.jbcent.com/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;RSA Conference 2010 reception&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; on Wednesday, March 3 at &lt;strong&gt;Jillians&amp;rsquo; Bar &amp;amp; Billiards Lounge&lt;/strong&gt; in the Metreon &amp;ndash; located on Level One, immediately adjacent to the Moscone Convention Center.&amp;nbsp; &lt;/p&gt; &lt;p&gt;RSVP to reserve your spot:&amp;nbsp; &lt;br /&gt;Email:&amp;nbsp; &lt;a href="mailto:aoberoi@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;aoberoi@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;u&gt; &lt;br /&gt;&lt;/u&gt;&lt;/strong&gt;Phone:&amp;nbsp; (408) 200-0742&lt;/p&gt; &lt;p&gt;Tickets will also be available on a first-come, first serve basis at the &lt;strong&gt;Cenzic booth (#2624)&lt;/strong&gt; at the &lt;a title="RSA Conference 2010" href="http://www.rsaconference.com/index.htm" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;RSA Conference&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Reception Details:&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;Date:&amp;nbsp; Wednesday, March 3, 2010&lt;br /&gt;Time:&amp;nbsp; 9 PM to Midnight&lt;br /&gt;Location:&amp;nbsp; Jillian&amp;rsquo;s Bar &amp;amp; Billiards Lounge&lt;br /&gt;101 Fourth Street&lt;br /&gt;San Francisco, CA 94103&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi, Marketing&lt;/strong&gt;&lt;br /&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://sanfrancisco.jbcent.com/" target=%quot;_blank%quot;&gt;Jillians San Francisco&lt;/a&gt;&lt;br/&gt;RSA Party RSVP now!&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.rsaconference.com/index.htm" target=%quot;_blank%quot;&gt;RSA 2010 Web Security Event&lt;/a&gt;&lt;br/&gt;Attend the annual Web security event of the year - RSA&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/251935</guid><pubDate>Tue, 02 Mar 2010 17:07:41 -0500</pubDate>
        <category>RSA Conference 2010</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects a Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability</title><link>http://blog.cenzic.com/public/item/251823</link><description>Weekly product update – Cenzic detects a Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability &lt;p&gt;As of February 26, 2010 Cenzic now detects a &lt;a title="Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability" href="http://www.securityfocus.com/bid/37995/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37995&lt;/strong&gt;).&amp;nbsp; The Sun Java System Application Server is prone to a remote information-disclosure vulnerability.&amp;nbsp; Attackers can exploit this issue to obtain potentially sensitive information that can aid in further attacks.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37995/info" target=%quot;_blank%quot;&gt;Sun Java System App Server HTTP TRACE Information Disclosure Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/251823</guid><pubDate>Fri, 26 Feb 2010 12:55:14 -0500</pubDate>
        <category>information disclosure vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects a Sun Java System Web Server Denial Of Service Vulnerability</title><link>http://blog.cenzic.com/public/item/251422</link><description>Weekly product update – Cenzic detects a Sun Java System Web Server Denial Of Service Vulnerability&lt;p&gt;As of February 19, 2010 Cenzic now detects a &lt;a title="Suna Java DOS Vulnerability" href="http://www.securityfocus.com/bid/37909/info" target="_blank"&gt;&lt;u&gt;&lt;strong&gt;Sun Java System Web Server 'admin' Server Denial of Service Vulnerability&lt;/strong&gt;&lt;/u&gt;&lt;/a&gt;&amp;nbsp;(&lt;strong&gt;BugtraqID 37909&lt;/strong&gt;).&amp;nbsp; An attacker can exploit this issue to crash the effected application, denying service to legitimate users.&amp;nbsp; Sun Java System Web Server 7.0 Update 6 is affected; other versions may also be vulnerable.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37909/info" target=%quot;_blank%quot;&gt;Sun Java System Web Server 'admin' Server Denial of Service Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/251422</guid><pubDate>Fri, 19 Feb 2010 21:13:41 -0500</pubDate>
        <category>denial of service vulnerability</category><category>Sun</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>OWASP Feb 25 Meeting: SAP, Fujitsu, PARC, Stanford, Berkeley Presenting</title><link>http://blog.cenzic.com/public/item/251363</link><description>Attend the latest OWASP meeting to hear insights on Web application security from SAP, Fujitsu, PARC, Stanford, and Berkeley&lt;p&gt;&lt;img height="183" alt="OWASP" hspace="10" src="http://www.cenzic.com/images/blog/owasp_logo.jpg" width="174" align="right" vspace="10" /&gt;Make a trip to Sunnyvale next week to attend the OWASP Bay Area meeting where we&amp;rsquo;ve invited the top security professionals from SAP, Fujitsu, PARC, Stanford, and Berkeley to share their insights on the latest Web application security trends.&lt;/p&gt; &lt;p&gt;As you know, the attendance is free and some food and a few alcoholic beverages will be provided.&amp;nbsp; &lt;strong&gt;However, please note:&lt;/strong&gt;&amp;nbsp; due to security issues at the location site (Fujitsu Offices), &lt;strong&gt;you must pre-register for the event!&lt;/strong&gt;&amp;nbsp; The registration desk will also ask for your &lt;strong&gt;citizen / permanent residence&lt;/strong&gt; &lt;strong&gt;status*.&lt;/strong&gt;&amp;nbsp; Badges will be ready at the check-in lobby for pre-registered attendees.&amp;nbsp; You can't enter the&amp;nbsp;meeting room without a badge.&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;b&gt;Register Today&lt;/b&gt; (space is limited and going fast)&lt;br /&gt;&lt;a href="http://owaspbayarea-feb2010.eventbrite.com/"&gt;&lt;b&gt;&lt;u&gt;http://owaspbayarea-feb2010.eventbrite.com/&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&lt;b&gt;Event Details&lt;br /&gt;&lt;br /&gt;Date:&lt;/b&gt;&amp;nbsp; Thursday, February 25, 2010&lt;br /&gt;&lt;b&gt;Time:&lt;/b&gt;&amp;nbsp; 1 &amp;ndash; 8 PM&lt;br /&gt;&lt;b&gt;Location:&lt;/b&gt;&amp;nbsp; &lt;br /&gt;Fujitsu Sunnyvale Campus (Building H)&lt;br /&gt;1250 E. Arques Avenue&lt;br /&gt;Sunnyvale, CA 94085&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Agenda&lt;/strong&gt;&lt;/p&gt; &lt;p&gt; &lt;table cellspacing="0" cellpadding="0" border="1" style="border-right: medium none; border-top: medium none; border-left: medium none; border-bottom: medium none; border-collapse: collapse"&gt; &lt;tbody&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: windowtext 1pt solid; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;1:00-1:15 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: windowtext 1pt solid; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;Check-in, registration, networking &lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;1:15-1:30 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;&lt;b&gt;Welcome Remarks and Overview of OWASP Bay Area&lt;/b&gt;&lt;br /&gt;Mandeep Khera, Bay Area Chapter Leader, Cenzic &lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;1:30-2:15 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;&lt;b&gt;Keynote &lt;br /&gt;&lt;/b&gt;Vishal Sikka, CTO,&lt;b&gt; SAP&lt;/b&gt; &lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;2:15-3:00 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;&lt;b&gt;WebBlaze: New Techniques and Tools for Web Security &lt;br /&gt;&lt;/b&gt;Dawn Song, Associate Professor,&lt;b&gt; UC Berkeley&lt;/b&gt; &lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;3:00-3:30 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;Networking Break, refreshments &lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;3:30-4:00 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;&lt;b&gt;State of the Art: Automated Black Box Web App Testing &lt;br /&gt;&lt;/b&gt;John Mitchell, Professor &amp;amp; Jason Bau, PH.D. Candidate &lt;br /&gt;&lt;b&gt;Stanford&lt;/b&gt;&lt;b&gt; University&lt;/b&gt;&lt;b&gt;&amp;nbsp; &lt;/b&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;4:00-4:30 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;&lt;b&gt;Controlling Data in the Cloud: Outsourcing Computation without Outsourcing Control &lt;br /&gt;&lt;/b&gt;Richard Chow, &lt;b&gt;PARC&lt;/b&gt; &lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;4:30&amp;ndash;5:00 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;Presentation Title, TBD &lt;br /&gt;Praveen Murthy,&lt;b&gt; Fujitsu&lt;/b&gt; &lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;5:00-6:00 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;&lt;b&gt;Panel Discussion &lt;br /&gt;&lt;/b&gt;Application Security Issues:&amp;nbsp; Cloud Security, Inertia, and the Future&lt;br /&gt;Q&amp;amp;A from the audience &lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td valign="top" width="127" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 95.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;6:30-8:00 PM &lt;/p&gt; &lt;/td&gt; &lt;td valign="top" width="463" style="border-right: windowtext 1pt solid; padding-right: 5.4pt; padding-left: 5.4pt; border-left-color: #ece9d8; padding-bottom: 0in; width: 347.4pt; border-top-color: #ece9d8; padding-top: 0in; border-bottom: windowtext 1pt solid; background-color: transparent"&gt; &lt;p align="left"&gt;Networking Reception - Dinner and Drinks!&lt;b&gt; &lt;/b&gt;&lt;/p&gt; &lt;/td&gt; &lt;/tr&gt; &lt;/tbody&gt; &lt;/table&gt; &lt;/p&gt; &lt;p&gt;Special thanks to Sree Rajan of Fujitsu for hosting this event and to Cenzic, AppSec Consulting, and Fujitsu for sponsoring. &lt;/p&gt; &lt;p&gt;&lt;strong&gt;*Fujitsu Policy:&lt;/strong&gt;&amp;nbsp; Please note that you will be asked to sign and write down your country of citizenship in order to comply with US Customs regulations and C/TPAT (Customs Trade Partnership Against Terrorism) certifications. As part of the compliance, we regrettably are not able to allow attendance to those who hold the citizenship of Cuba, Iran, North Korea, Sudan, or Syria without a US Green Card. We sincerely apologize for any inconvenience this may cause.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Mandeep Khera, CMO at Cenzic&lt;/strong&gt;&lt;br /&gt;&lt;a href="mailto:Mandeep@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Mandeep@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/251363</guid><pubDate>Thu, 18 Feb 2010 19:16:44 -0500</pubDate>
        <category>OWASP</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an IBM WAS Security Bypass Vulnerability</title><link>http://blog.cenzic.com/public/item/250174</link><description>Weekly product update – Cenzic detects an IBM WAS Security Bypass Vulnerability&lt;p&gt;As of February 12, 2010 Cenzic now detects an &lt;a title="IBM WAS Security Bypass Vulnerability" href="http://www.securityfocus.com/bid/38122/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;IBM WebSphere Application Server 'Requires SSL' Option Security Bypass Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 38122&lt;/strong&gt;).&amp;nbsp; IBM WebSphere Application Server (WAS) is prone to a security-bypass vulnerability.&amp;nbsp; Successful exploits allow attackers to bypass certain security restrictions, which may lead to other attacks.&amp;nbsp; This issue affects WAS 7.0 through 7.0.0.8.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;Have a great 3-day weekend everyone!&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/38122/info" target=%quot;_blank%quot;&gt;IBM WebSphere Application Server 'Requires SSL' Option Security Bypass Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/250174</guid><pubDate>Fri, 12 Feb 2010 18:24:36 -0500</pubDate>
        <category>IBM</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Web Vulnerability Scanner Comparison</title><link>http://blog.cenzic.com/public/item/250026</link><description>Remarks on the recent Web vulnerability scanner comparison by Larry Suto&lt;p&gt;Larry Suto has recently released &lt;a title="Larry Suto Report on Web Vulnerability Scanners 2010" href="http://ha.ckers.org/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;a report&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;comparing&amp;nbsp;&lt;strong&gt;various Web vulnerability scanner products&lt;/strong&gt;.&amp;nbsp; I&amp;rsquo;d like to thank Larry for his efforts and also point out that Cenzic encourages such comparisons, as they help users make more informed decisions. &lt;/p&gt; &lt;p&gt;That being said, some of the Larry&amp;rsquo;s results sparked our interest and raised a few questions.&amp;nbsp; As with any software product, results depend on how it&amp;rsquo;s configured and what assumptions are made.&amp;nbsp; Our Hailstorm product is being used by hundreds of customers who are extremely pleased with the results while testing thousands of applications on a monthly basis.&amp;nbsp; So we ran some of the test ourselves against the same target applications in an effort to better understand all of Larry&amp;rsquo;s findings. &lt;/p&gt; &lt;p&gt;Cenzic is a product of its innovation and responsiveness to our customers&amp;rsquo; needs. We&amp;rsquo;ve always been (and continue to be) highly committed to on-going product improvements (where warranted), so we&amp;rsquo;re eager to learn as much from this report as possible.&amp;nbsp; Interestingly enough, however, our own results were somewhat different than Larry&amp;rsquo;s findings.&amp;nbsp; We're&amp;nbsp;in&amp;nbsp;current discussions with Larry&amp;nbsp;to better understand how he configured the product and confirm his assumptions versus our own.&amp;nbsp; Hopefully I&amp;rsquo;ll be able to provide an update on that soon.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Lars Ewe, CTO&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Lars@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Lars@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://ha.ckers.org/files/Accuracy_and_Time_Costs_of_Web_App_Scanners.pdf" target=%quot;_blank%quot;&gt;Analyzing the Accuracy and Time Costs of Web Application Security Scanners&lt;/a&gt;&lt;br/&gt;Larry Suto 2010 report on Web vulnerability scanners&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/250026</guid><pubDate>Wed, 10 Feb 2010 22:55:08 -0500</pubDate>
        <category>web vulnerability scanner</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>ISC2 Security Leadership Event</title><link>http://blog.cenzic.com/public/item/249748</link><description>Attend the ISC2 Security Leadership event tomorrow in San Jose, CA&lt;p&gt;If you happen to be in the heart of Silicon Valley on February 9, 2010, then attend the &lt;a title="ISC2 Leadership Event Feb 9, 2010" href="http://www.isc2.org/EventDetails.aspx?id=5644" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;ISC2 Security Leadership event&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; at the Double Tree Hotel in San Jose, CA.&amp;nbsp; &lt;/p&gt; &lt;p&gt;The all-day event (9-5 pm) will focus on how to measure your security success (or failure), so be prepared to hear ways you can explore methods for determining how well you&amp;rsquo;re managing the limited labor, capital, and technology resources.&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Event Details:&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;ISC2 Security Leadership Seminar &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Title:&lt;/strong&gt;&amp;nbsp; Fact not FUD:&amp;nbsp; Managing What You Can Measure&lt;br /&gt;&lt;strong&gt;Date:&lt;/strong&gt;&amp;nbsp; Tuesday, February 9, 2010&lt;br /&gt;&lt;strong&gt;Time:&lt;/strong&gt;&amp;nbsp; 9 &amp;ndash; 5 PM&lt;br /&gt;&lt;strong&gt;Location:&lt;/strong&gt;&amp;nbsp; Double Tree Hotel in San Jose, CA&lt;/p&gt; &lt;p&gt;See you there tomorrow!&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.isc2.org/EventDetails.aspx?id=5644" target=%quot;_blank%quot;&gt;ISC2 Secure San Jose Event&lt;/a&gt;&lt;br/&gt;Attend this Security Leadership event on Feb 9, 2010&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249748</guid><pubDate>Mon, 08 Feb 2010 16:46:46 -0500</pubDate>
        <category>Security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cyber Security Predictions for the Next Decade</title><link>http://blog.cenzic.com/public/item/249747</link><description>Top 5 cyber security predictions for the upcoming decade&lt;p&gt;Enterprise Systems Magazine just published my top 5 cyber security predictions for the upcoming decade and I wanted to share them with you.&amp;nbsp; I hope you enjoy them &amp;hellip; and please send any comments my way as well.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Top 5 Cyber Security Predictions for the next 10 years:&lt;/strong&gt;&lt;/p&gt; &lt;ol&gt; &lt;li&gt;Despite government efforts, cyber war will be more common with more severe Web application attacks. We&amp;rsquo;ve been predicting cyber wars for a couple of years and have started to see significant incidents in 2009.&amp;nbsp; In addition, hackers will target telecommunications and utility infrastructures of key nations.&amp;nbsp;&lt;/li&gt; &lt;li&gt;Social network sites like Facebook and Twitter will continue to be targeted for attacks due to their popularity and usage.&amp;nbsp; Game changing social networking apps will emerge each with a unique set of security challenges.&amp;nbsp; Social networking will become even more prevalent as hackers go after these user bases looking for personal financial information to enable them to siphon money from bank accounts and credit cards.&amp;nbsp; Data from social networks will also give rise to increased identity theft as hackers sort through social networks to gather clues to unlock passwords and steal identities.&amp;nbsp;&lt;/li&gt; &lt;li&gt;The rise in Smartphone use, particularly the popularity of specific phones (i.e. the iPhone), begets an escalation in mobile app use as more and more people use phone apps to enhance both their business and personal worlds.&amp;nbsp; These downloadable apps will increasingly become a target for hackers who see millions of potential targets, most of which use a Web infrastructure for hackers to exploit.&amp;nbsp;&lt;/li&gt; &lt;li&gt;Cloud computing will become more prevalent as organizations try to optimize their infrastructure to streamline costs.&amp;nbsp; However, inherent security risks are synonymous with Cloud computing, as hackers will target Cloud providers.&amp;nbsp;&lt;/li&gt; &lt;li&gt;The collective security consciousness will be raised.&amp;nbsp; Businesses large and small will adopt technologies to secure their Websites, regulations will be developed, and fines increased. Universities will make security, especially application security, a mandatory requirement for all development courses and there will be more regulations around cyber security including increases in fines to companies found negligent along with more severe criminal punishment for hackers. Yet, hackers will also become more organized and sophisticated.&lt;/li&gt; &lt;/ol&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Mandeep Khera, CMO&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Mandeep@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Mandeep@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.esj.com/articles/2010/02/02/Cybersecurity-Past-and-Present.aspx" target=%quot;_blank%quot;&gt;Q&amp;A: Assessing Cybersecurity's Past, Planning for the Future&lt;/a&gt;&lt;br/&gt;How regulation, social networking, and popular technologies will impact enterprise security management&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249747</guid><pubDate>Mon, 08 Feb 2010 16:28:22 -0500</pubDate>
        
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an Apache Integer Overflow Vulnerability</title><link>http://blog.cenzic.com/public/item/249608</link><description>Weekly product update – Cenzic detects an Apache Integer Overflow Vulnerability&lt;p&gt;As of February 5, 2010 Cenzic now detects an &lt;a title="Apache Integer Overflow Vulnerability" href="http://www.securityfocus.com/bid/37966/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37966&lt;/strong&gt;).&amp;nbsp; An attacker can exploit&amp;nbsp;the Apache remote integer overflow vulnerability&amp;nbsp;and execute arbitrary code.&amp;nbsp; Successful exploits will compromise affected computers.&amp;nbsp; Failed exploit attempts will result in a denial-of-service condition.&amp;nbsp; Note that this issue affects platforms on which 'sizeof(int)' is less than 'sizeof(long)'.&amp;nbsp; In particular, this occurs on some 64-bit architectures.&amp;nbsp; Versions prior to Apache 1.3.42 are vulnerable.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37966/info" target=%quot;_blank%quot;&gt;Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249608</guid><pubDate>Fri, 05 Feb 2010 15:49:36 -0500</pubDate>
        <category>apache vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>SANS Application Security 2010 Conference</title><link>http://blog.cenzic.com/public/item/249487</link><description>We hope to see you at the SANS Application Security 2010 Conference in San Francisco&lt;p&gt;I just got back from the cocktail reception that kicked off the &lt;a title="SANS 2010 Application Security Conference" href="https://www.sans.org/appsec-2010/summit.php#overview" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;SANS Application Security Conference&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; held at the Sheraton Fisherman&amp;rsquo;s Wharf Hotel in San Francisco this year.&amp;nbsp; &lt;/p&gt; &lt;p&gt;So stop tomorrow (Feb 4) for a free lunch at 12:30 PM in the President&amp;rsquo;s Ballroom and hear our esteemed CTO, Lars Ewe, present on &lt;strong&gt;&amp;ldquo;AJAX:&amp;nbsp; The Truth Behind the Hype&amp;rdquo;&lt;/strong&gt;.&amp;nbsp; Lars is also a panelist in the &lt;strong&gt;SANS vendor tools shootout&lt;/strong&gt; (along with IBM and Vericode) at 4:30 PM.&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Some of the things you&amp;rsquo;ll learn at the SANS Application Security Conference include:&lt;/strong&gt;&lt;/p&gt; &lt;ol&gt; &lt;li&gt;The essentials of a comprehensive Web site security program and how to secure a Website &lt;/li&gt; &lt;li&gt;The most current information on Web hacking techniques and how to guard against these prevalent Web vulnerabilities &lt;/li&gt; &lt;li&gt;Unique procurement practices that will help manage application security outsourcing and improve application security &lt;/li&gt; &lt;li&gt;The confessions of a professional Web application hacker &lt;/li&gt; &lt;li&gt;What your peers are doing to secure their Web applications and Web application best practices &lt;/li&gt; &lt;li&gt;What tools are available and how do they compare? Which tools should you have in your security toolbox to ensure your applications are locked up tight. &lt;/li&gt; &lt;/ol&gt; &lt;p&gt;Looking forward to seeing you there!&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://www.sans.org/appsec-2010/summit.php#overview" target=%quot;_blank%quot;&gt;SANS Security Summit&lt;/a&gt;&lt;br/&gt;Attend the Feb 4-5 SANS Security Summit held in San Francisco, CA&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249487</guid><pubDate>Wed, 03 Feb 2010 18:16:18 -0500</pubDate>
        <category>application security</category><category>SANS</category>
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>