<?xml version="1.0" encoding="UTF-8" standalone="yes"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.cenzic.com/public/" version="2.0"><!--

MyST Blogsite® RSS Web Feed | Powered by MySmartChannels™ Weblog Application Server

MyST Blogsite and MySmartChannels are services of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com and http://blogsite.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters:

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)
  enhanced=true|false (default=false)
  limit=n (default=15)
  score=none|emoticon|simple|stars|text (default=text)
  smartPoints=true|false (default=true)
  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)
  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>What's New | Cenzic Security Blog</title><link>http://blog.cenzic.com/public/blog/202621</link><description>Recent Web application security news from Cenzic</description><atom:link type="application/rss+xml" rel="self" href="http://blog.cenzic.com/public/rss/202621?"/><language>en-us</language><copyright>Copyright (C) 2009 Cenzic, Inc--All Rights Reserved -- This channel is part of the Cenzic Security Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 01 May 2008 13:00:52 -0400</pubDate><lastBuildDate>Thu, 02 Jul 2009 20:07:28 -0400</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V6.00.0627)</generator><image><url>http://blog.cenzic.com/styles/blogsite/Cenzic/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.cenzic.com/public/blog/202621</link><title>What's New | Cenzic Security Blog</title><description>This blogsite contains information on all security topics ranging from web application security, security software, vulnerabilities, enterprise security, penetration testing and hacker news.</description></image>
       <category>Session management</category><category>Web application security</category><category>Security trends</category><category>Security report</category><category>Managed security</category><category>Risk assessment software</category><category>enterprise security management</category>
       
       
      
    
     <item><title>OWASP Security Spending Report</title><link>http://blog.cenzic.com/public/item/235655</link><description>Read the March 2009 OWASP Security Spending Report&lt;p&gt;If case you haven&amp;rsquo;t had a chance to read &lt;a title="OWASP Security Spending Report March 2009" href="http://www.eema.org/downloads/is_finished_papers/OWASP_SSB_Project_Report_March_2009.pdf" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;OWASP&amp;rsquo;s latest security spending report&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;, I suggest you take a peek over the long holiday weekend.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;Key findings of this study are:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Organizations that have suffered a public data breach spend more on security in the development process than those that have not.&lt;/li&gt;&lt;li&gt;Web application security spending is expected to either stay flat or increase in nearly two thirds of companies.&lt;/li&gt;&lt;li&gt;Half of respondents consider &lt;strong&gt;security experience important when hiring developers&lt;/strong&gt;, and a majority provide their developers with security training.&lt;/li&gt;&lt;li&gt;At least 61% of respondents perform an independent third party security review before deploying a Web application while 17% do not (the remainder do not know or do so when requested by customers).&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.eema.org/downloads/is_finished_papers/OWASP_SSB_Project_Report_March_2009.pdf" target=%quot;_blank%quot;&gt;OWASP Security Spending Report&lt;/a&gt;&lt;br/&gt;Read the March 2009 OWASP Security Spending Report&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235655</guid><pubDate>Thu, 02 Jul 2009 20:05:39 -0400</pubDate>
        <category>OWASP</category><category>security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>SaaS Web Vulnerability Scanning</title><link>http://blog.cenzic.com/public/item/235653</link><description>Read what's new in the 6.0 launch of our SaaS Web vulnerability scanning product – Cenzic ClickToSecure&lt;p&gt;&lt;a href="http://www.cenzic.com/downloads/Cenzic_ClickToSecure_v6.pdf"&gt;&lt;img alt="Read what's new in our SaaS vulnerability product" hspace="10" src="http://www.cenzic.com/images/blog/whats_new_cts_v6.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;If you are looking for a &lt;strong&gt;Web vulnerability scanning product&lt;/strong&gt; &amp;ndash; either software or SaaS &amp;ndash; you should check out Cenzic.&amp;nbsp; We just launched our 6.0 release of both products &amp;ndash; Cenzic Hailstorm (software) and Cenzic ClickToSecure (SaaS).&amp;nbsp; &lt;/p&gt;&lt;p&gt;Read what&amp;rsquo;s new in our &lt;a title="What's New in our SaaS Web Vulnerability Scanning Product" href="http://www.cenzic.com/downloads/Cenzic_ClickToSecure_v6.pdf" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;SaaS product here&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; Some feature highlights include:&amp;nbsp; &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Pages Visited&lt;/strong&gt; &amp;ndash;&amp;nbsp; Monitors URL Requests during &amp;amp; after Assessment runs&amp;nbsp;&lt;/li&gt;&lt;li&gt;Web Application Firewall (Imperva/SecureSphere) integration&lt;/li&gt;&lt;li&gt;Ability to request Assessments in multiple ways&lt;/li&gt;&lt;li&gt;Ability to run and &lt;strong&gt;schedule self Assessments&lt;/strong&gt;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improved Web 2.0 support&lt;/strong&gt;, specifically for Flash and AJAX based Web applications&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/downloads/Cenzic_ClickToSecure_v6.pdf" target=%quot;_blank%quot;&gt;Cenzic ClickToSecure&lt;/a&gt;&lt;br/&gt;Learn the latest in our 6.0 launch of SaaS Web vulnerability scanning product&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235653</guid><pubDate>Thu, 02 Jul 2009 19:48:38 -0400</pubDate>
        <category>Web vulnerability scanning</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>What’s New in Our Web Application Security Product, Cenzic Hailstorm 6.0</title><link>http://blog.cenzic.com/public/item/235559</link><description>Read what’s new in our Web application security software products – Cenzic Hailstorm Enterprise ARC and Professional 6.0&lt;p&gt;&lt;a href="http://www.cenzic.com/downloads/Cenzic_Hailstorm_v6.pdf"&gt;&lt;img alt="What's New in Cenzic Hailstorm 6.0" hspace="10" src="http://www.cenzic.com/images/blog/whats_new_hailstorm_v6.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;Just in case you wanted to read the feature / benefit details about our latest &lt;strong&gt;Web application security software release&lt;/strong&gt;, here&amp;rsquo;s&amp;nbsp;some &lt;a title="What's New in Cenzic Hailstorm 6.0" href="http://www.cenzic.com/downloads/Cenzic_Hailstorm_v6.pdf" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;information&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp;&amp;nbsp;It will be posted to our Website shortly, and as a customer, you&amp;rsquo;ll get a hard copy of it in the mail.&amp;nbsp; &lt;/p&gt;&lt;p&gt;It&amp;rsquo;s been two weeks since our launch&amp;nbsp;and we&amp;rsquo;ve received nothing but positive praise from our users&amp;nbsp;&amp;ndash; so if you haven&amp;rsquo;t upgraded yet, do so before the July 4th weekend.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/downloads/Cenzic_Hailstorm_v6.pdf" target=%quot;_blank%quot;&gt;What's New in Cenzic Hailstorm 6.0&lt;/a&gt;&lt;br/&gt;Read the latest features and benefits of our latest software release&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235559</guid><pubDate>Tue, 30 Jun 2009 19:31:44 -0400</pubDate>
        <category>cenzic</category><category>web application security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Defining and Detecting HTTP Parameter Pollution</title><link>http://blog.cenzic.com/public/item/235538</link><description>Learn more about HTTP Parameter Pollution and find out ways to detect this latest attack&lt;p&gt;&lt;a href="http://tacticalwebappsec.blogspot.com/2009/05/http-parameter-pollution.html"&gt;&lt;img alt="HTTP Parameter Pollution" hspace="10" src="http://www.cenzic.com/images/blog/fingerprint.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;There&amp;rsquo;s been a lot chat on Twitter recently about HTTP Parameter Pollution,&amp;nbsp; so I wanted to describe the vulnerability in more detail and how Cenzic can detect it in its latest SmartAttack release.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What is HTTP Parameter Pollution?&lt;/strong&gt;&lt;br /&gt;An HTTP Parameter Pollution is where an attacker can submit additional parameters to a Web application -- and if these parameters have the same name as an existing parameter -- the Web application may react in one of the following ways -&lt;/p&gt;&lt;ul&gt;&lt;li&gt;It may only take the data from the first parameter&lt;/li&gt;&lt;li&gt;It may take the data from the last parameter&lt;/li&gt;&lt;li&gt;It may take the data from all parameters and concatenate them together&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Such results enable the attackers to distribute attack payloads across multiple parameters to evade signature-based filters.&amp;nbsp; For more details about the attack, visit this &lt;a href="http://tacticalwebappsec.blogspot.com/2009/05/http-parameter-pollution.html"&gt;&lt;strong&gt;&lt;u&gt;blog post&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and/or read this recent &lt;a title="PPT on HTTP Parameter Pollution" href="http://www.owasp.org/images/b/ba/AppsecEU09_CarettoniDiPaola_v0.8.pdf" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PowerPoint presentation&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; delivered at an OWASP European meeting. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;How to Detect an HTTP Parameter Pollution Vulnerability:&lt;/strong&gt;&lt;br /&gt;The latest Cenzic SmartAttack walks the traversal and identifies HTTP requests that are candidates for fault injection.&amp;nbsp; For each candidate request, the SmartAttack sends a series of pairs of injected requests with each parameter repeated once with its original value and once with an incorrect value.&lt;/p&gt;&lt;p&gt;If the application gives different responses for the original and the injected injection request, it ensures that the application is blindly looking at the last occurrence of the parameter and the SmartAttack generates a Failure.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://tacticalwebappsec.blogspot.com/2009/05/http-parameter-pollution.html" target=%quot;_blank%quot;&gt;HTTP Parameter Pollution&lt;/a&gt;&lt;br/&gt;Blog post from Tactical Web Application Security&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.owasp.org/images/b/ba/AppsecEU09_CarettoniDiPaola_v0.8.pdf" target=%quot;_blank%quot;&gt;Presentation of HTTP Parameter Pollution&lt;/a&gt;&lt;br/&gt;Shown at a 2009 OWASP AppSec Europe conference&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235538</guid><pubDate>Tue, 30 Jun 2009 11:25:52 -0400</pubDate>
        <category>HTTP Parameter Pollution</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Issues New SmartAttack in 6.0 Release: HTTP Parameter Pollution Vulnerability</title><link>http://blog.cenzic.com/public/item/235439</link><description>The HTTP Parameter Pollution Vulnerability is now detectable in Cenzic’s 6.0 release as a new SmartAttack category&lt;p&gt;As of June 26, 2009, Cenzic added its &lt;strong&gt;101st SmartAttack&lt;/strong&gt; to its latest 6.0 product suite:&amp;nbsp; &lt;strong&gt;HTTP Parameter Pollution Vulnerability&lt;/strong&gt; (version 1.0).&amp;nbsp; &lt;/p&gt;&lt;p&gt;Published just a few days back, the HTTP Parameter Pollution Vulnerability is one of the newest ways hackers can exploit Web applications.&amp;nbsp; It pinpoints the anomaly in handling multiple occurrences of the same parameter by various platforms. This vulnerability plays the role of the &amp;quot;enabler&amp;quot;, which can be exploited by an attacker to further craft complex and destructive attacks.&amp;nbsp; Due to the devastating nature of this attack, we created a new SmartAttack immediately to enable our customers to detect such vulnerabilities and avoid further attacks.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Web Server Vulnerabilities SmartAttack Update&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;In this week&amp;rsquo;s update, we&amp;rsquo;ve also enhanced our Web Server Vulnerabilities SmartAttack to it can detect the &lt;a title="PHP DOS Vulnerability" href="http://www.securityfocus.com/bid/35440/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PHP 'exif_read_data()' JPEG Image Processing Denial Of Service Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 35440&lt;/strong&gt;).&amp;nbsp; PHP is prone to a denial-of-service vulnerability in its 'exif_read_data()' function.&amp;nbsp; Successful exploits may allow remote attackers to cause denial-of-service conditions in applications that use the vulnerable function.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/35440/" target=%quot;_blank%quot;&gt;PHP 'exif_read_data()' JPEG Image Processing Denial Of Service Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235439</guid><pubDate>Fri, 26 Jun 2009 17:38:02 -0400</pubDate>
        <category>cenzic</category><category>HTTP Parameter Pollution Vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Black Hat 2009 – Learn the Latest Security Trends</title><link>http://blog.cenzic.com/public/item/235334</link><description>The latest security trends will be highlighted at the Black Hat 2009 event in Vegas&lt;p&gt;&lt;img alt="Black Hat 2009 Conference Event in Las Vegas" hspace="10" src="http://www.cenzic.com/images/blog/black_hat_briefings_and_training.jpg" align="right" vspace="10" border="0" /&gt;It&amp;rsquo;s the time of year again to &amp;ldquo;get your geek on&amp;rdquo; as the &lt;a title="Black Hat 2009 Event held in Las Vegas, NV" href="https://www.blackhat.com/html/bh-usa-09/bh-usa-09-schedule.html" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Black Hat 2009&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; event is gearing up for another amazing display of the coolest security trends in hot Las Vegas, NV.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;The conference is held at &lt;strong&gt;Caesar&amp;rsquo;s Palace&lt;/strong&gt; and starts at 8 AM sharp on &lt;strong&gt;Wednesday, July 29&lt;/strong&gt; and ends on that Thursday afternoon (&lt;strong&gt;July 30&lt;/strong&gt;).&amp;nbsp; &lt;/p&gt;&lt;p&gt;Be sure to stop by &lt;strong&gt;Cenzic&amp;rsquo;s booth #17&lt;/strong&gt; to see our latest product suite release:&amp;nbsp; 6.0.&amp;nbsp; &lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://www.blackhat.com/html/bh-usa-09/bh-usa-09-schedule.html" target=%quot;_blank%quot;&gt;Black Hat 2009 Event Schedule&lt;/a&gt;&lt;br/&gt;Find the coolest security talk you can't live without&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235334</guid><pubDate>Wed, 24 Jun 2009 17:38:34 -0400</pubDate>
        <category>Black Hat</category><category>Black Hat 2009</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Recording on Web Application Security – A Ticking Time Bomb!</title><link>http://blog.cenzic.com/public/item/235277</link><description>Get recording and slides on 5 reasons why you need Web application security now&lt;p&gt;&lt;a href="http://www.cenzic.com/resources/webinars/tickingtimebomb/"&gt;&lt;img alt="Webcast recording on Forrester presentation June 2009" hspace="10" src="http://www.cenzic.com/images/blog/timebomb.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;If you missed the live Forrester event on the &lt;a title="Webcast recording on Forrester presentation June 2009" href="http://www.cenzic.com/resources/webinars/tickingtimebomb/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;5 top reasons why you need Web application security now&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;, then get the recording and the slides.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Just fill out our short Web registration form to learn:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Complexities around application security &lt;/li&gt;&lt;li&gt;Cost of not doing anything &lt;/li&gt;&lt;li&gt;Easier and cheaper solutions to secure your Web applications in this tough economy&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Presenters:&lt;/strong&gt;&amp;nbsp;&amp;nbsp; &lt;br /&gt;Chenxi Wang, Senior Analyst at &lt;strong&gt;Forrester Research &lt;/strong&gt;and &lt;br /&gt;Mandeep Khera, CMO of Cenzic&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/resources/webinars/tickingtimebomb/" target=%quot;_blank%quot;&gt;Get recording and slides to this Forrest Webcast&lt;/a&gt;&lt;br/&gt;5 reasons why you need Web application security now&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235277</guid><pubDate>Tue, 23 Jun 2009 19:38:45 -0400</pubDate>
        <category>web application security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>PCI Blues - MasterCard Tightens PCI Compliance Requirements</title><link>http://blog.cenzic.com/public/item/235123</link><description>Level 2 merchants are required to undergo on-site audits for PCI compliance&lt;p&gt;MasterCard issued&amp;nbsp;&lt;strong&gt;new requirements for PCI compliance for Level 2 merchants&lt;/strong&gt; -- they will soon be required&amp;nbsp;to do an annual on-site audit.&amp;nbsp; This used to be a requirement for Level 1 merchants only.&amp;nbsp; Level 1 merchants are retailers doing more than 6 million credit card transactions a year where as Level 2 merchants do between 1 million and 6 million transactions. The requirements go into effect on &lt;strong&gt;December 31, 2010&lt;/strong&gt;. &lt;/p&gt;&lt;p&gt;MasterCard's&amp;nbsp;intentions are good, as&amp;nbsp;they are trying to ensure retailers have better controls.&amp;nbsp; However,&amp;nbsp;I still believe that instead of creating more bureacracy and audits, we need to focus more on looking at the requirements of the PCI standard and clarifying what to do. &lt;/p&gt;&lt;p&gt;PCI Data Security Standard is a good thing and has raised awareness for security issues for the merchants.&amp;nbsp; But&amp;nbsp;most merchants, especially the smaller ones, are still confused on what to do.&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;Merchants who are attaining compliance out of fear are being lulled into a false sense of security by run-of-the-mill vendors who issue a certificate for a few&amp;nbsp;hundred bucks.&amp;nbsp; Here's my 5-step recommended plan for a better process on making sure that merchants get a tighter security for their infrastructure:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Education:&lt;/strong&gt;&amp;nbsp; Focus on educating merchants on different levels of security. Credit card companies should offer free Web seminars and courses to help merchants in basic security issues. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Clear rules:&lt;/strong&gt;&amp;nbsp; PCI concil should continue to work on clarifying the requirements and how to get compliant. The last version helped and hopefully we can keep simpifying the standard. For example, throwing an app firewall at the problem does not equal secure applications. &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Subsidies:&lt;/strong&gt;&amp;nbsp; Credit card companies should provide subsidies for smaller merchants who can't afford to pay for security.&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Focus on the Weakest link:&lt;/strong&gt;&amp;nbsp; With 80% of attacks happening through the Web applications, it's the weakest link. Yet, most of the focus of the standard is on network security.&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Enforcement and positive reinforcement:&lt;/strong&gt;&amp;nbsp; With clear rules, subsidies, and education in place, there shouldn't be many excuses for merchants to not comply. Start enforcing by initial warning and then penalties. Give visibilty to the good merchants so they can increase their sales. &lt;/li&gt;&lt;/ol&gt;&lt;p&gt;With over 250 million records stolen in 2008 alone, resulting in billions of dollars in losses, it's obvious that the current rules are not working.&amp;nbsp; Something has to change.&amp;nbsp; Period.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Mandeep Khera, CMO&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Mandeep@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Mandeep@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235123</guid><pubDate>Fri, 19 Jun 2009 20:23:13 -0400</pubDate>
        <category>PCI</category><category>pci compliance</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an Apache Tomcat XML Parser Information Disclosure Vulnerability</title><link>http://blog.cenzic.com/public/item/235113</link><description>An Apache Tomcat XML Parser Information Disclosure Vulnerability is now detectable in the Cenzic Web Server SmartAttack&lt;p&gt;As of June 19, 2009, Cenzic can detect the &lt;a title="Apache Tomcat XML Parser Information Disclosure Vulnerability" href="http://www.securityfocus.com/bid/35416/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache Tomcat XML Parser Information Disclosure Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 35416&lt;/strong&gt;).&amp;nbsp; Apache Tomcat is prone to an Information Disclosure Vulnerability where attackers can exploit this issue to obtain sensitive information that may lead to further attacks.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/35416/" target=%quot;_blank%quot;&gt;Apache Tomcat XML Parser Information Disclosure Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235113</guid><pubDate>Fri, 19 Jun 2009 15:02:33 -0400</pubDate>
        <category>apache</category><category>information disclosure vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Partner Brings Web Application Security to South Africa</title><link>http://blog.cenzic.com/public/item/235006</link><description>CentricEdge introduces Cenzic’s Web application security products at South African event&lt;p&gt;&lt;a href="http://www.itweb.co.za/events/securitysummit/2009/registration.asp"&gt;&lt;img alt="CentricEdge introducing Cenzic at South African Event" hspace="10" src="http://www.cenzic.com/images/blog/booth30.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;Cenzic, in collaboration with its South African partner, &lt;strong&gt;CentricEdge&lt;/strong&gt;, was a sponsor at this year&amp;rsquo;s &lt;a title="ITWeb Annual Security Summit" href="http://www.itweb.co.za/events/securitysummit/2009/registration.asp" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;ITWeb Annual Security Summit&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; to educate audience members on Web application security.&amp;nbsp; &lt;/p&gt;&lt;p&gt;The South African event highlighted tools, techniques, and strategies for organizations to adopt in order to &lt;strong&gt;better safeguard their information&lt;/strong&gt;.&amp;nbsp; Key themes at this year&amp;rsquo;s event included &lt;strong&gt;cybercrime&lt;/strong&gt;, mobile security, &lt;strong&gt;security in the cloud&lt;/strong&gt;, AV malware, threat modelling, the security development lifecycle, PCI compliance, Web security, virtualization and security, and vulnerability management.&amp;nbsp; &lt;/p&gt;&lt;p&gt;We&amp;rsquo;d like to &lt;strong&gt;thank CenzicEdge&lt;/strong&gt; for creating the tradeshow display containing Cenzic branding along with pitching our technology to a new audience.&amp;nbsp; Their Website is under maintenance at the moment, but check back soon to learn more about this company: &lt;a href="http://www.centricedge.co.za/"&gt;&lt;strong&gt;&lt;u&gt;www.centricedge.co.za&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Chris Carvacho, Sales Ops&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:CCarvacho@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;CCarvacho@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.itweb.co.za/events/securitysummit/2009/registration.asp" target=%quot;_blank%quot;&gt;ITWeb Annual Security Summit&lt;/a&gt;&lt;br/&gt;Learn more about this annual South African security event&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.centricedge.co.za" target=%quot;_blank%quot;&gt;CentricEdge&lt;/a&gt;&lt;br/&gt;Learn more about this Web security consulting company in South Africa&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/235006</guid><pubDate>Wed, 17 Jun 2009 20:07:26 -0400</pubDate>
        <category>web application security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic 6.0 Product Launch for Software &amp; Cloud Computing Options</title><link>http://blog.cenzic.com/public/item/234944</link><description>Cenzic announces the latest launch of its software and cloud computing products that protect Websites against hacker attacks&lt;p&gt;&lt;a href="http://www.cenzic.com/pr_20090616/"&gt;&lt;img alt="Cenzic announces its latest 6.0 product suite release" hspace="10" src="http://www.cenzic.com/images/blog/clouds.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;Today&amp;rsquo;s launch day here at Cenzic &amp;ndash; we have the &lt;a title="Cenzic announces the 6.0 release of its product suite" href="http://www.cenzic.com/pr_20090616/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;latest releases for both our software and cloud computing products&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; that will help you better protect your Websites from hackers.&amp;nbsp; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cenzic's 6.0 Product Suite&lt;/strong&gt; (Click-to-Secure, Hailstorm Enterprise ARC and Hailstorm Professional) &lt;strong&gt;now includes&lt;/strong&gt;:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;More &lt;strong&gt;self-service&lt;/strong&gt; capabilities for SaaS customers&lt;/li&gt;&lt;li&gt;Significant enhancements to vulnerability findings in &lt;strong&gt;Web 2.0 technologies&lt;/strong&gt; such as Ajax and Flash &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Real-time monitoring&lt;/strong&gt; of application assessments with actionable results &lt;/li&gt;&lt;li&gt;Integration with &lt;strong&gt;Imperva&amp;rsquo;s SecureSphere Web Application Firewall&lt;/strong&gt; allowing for the export of assessment results &lt;/li&gt;&lt;li&gt;User interface and dashboard improvements for &lt;strong&gt;ease of use&lt;/strong&gt; and manageability&lt;/li&gt;&lt;li&gt;Full support for &lt;strong&gt;CVE and CWE IDs&lt;/strong&gt; maintained by MITRE &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Increased scalability&lt;/strong&gt; with &lt;strong&gt;parallel processing&lt;/strong&gt; to allow for running multiple assessments &lt;/li&gt;&lt;li&gt;&lt;strong&gt;Improved spidering&lt;/strong&gt; features to strengthen application coverage &lt;/li&gt;&lt;li&gt;Integration with IBM Rational ClearQuest &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;So take a test drive of our latest product suite today!&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/pr_20090616/" target=%quot;_blank%quot;&gt;Cenzic Announces New Web Security Product Releases Focused on Cloud Computing, Web 2.0, Scalability, Integrations, and Industry Standards&lt;/a&gt;&lt;br/&gt;Integration to IBM ClearQuest and Imperva Firewall Among New Features&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/234944</guid><pubDate>Tue, 16 Jun 2009 18:07:51 -0400</pubDate>
        <category>cenzic</category><category>cloud computing</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an Apache Tomcat Authentication Vulnerability</title><link>http://blog.cenzic.com/public/item/234743</link><description>An Apache Tomcat Authentication Vulnerability is now detectable in the Cenzic Web Server SmartAttack&lt;p&gt;As of June 12, 2009, Cenzic can detect the &lt;a title="Apache Tomcat Authentication Vulnerability" href="http://www.securityfocus.com/bid/35196/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 35196&lt;/strong&gt;).&amp;nbsp; Apache Tomcat is prone to a username-enumeration weakness because it displays different responses to login attempts, depending on whether or not the username exists.&amp;nbsp; Attackers may exploit this weakness to discern valid usernames. This may aid them in brute-force password cracking or other attacks.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/35196/" target=%quot;_blank%quot;&gt;Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/234743</guid><pubDate>Fri, 12 Jun 2009 16:37:32 -0400</pubDate>
        <category>apache tomcat vulnerability</category><category>cenzic</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Last Chance to Ask Forrester Analyst About Web Security</title><link>http://blog.cenzic.com/public/item/234597</link><description>Attend today’s live Web seminar on Web Security and ask Forrester analyst questions&lt;p&gt;&lt;a href="http://w.on24.com/r.htm?e=149382&amp;s=1&amp;k=B344C62464138EA4CE476A6664CE7FCE&amp;partnerref=CZBlog"&gt;&lt;img alt="Web seminar on Web Security from Forrester Analyst" hspace="10" src="http://www.cenzic.com/images/blog/timebomb.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;Well today&amp;rsquo;s the big day for our live Web seminar on &lt;a title="Web seminar on Web security by Forrester analyst" href="http://w.on24.com/r.htm?e=149382&amp;s=1&amp;k=B344C62464138EA4CE476A6664CE7FCE&amp;partnerref=CZBlog" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Web security, presented by Forrester analyst Chenxi Wang&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; Be sure to attend so you can ask her questions about the specifics of why the need is stronger than ever to protect your data.&lt;/p&gt;&lt;p&gt;We look forward to you &amp;ldquo;seeing&amp;rdquo; you later today!&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Forrester Webcast:&amp;nbsp; 5 reasons why you need Web security now&lt;br /&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;For:&lt;/strong&gt;&amp;nbsp; Security professionals in charge of protecting Websites and ensuring regulatory compliance&lt;br /&gt;&lt;strong&gt;Date:&lt;/strong&gt; Thursday, June 11, 2009 &lt;br /&gt;&lt;strong&gt;Time:&lt;/strong&gt; 11 am Pacific (2 pm Eastern) &lt;br /&gt;Duration: 1 hour &lt;br /&gt;&lt;strong&gt;Cost:&lt;/strong&gt; Complimentary&lt;br /&gt;&lt;strong&gt;Presenters:&lt;/strong&gt;&amp;nbsp;&amp;nbsp; &lt;br /&gt;Chenxi Wang, Senior Analyst at Forrester Research and &lt;br /&gt;Mandeep Khera, CMO of Cenzic&lt;br /&gt;&lt;br /&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://w.on24.com/r.htm?e=149382&amp;s=1&amp;k=B344C62464138EA4CE476A6664CE7FCE&amp;partnerref=CZBlog" target=%quot;_blank%quot;&gt;Register to attend this Forrest Webcast&lt;/a&gt;&lt;br/&gt;5 reasons why you need Web security now&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/234597</guid><pubDate>Thu, 11 Jun 2009 10:52:31 -0400</pubDate>
        <category>web security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an Apache Tomcat Denial of Service Vulnerability</title><link>http://blog.cenzic.com/public/item/234342</link><description>An Apache Tomcat Denial of Service Vulnerability is now detectable in the Cenzic Web Server SmartAttack&lt;p&gt;&lt;a href="http://www.securityfocus.com/bid/35193/"&gt;&lt;img alt="Cenzic weekly product updates" hspace="10" src="http://www.cenzic.com/images/blog/error101.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;As of June 5, 2009, Cenzic can detect the &lt;a title="Apache Tomcat Denial of Service Vulnerability" href="http://www.securityfocus.com/bid/35193/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 35193&lt;/strong&gt;).&amp;nbsp;&amp;nbsp; Apache Tomcat is prone to a denial-of-service vulnerability.&amp;nbsp; Attackers can exploit this issue and cause the server to end up in an error state, denying service to legitimate users. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/35193/" target=%quot;_blank%quot;&gt;Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/234342</guid><pubDate>Fri, 05 Jun 2009 17:12:20 -0400</pubDate>
        <category>apache tomcat</category><category>cenzic</category><category>denial of service</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>SANSFire 2009: Learn Latest Web Security Trends</title><link>http://blog.cenzic.com/public/item/234300</link><description>Attend the SANSFire 2009 event in Baltimore to learn the latest Web security trends&lt;p&gt;It&amp;rsquo;s that time of year again &amp;ndash; June means you&amp;rsquo;ve got to attend the &lt;a title="SANSFire 2009 event in DC June 16-17" href="http://www.sans.org/sansfire09/event.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;2009 SANSFire event&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; to learn the latest trends in Web security.&amp;nbsp; If you&amp;rsquo;re in Baltimore, be sure to stop by the &lt;strong&gt;Cenzic booth #14&lt;/strong&gt;, as we&amp;rsquo;ll be giving away $50 AmEx gift cards, free Web security scans of your Website (up to 50 pages), and iTunes music.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;Oh, and we&amp;rsquo;re also sponsoring a lunch and learn &amp;ndash; eat while learning about the latest hacking techniques.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Event Details&lt;/strong&gt;&lt;br /&gt;SANSFire 2009, June 16-17, 2009&lt;br /&gt;&lt;a href="http://www.sans.org/sansfire09/event.php"&gt;&lt;strong&gt;&lt;u&gt;http://www.sans.org/sansfire09/event.php&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Venue&lt;/strong&gt;&lt;br /&gt;Hilton Baltimore&lt;br /&gt;401 West Pratt Street&lt;br /&gt;Baltimore, MD 21201 US&lt;br /&gt;Phone: 443-573-8700&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Vendor Expo&lt;/strong&gt;&amp;nbsp; &lt;br /&gt;Cenzic will be at &lt;strong&gt;Booth # 14&lt;/strong&gt;&lt;br /&gt;Tuesday, June 16: 12:00pm - 1:30pm and &lt;br /&gt;5:00pm - 7:30pm &lt;br /&gt;Wednesday, June 17: 7:00am - 8:30am * NEW TIME!&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Cenzic Lunch &amp;amp; Learn&lt;/strong&gt;&lt;br /&gt;12:30-1:15 pm on June 17 at Room Billie Holiday 5&lt;br /&gt;&lt;u&gt;Hacking 101: How Hackers Attack your Website and the Common Mistakes to Avoid&lt;/u&gt;&lt;/p&gt;&lt;p&gt;What are some of the latest attacks Hackers use to exploit Websites? With 400 new Web vulnerabilities a month (and growing) - you need to keep ahead of the hacker curve and address these attacks and security concerns head-on! &lt;/p&gt;&lt;p&gt;Attend this interactive Cenzic Lunch &amp;amp; Learn demo to see examples of some of the most complicated Web application attacks used by hackers, and learn the ways you can prevent hacker attacks.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.sans.org/sansfire09/event.php" target=%quot;_blank%quot;&gt;SANSFire 2009, June 16-17, 2009&lt;/a&gt;&lt;br/&gt;Attend this Baltimore event on Web security&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/234300</guid><pubDate>Thu, 04 Jun 2009 18:55:03 -0400</pubDate>
        <category>SANSFire 2009</category><category>web security</category>
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>