<?xml version="1.0" encoding="UTF-8" standalone="yes"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.cenzic.com/public/" version="2.0"><!--

MyST Blogsite® RSS Web Feed | Powered by MySmartChannels™ Weblog Application Server

MyST Blogsite and MySmartChannels are services of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com and http://blogsite.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters:

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)
  enhanced=true|false (default=false)
  limit=n (default=15)
  score=none|emoticon|simple|stars|text (default=text)
  smartPoints=true|false (default=true)
  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)
  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>What's New | Cenzic Security Blog</title><link>http://blog.cenzic.com/public/blog/202621</link><description>Recent Web application security news from Cenzic</description><atom:link type="application/rss+xml" rel="self" href="http://blog.cenzic.com/public/rss/202621?"/><language>en-us</language><copyright>Copyright (C) 2009 Cenzic, Inc--All Rights Reserved -- This channel is part of the Cenzic Security Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 01 May 2008 13:00:52 -0400</pubDate><lastBuildDate>Tue, 31 Aug 2010 17:29:32 -0400</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V6.00.0828)</generator><image><url>http://blog.cenzic.com/styles/blogsite/Cenzic/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.cenzic.com/public/blog/202621</link><title>What's New | Cenzic Security Blog</title><description>This blogsite contains information on all security topics ranging from web application security, security software, vulnerabilities, enterprise security, penetration testing and hacker news.</description></image>
       <category>Session management</category><category>Web application security</category><category>Security trends</category><category>Security report</category><category>Managed security</category><category>Risk assessment software</category><category>enterprise security management</category>
       
       
      
    
     <item><title>Reminder: OWASP AppSec USA Annual Conference Sep 9-10</title><link>http://blog.cenzic.com/public/item/258935</link><description>Sep 9-10 marks the annual OWASP AppSec USA event in Irvine, CA&lt;p&gt;Be sure to attend this year&amp;rsquo;s annual &lt;a title="OWASP annual conference in Irvine, CA" href="http://www.owasp.org/index.php/AppSec_US_2010,_CA#tab=September_9th" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;OWASP AppSec USA Conference next week on Sep 9-10 in Irvine, CA&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;In addition to the sand and palm trees, attend the latest presentations on application security from security experts representing companies like &lt;strong&gt;Adobe, Mozilla, and Boeing&lt;/strong&gt;.&amp;nbsp; &lt;/p&gt; &lt;p&gt;One presentation we&amp;rsquo;d like to highlight:&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;&amp;ldquo;Session Management Security Tips &amp;amp; Tricks&amp;rdquo;&lt;/strong&gt;&lt;br /&gt;by&lt;br /&gt;Lars Ewe, Cenzic CTO&lt;br /&gt;September 10 at 11:15 &amp;ndash; Noon&lt;br /&gt;Pacific Ballroom&lt;br /&gt;UC Irvine Conference Center&lt;br /&gt;Irvine, CA&lt;/p&gt; &lt;p&gt;We&amp;rsquo;ll see you in sunny California!&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.owasp.org/index.php/AppSec_US_2010,_CA#tab=September_9th" target=%quot;_blank%quot;&gt;OWASP AppSec USA Annual Conference&lt;/a&gt;&lt;br/&gt;Attend this application security conference in Irvine, CA&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258935</guid><pubDate>Tue, 31 Aug 2010 17:28:25 -0400</pubDate>
        <category>OWASP</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Hack Highlight: BP Websites Defaced via XSS Vulnerability</title><link>http://blog.cenzic.com/public/item/258899</link><description>BP online presence defaced via Cross Site Scripting (XSS) Vulnerability by hacking community &lt;p&gt;&lt;a href="http://praetorianprefect.com/archives/2010/06/going-after-bp/" target="_blank" title="BP online presence defaced via XSS"&gt;&lt;img vspace="10" hspace="10" align="right" src="http://www.cenzic.com/images/blog/bp_billionaire_polluters.jpg" alt="BP online presence defaced via XSS" /&gt;&lt;/a&gt;BP continues to be the subject of criticism following the Deepwater Horizon oil spill, as the &lt;b&gt;hacking community is taking umbrage to some of BP&amp;rsquo;s recent public relations activities&lt;/b&gt; in the online arena, such as a recent website defacement via Cross-Site Scripting (XSS).&amp;nbsp; &lt;/p&gt; &lt;p&gt;Specifically, reactions to BP&amp;rsquo;s having bought the sponsored link for the search term &amp;lsquo;oil spill&amp;rsquo; seems to have triggered resentment in the form of both &lt;a target="_blank" href="http://praetorianprefect.com/archives/2010/06/going-after-bp/" title="Hackers Going after BP"&gt;&lt;b&gt;&lt;u&gt;reconnaissance work, a Twitter account compromise, and an amusing cross site scripting vulnerability&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;. &lt;/p&gt; &lt;p&gt;According to the article, the XSS ought to be corrected, and dual factor authentication on VPN&amp;rsquo;s is kind of a must have at this point.&amp;nbsp; And BP should also undertake a security audit of their perimeter, web properties, online services used, and security policies.&amp;nbsp; &lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;b&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/b&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;b&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://praetorianprefect.com/archives/2010/06/going-after-bp/" target=%quot;_blank%quot;&gt;Going After BP&lt;/a&gt;&lt;br/&gt;BP online presence defaced via Cross Site Scripting (XSS) Vulnerability by hacking community&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258899</guid><pubDate>Mon, 30 Aug 2010 14:10:51 -0400</pubDate>
        <category>BP</category><category>XSS vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects a PHP Buffer Overflow Vulnerability</title><link>http://blog.cenzic.com/public/item/258843</link><description>Weekly product update – Cenzic detects a PHP Buffer Overflow Vulnerability&lt;p&gt;As of August 27, 2010 Cenzic now detects a &lt;a title="PHP Buffer Overflow Vulnerability" href="http://www.securityfocus.com/bid/42516/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PHP 'ibase_gen_id()' Function off-by-one Buffer Overflow Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 42516&lt;/strong&gt;).&amp;nbsp; PHP is prone to an off-by-one buffer-overflow vulnerability because it fails to perform boundary checks before copying user-supplied data to insufficiently sized memory buffers.&amp;nbsp;&amp;nbsp; A hacker can exploit this issue to execute arbitrary machine code in the context of the PHP process.&amp;nbsp; Failed exploit attempts will likely crash the web server, denying service to legitimate users.&amp;nbsp; &lt;strong&gt;PHP 5.3.3 is vulnerable&lt;/strong&gt;; other versions may also be affected.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/42516/info" target=%quot;_blank%quot;&gt;PHP 'ibase_gen_id()' Function off-by-one Buffer Overflow Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258843</guid><pubDate>Fri, 27 Aug 2010 15:35:06 -0400</pubDate>
        <category>buffer overflow</category><category>buffer overflow vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Hack Highlight: Twitter XSS Vulnerability Possibly Exploited by Turkish Hackers</title><link>http://blog.cenzic.com/public/item/258416</link><description>Cross Site Scripting (XSS) Vulnerability on Twitter exploited by Turkish Hackers&lt;p&gt;&lt;img hspace="10" alt="Twitter XSS Vulnerability Possibly Exploited by Turkish Hackers" vspace="10" align="right" src="http://www.cenzic.com/images/blog/Twitter-XSS-Vulnerability-Possibly-Exploited-by-Turkish-Hackers-1.jpg" /&gt;As part of our blog series on highlighting specific website attacks occurring in the real world, we&amp;rsquo;d like to highlight the popular vulnerability that hackers love to exploit:&amp;nbsp; &lt;strong&gt;Cross-Site Scripting (XSS).&lt;/strong&gt;&amp;nbsp; &lt;/p&gt; &lt;p&gt;Back in June 2010, a persistent &lt;a title="XSS vulnerability exploited by Turkish hackers on Twitter website" href="http://news.softpedia.com/news/Twitter-XSS-Vulnerability-Possibly-Exploited-by-Turkish-Hackers-145594.shtml" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Cross-Site Scripting Vulnerability (XSS) on Twitter&amp;rsquo;s website&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; was exploited by Turkish hackers to post a rogue status, &amp;ldquo;Hacked by Turkish Hackers&amp;rdquo;.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Twitter quickly fixed the vulnerability, but continues to suffer from bad press about a variety of hacks on their popular social network site.&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Mandeep Khera, CMO&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Mandeep@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Mandeep@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://news.softpedia.com/news/Twitter-XSS-Vulnerability-Possibly-Exploited-by-Turkish-Hackers-145594.shtml" target=%quot;_blank%quot;&gt;Twitter XSS Vulnerability Possibly Exploited by Turkish Hackers&lt;/a&gt;&lt;br/&gt;A Twitter cross-site scripting (XSS) vulnerability reported late last week was quickly fixed by the website's security staff.&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258416</guid><pubDate>Mon, 23 Aug 2010 19:55:13 -0400</pubDate>
        <category>Cross Site Scripting</category><category>Twitter</category><category>XSS</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects a Sun Java System Denial of Service Vulnerability</title><link>http://blog.cenzic.com/public/item/258357</link><description>Weekly product update – Cenzic detects a Sun Java System Denial of Service Vulnerability &lt;p&gt;&lt;img hspace="10" alt="Cenzic SmartAttack Update for Aug 20, 2010" vspace="10" align="right" src="http://www.cenzic.com/images/blog/binary_crossword.jpg" /&gt;As of August 20, 2010 Cenzic now detects a &lt;a title="Sun Java System Web Server Admin Interface Denial of Service Vulnerability" href="http://www.securityfocus.com/bid/41389/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Sun Java System Web Server Admin Interface Denial of Service Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 41389&lt;/strong&gt;).&amp;nbsp; Sun Java System Web Server is prone to a denial-of-service vulnerability.&amp;nbsp; An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Sun Java System Web Server 7.0 Update 7 is affected; other versions may also be vulnerable.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;br /&gt;&lt;/strong&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/41389/info" target=%quot;_blank%quot;&gt;Sun JAVA System Denial of Service Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258357</guid><pubDate>Fri, 20 Aug 2010 15:32:42 -0400</pubDate>
        <category>denial of service vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Hack Highlight: Session Management Vulnerability Exploited to Gain iPad User Information</title><link>http://blog.cenzic.com/public/item/258322</link><description>Hackers exploited a Session Management Vulnerability in the AT&amp;T’s network to gain iPad User information&lt;p&gt;&lt;img hspace="10" alt="Session Management Vulnerability expoited by hackers to gain iPad user information" vspace="10" align="right" src="http://www.cenzic.com/images/blog/ipad.jpg" /&gt;As part of our blog series on highlighting specific website attacks occurring in the real world, we&amp;rsquo;d be amiss if we didn&amp;rsquo;t mention the &lt;a title="session management vulnerability exploited by hackers to gain iPad users' info" href="http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=225701411&amp;amp;cid=RSSfeed" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;session management vulnerability that was exploited to gain iPad user information&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; back in June 2010.&lt;/p&gt; &lt;p&gt;A security flaw in AT&amp;amp;T's network exposed the e-mail addresses of more than &lt;strong&gt;100,000 owners of Apple's 3G iPad&lt;/strong&gt;. The security hole was uncovered by Goatse Security, a group known among security experts as hackers who enjoy pulling Web pranks. The group exploited a session prediction vulnerability which allowed the hackers to write a script to predict the iPad owners' unique identification numbers to obtain their e-mail addresses. &lt;/p&gt; &lt;p&gt;The list of exposed owners included &lt;strong&gt;New York Mayor Michael Bloomberg, White House Chief of Staff Rahm Emanuel&lt;/strong&gt; and other powerful figures in finance, media and politics. &lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Mandeep Khera, CMO&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Mandeep@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Mandeep@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.darkreading.com/database_security/security/app-security/showArticle.jhtml?articleID=225701411&amp;cid=RSSfeed" target=%quot;_blank%quot;&gt;AT&amp;T iPad Breaches Are About App Security, Not Mobile Devices, Experts Say&lt;/a&gt;&lt;br/&gt;According to analysts Session Management vulnerability exploited to gain iPad users? information&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258322</guid><pubDate>Thu, 19 Aug 2010 19:59:44 -0400</pubDate>
        <category>ipad</category><category>Session Management Vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Most Dangerous Internet Search? Cameron Diaz.</title><link>http://blog.cenzic.com/public/item/258307</link><description>Searching on the web for Cameron Diaz is risky business&lt;p&gt;Move over Jessica Biel, &lt;a title="Most dangerous Internet search? Cameron Diaz." href="http://www.cbsnews.com/8301-31749_162-20014084-10391698.html" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Cameron Diaz just made the number one spot for most risky Internet search&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; Searches related to Diaz are more likely to bring up sites linked to dangerous malware and spyware.&lt;/p&gt; &lt;p&gt;It&amp;rsquo;s the fastest and easiest ways to get you&lt;/p&gt; &lt;p&gt;By clicking on strange sites, it&amp;rsquo;s the fastest and easiest way to get your computer infected with malware.&amp;nbsp; Once a computer is infected, cyber criminals can steal victim&amp;rsquo;s sensitive information such as banking passwords, social security numbers, etc.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Consider yourself warned ;-)&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cbsnews.com/8301-31749_162-20014084-10391698.html" target=%quot;_blank%quot;&gt;Web Search for Cameron Diaz is Risky Business&lt;/a&gt;&lt;br/&gt;Most dangerous Internet search? Cameron Diaz.&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258307</guid><pubDate>Thu, 19 Aug 2010 14:49:27 -0400</pubDate>
        <category>cameron diaz</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>John Weinschenk, CEO of Cenzic Featured on Application Security MythBusters Series</title><link>http://blog.cenzic.com/public/item/258049</link><description>Watch this video on application security MythBusters featuring Cenzic CEO, John Weinschenk&lt;p&gt;&lt;a href="http://www.cenzic.com/resources/videos/mythbusters/?fn=weinschenk.flv" target="_blank" title="Video on application security mythbusters series featuring John Weinschenk"&gt;&lt;img vspace="10" hspace="10" align="right" src="http://www.cenzic.com/downloads/videos/mythbusters/weinschenk.flv.jpg" alt="Application Security MythBusters Series video: John Weinschenk" /&gt;&lt;/a&gt;As part of its Application Security MythBusters series, Cenzic &lt;a target="_blank" href="http://www.cenzic.com/resources/videos/mythbusters/?fn=weinschenk.flv" title="Application Security MythBusters Series video: John Weinschenk, CEO of Cenzic"&gt;&lt;b&gt;&lt;u&gt;interviewed John Weinschenk, President and CEO of Cenzic&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;When Cenzic&amp;rsquo;s Chief Marketing Officer, Mandeep Khera, asks John about the state of Web application security, he answers that despite the plethora&amp;nbsp;of hacking going on, people are still in denial about&amp;nbsp;their websites not being&amp;nbsp;secure.&amp;nbsp; Mr. Weinschenk believes that other security solutions like &lt;b&gt;SSL have a place&lt;/b&gt;, but they won&amp;rsquo;t protect sensitive data. &lt;/p&gt; &lt;p&gt;Watch the 4 minute video today!&lt;/p&gt; &lt;p&gt;If you have any other questions or topic suggestions about the latest myths out there, send an email to:&amp;nbsp; &lt;a href="mailto:MythBusters@cenzic.com"&gt;&lt;b&gt;&lt;u&gt;MythBusters@cenzic.com&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;b&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/b&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;b&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/resources/videos/mythbusters/?fn=weinschenk.flv" target=%quot;_blank%quot;&gt;Application Security MythBusters Series: Video of John Weinschenk, CEO of Cenzic&lt;/a&gt;&lt;br/&gt;Watch this 4 min video on Application Security MythBusters Series featuring John Weinschenk, CEO of Cenzic&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/258049</guid><pubDate>Mon, 16 Aug 2010 16:06:52 -0400</pubDate>
        <category>application security</category><category>mythbusters</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Adds New SmartAttack to Its Attack Library: Unrestricted File Upload</title><link>http://blog.cenzic.com/public/item/257785</link><description>Weekly product update – Cenzic adds 107th SmartAttack: Unrestricted File Upload&lt;p&gt;&lt;img hspace="10" alt="Unrestricted File Upload" vspace="10" align="right" src="http://www.cenzic.com/images/blog/smartattack_file-upload.jpg" /&gt;As of August 13, 2010 Cenzic created a brand new SmartAttack, &lt;strong&gt;Unrestricted File Upload&lt;/strong&gt;, bringing the total attack category library to &lt;strong&gt;107&lt;/strong&gt;.&amp;nbsp; The new SmartAttack checks various flaws present in the &amp;quot;file upload&amp;quot; functionality. Presence of these flaws may result in various attacks like Cross-Site Scripting, Malware hosting, etc. &lt;/p&gt; &lt;p&gt;Along in this weekly product update, Cenzic can also detect &lt;a title="PHP Multiple Vulnerabilities" href="http://www.securityfocus.com/bid/41991/references" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;PHP Multiple Vulnerabilities like Remote Code Execution, Unauthorized Access Attacks&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 41991&lt;/strong&gt;).&amp;nbsp; PHP is prone to multiple security vulnerabilities that an attacker can exploit to execute arbitrary code, crash the affected application, gain access to sensitive information, and bypass security restrictions.&amp;nbsp; Other attacks are also possible.&amp;nbsp; Versions PHP 5.3 (Prior to 5.3.3) and PHP 5.2 (Prior to 5.2.14) are affected.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/41991/references" target=%quot;_blank%quot;&gt;PHP Multiple Vulnerabilities like Remote Code Execution, Unauthorized Access Attacks&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/257785</guid><pubDate>Fri, 13 Aug 2010 14:22:36 -0400</pubDate>
        <category>php vulnerabilities</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Hack Highlight: Hackers Exploit SQL Vulnerability on Thousands of Websites</title><link>http://blog.cenzic.com/public/item/257751</link><description>Back in June 2010 hackers exploited a SQL vulnerability on thousands of websites&lt;p&gt;&lt;img hspace="10" alt="SQL Injection Vulnerability" vspace="10" align="right" src="http://www.cenzic.com/images/blog/binary_x.jpg" /&gt;This post will be the first among&amp;nbsp;many where we&amp;rsquo;ll highlight specific website attacks occurring in the real world.&amp;nbsp; In June 2010, hackers exploited a &lt;a title="SQL Vulnerability" href="http://threatpost.com/en_us/blogs/mass-sql-injection-attack-hits-sites-running-iis-061010" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;SQL vulnerability on more than 100,000 webpages&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;, including victims as diverse as The Wall Street Journal, TomTom, and the UK's Strathclyde police were hit by an attack that redirected visitors to a website that attempted to install malware on their machines. &lt;/p&gt; &lt;p&gt;The sites were infected using SQL injection exploits, which allow attackers to tamper with a server's database by typing commands into user-input fields. The hackers used the exploit to &lt;strong&gt;plant iframes in the compromised sites that redirected visitors to robint.us.&lt;/strong&gt;&amp;nbsp; Malicious JavaScript on that site attempted to infect end users with malware dubbed Mal/Behav-290.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Mandeep Khera, CMO&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Mandeep@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Mandeep@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://threatpost.com/en_us/blogs/mass-sql-injection-attack-hits-sites-running-iis-061010" target=%quot;_blank%quot;&gt;Mass SQL Injection Attack Hits Sites Running IIS&lt;/a&gt;&lt;br/&gt;Read more about this popular web attack that occurred in June 2010&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/257751</guid><pubDate>Thu, 12 Aug 2010 19:54:53 -0400</pubDate>
        <category>SQL vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>PCI Compliance Standard: No New Updates</title><link>http://blog.cenzic.com/public/item/257741</link><description>No new requirements proposed in v 2.0 of the PCI compliance security standard&lt;p&gt;The long-anticipated new version of the PCI Compliance Data Security Standard includes &lt;a title="No new requirements for the PCI Compliance standard" href="http://www.bankinfosecurity.com/articles.php?art_id=2838" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;no new requirements&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; - just clarifications and new guidance on existing components. &lt;/p&gt; &lt;p&gt;A more detailed summary of the proposed versions 2.0 of PCI DSS and PA DSS will be released in September, prior to the council's community meetings. The final version of the amended standards is expected to be released in October, and go into effect on January 11, 2011. &lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.bankinfosecurity.com/articles.php?art_id=2838" target=%quot;_blank%quot;&gt;PCI Updates Unveiled&lt;/a&gt;&lt;br/&gt;No New Requirements Proposed in Version 2.0 of Security Standard&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/257741</guid><pubDate>Thu, 12 Aug 2010 14:00:14 -0400</pubDate>
        <category>pci compliance</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Chenxi Wang from Forrester Research Featured on Application Security MythBusters Series</title><link>http://blog.cenzic.com/public/item/257723</link><description>Watch this video on application security MythBusters featuring Chenxi Wang of Forrester Research &lt;p&gt;&lt;a title="Chenxi Wang of Forrester Research featured on application security mythbusters series" href="http://www.cenzic.com/resources/videos/mythbusters/?fn=wang.flv" target="_blank"&gt;&lt;img hspace="10" alt="Chenxi Wang, Ph.D. of Forrester Research featured on application security mythbusters series" vspace="10" align="right" src="http://www.cenzic.com/downloads/videos/mythbusters/wang.flv.jpg" /&gt;&lt;/a&gt;As part of its Application Security MythBusters series, Cenzic interviewed &lt;a title="Chenxi Wang, Ph.D. from Forrester Research featured on application security mythbusters series" href="http://www.cenzic.com/resources/videos/mythbusters/?fn=wang.flv" target="_blank"&gt;&lt;b&gt;&lt;u&gt;Chenxi Wang, Ph.D., Principal Analyst at Forrester Research&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;When Cenzic&amp;rsquo;s Chief Marketing Officer, Mandeep Khera, asks Dr. Wang on her perspective about the state of Web application security, she answers in one word:&amp;nbsp; &lt;b&gt;abysmal&lt;/b&gt;.&amp;nbsp; According to this analyst, very few people even realize the dangers of working with so many unprotected web applications.&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;And as far as PCI compliance goes, Chenxi agrees that the regulation is a &lt;b&gt;great step forward&lt;/b&gt; towards a more secure Internet but on the flip side, it enables people to have a &lt;b&gt;&amp;ldquo;check box&amp;rdquo; mentality&lt;/b&gt;.&amp;nbsp; She suggests that every company should be continuously auditing their applications&amp;nbsp;and going deeper than the basic PCI compliance tests.&amp;nbsp; &lt;/p&gt; &lt;p&gt;And like other speakers on this video series, Dr. Wang believes more secure code training is needed in order to solve the problem at its root.&amp;nbsp; In the meantime, companies must spend money on fixing their applications.&lt;/p&gt; &lt;p&gt;Watch the 8 minute video today!&lt;/p&gt; &lt;p&gt;If you have any other questions or topic suggestions about the latest myths out there, send an email to:&amp;nbsp; &lt;a href="mailto:MythBusters@cenzic.com"&gt;&lt;u&gt;&lt;b&gt;MythBusters@cenzic.com&lt;/b&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;b&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/b&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;b&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/resources/videos/mythbusters/?fn=wang.flv" target=%quot;_blank%quot;&gt;Chenxi Wang of Forrester Research featured on application security mythbusters series&lt;/a&gt;&lt;br/&gt;Watch this exciting video today featuring Chenxi Wang, Ph.D. of Forrester Research on application security muthbusters series&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/257723</guid><pubDate>Wed, 11 Aug 2010 21:26:45 -0400</pubDate>
        <category>application security</category><category>itunes</category><category>mythbusters</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an Apache Information Disclosure Vulnerability &amp; Updates 1 SmartAttack™</title><link>http://blog.cenzic.com/public/item/257276</link><description>Weekly product update: Cenzic detects an Apache Information Disclosure Vulnerability &amp; updates 1 SmartAttack™&lt;p&gt;As of August 6, 2010 Cenzic now detects an &lt;a title="Apache Information Disclosure Vulnerability" href="http://www.securityfocus.com/bid/42102/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 42102&lt;/strong&gt;). &amp;nbsp;Attackers can leverage this issue to gain access to sensitive information that can aid in further attacks.&amp;nbsp; Apache 2.2.9 on Unix is vulnerable.&lt;/p&gt; &lt;p&gt;We also enhanced our &lt;strong&gt;Session ID in URL SmartAttack&lt;/strong&gt; so it can detect session ids that are stored in unconventional ways (e.g. in a URL path parameter).&amp;nbsp; This enhancement enables the SmartAttack to perform more accurately.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/42102/info" target=%quot;_blank%quot;&gt;Apache 'mod_proxy_http' 2.2.9 for Unix Timeout Handling Information Disclosure Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/257276</guid><pubDate>Fri, 06 Aug 2010 17:55:10 -0400</pubDate>
        <category>information disclosure vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>OWASP AppSec USA Annual Conference in Irvine, CA</title><link>http://blog.cenzic.com/public/item/257232</link><description>Attend this legendary OWASP AppSec USA event in Irvine, CA&lt;p&gt;&lt;img hspace="10" alt="OWASP AppSec USA 2010" vspace="10" align="right" src="http://www.cenzic.com/images/blog/owasp_appsec-usa-2010.jpg" /&gt;This year&amp;rsquo;s annual &lt;a title="OWASP AppSec USA Conference" href="http://www.owasp.org/index.php/AppSec_US_2010,_CA#tab=September_9th" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;OWASP AppSec USA Conference&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; is being held on the West coast for a change &amp;ndash; it will be a great time of year to visit southern California.&amp;nbsp; &lt;/p&gt; &lt;p&gt;So while you&amp;rsquo;re getting your fill of sun and palm trees, attend the latest talks&amp;nbsp;on application security from security experts&amp;nbsp;from Adobe, Mozilla, and Boeing.&amp;nbsp; &lt;/p&gt; &lt;p&gt;One presentation we&amp;rsquo;d like to highlight:&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Session Management Security Tips &amp;amp; Tricks&lt;/strong&gt;&lt;br /&gt;by&lt;br /&gt;Lars Ewe, Cenzic CTO&lt;br /&gt;&lt;strong&gt;September 10 at 11:15 &amp;ndash; Noon&lt;/strong&gt;&lt;br /&gt;Pacific Ballroom&lt;br /&gt;UC Irvine Conference Center&lt;br /&gt;Irvine, CA&lt;/p&gt; &lt;p&gt;We look forward to seeing you&amp;nbsp;in sunny California!&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.owasp.org/index.php/AppSec_US_2010,_CA#tab=September_9th" target=%quot;_blank%quot;&gt;OWASP AppSec USA Annual Conference&lt;/a&gt;&lt;br/&gt;Attend this application security conference in Irvine, CA&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/257232</guid><pubDate>Thu, 05 Aug 2010 21:36:22 -0400</pubDate>
        <category>OWASP</category><category>OWASP USA in Irvine</category>
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>