<?xml version="1.0" encoding="UTF-8" standalone="yes"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.cenzic.com/public/" version="2.0"><!--

MyST Blogsite® RSS Web Feed | Powered by MySmartChannels™ Weblog Application Server

MyST Blogsite and MySmartChannels are services of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com and http://blogsite.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters:

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)
  enhanced=true|false (default=false)
  limit=n (default=15)
  score=none|emoticon|simple|stars|text (default=text)
  smartPoints=true|false (default=true)
  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)
  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>What's New | Cenzic Security Blog</title><link>http://blog.cenzic.com/public/blog/202621</link><description>Recent Web application security news from Cenzic</description><atom:link type="application/rss+xml" rel="self" href="http://blog.cenzic.com/public/rss/202621?"/><language>en-us</language><copyright>Copyright (C) 2009 Cenzic, Inc--All Rights Reserved -- This channel is part of the Cenzic Security Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 01 May 2008 13:00:52 -0400</pubDate><lastBuildDate>Mon, 08 Feb 2010 16:48:31 -0500</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V6.00.0828)</generator><image><url>http://blog.cenzic.com/styles/blogsite/Cenzic/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.cenzic.com/public/blog/202621</link><title>What's New | Cenzic Security Blog</title><description>This blogsite contains information on all security topics ranging from web application security, security software, vulnerabilities, enterprise security, penetration testing and hacker news.</description></image>
       <category>Session management</category><category>Web application security</category><category>Security trends</category><category>Security report</category><category>Managed security</category><category>Risk assessment software</category><category>enterprise security management</category>
       
       
      
    
     <item><title>ISC2 Security Leadership Event</title><link>http://blog.cenzic.com/public/item/249748</link><description>Attend the ISC2 Security Leadership event tomorrow in San Jose, CA&lt;p&gt;If you happen to be in the heart of Silicon Valley on February 9, 2010, then attend the &lt;a title="ISC2 Leadership Event Feb 9, 2010" href="http://www.isc2.org/EventDetails.aspx?id=5644" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;ISC2 Security Leadership event&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; at the Double Tree Hotel in San Jose, CA.&amp;nbsp; &lt;/p&gt; &lt;p&gt;The all-day event (9-5 pm) will focus on how to measure your security success (or failure), so be prepared to hear ways you can explore methods for determining how well you&amp;rsquo;re managing the limited labor, capital, and technology resources.&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Event Details:&lt;/strong&gt;&lt;/p&gt; &lt;p&gt;ISC2 Security Leadership Seminar &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Title:&lt;/strong&gt;&amp;nbsp; Fact not FUD:&amp;nbsp; Managing What You Can Measure&lt;br /&gt;&lt;strong&gt;Date:&lt;/strong&gt;&amp;nbsp; Tuesday, February 9, 2010&lt;br /&gt;&lt;strong&gt;Time:&lt;/strong&gt;&amp;nbsp; 9 &amp;ndash; 5 PM&lt;br /&gt;&lt;strong&gt;Location:&lt;/strong&gt;&amp;nbsp; Double Tree Hotel in San Jose, CA&lt;/p&gt; &lt;p&gt;See you there tomorrow!&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.isc2.org/EventDetails.aspx?id=5644" target=%quot;_blank%quot;&gt;ISC2 Secure San Jose Event&lt;/a&gt;&lt;br/&gt;Attend this Security Leadership event on Feb 9, 2010&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249748</guid><pubDate>Mon, 08 Feb 2010 16:46:46 -0500</pubDate>
        <category>Security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cyber Security Predictions for the Next Decade</title><link>http://blog.cenzic.com/public/item/249747</link><description>Top 5 cyber security predictions for the upcoming decade&lt;p&gt;Enterprise Systems Magazine just published my top 5 cyber security predictions for the upcoming decade and I wanted to share them with you.&amp;nbsp; I hope you enjoy them &amp;hellip; and please send any comments my way as well.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Top 5 Cyber Security Predictions for the next 10 years:&lt;/strong&gt;&lt;/p&gt; &lt;ol&gt; &lt;li&gt;Despite government efforts, cyber war will be more common with more severe Web application attacks. We&amp;rsquo;ve been predicting cyber wars for a couple of years and have started to see significant incidents in 2009.&amp;nbsp; In addition, hackers will target telecommunications and utility infrastructures of key nations.&amp;nbsp;&lt;/li&gt; &lt;li&gt;Social network sites like Facebook and Twitter will continue to be targeted for attacks due to their popularity and usage.&amp;nbsp; Game changing social networking apps will emerge each with a unique set of security challenges.&amp;nbsp; Social networking will become even more prevalent as hackers go after these user bases looking for personal financial information to enable them to siphon money from bank accounts and credit cards.&amp;nbsp; Data from social networks will also give rise to increased identity theft as hackers sort through social networks to gather clues to unlock passwords and steal identities.&amp;nbsp;&lt;/li&gt; &lt;li&gt;The rise in Smartphone use, particularly the popularity of specific phones (i.e. the iPhone), begets an escalation in mobile app use as more and more people use phone apps to enhance both their business and personal worlds.&amp;nbsp; These downloadable apps will increasingly become a target for hackers who see millions of potential targets, most of which use a Web infrastructure for hackers to exploit.&amp;nbsp;&lt;/li&gt; &lt;li&gt;Cloud computing will become more prevalent as organizations try to optimize their infrastructure to streamline costs.&amp;nbsp; However, inherent security risks are synonymous with Cloud computing, as hackers will target Cloud providers.&amp;nbsp;&lt;/li&gt; &lt;li&gt;The collective security consciousness will be raised.&amp;nbsp; Businesses large and small will adopt technologies to secure their Websites, regulations will be developed, and fines increased. Universities will make security, especially application security, a mandatory requirement for all development courses and there will be more regulations around cyber security including increases in fines to companies found negligent along with more severe criminal punishment for hackers. Yet, hackers will also become more organized and sophisticated.&lt;/li&gt; &lt;/ol&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Mandeep Khera, CMO&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Mandeep@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Mandeep@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.esj.com/articles/2010/02/02/Cybersecurity-Past-and-Present.aspx" target=%quot;_blank%quot;&gt;Q&amp;A: Assessing Cybersecurity's Past, Planning for the Future&lt;/a&gt;&lt;br/&gt;How regulation, social networking, and popular technologies will impact enterprise security management&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249747</guid><pubDate>Mon, 08 Feb 2010 16:28:22 -0500</pubDate>
        
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects an Apache Integer Overflow Vulnerability</title><link>http://blog.cenzic.com/public/item/249608</link><description>Weekly product update – Cenzic detects an Apache Integer Overflow Vulnerability&lt;p&gt;As of February 5, 2010 Cenzic now detects an &lt;a title="Apache Integer Overflow Vulnerability" href="http://www.securityfocus.com/bid/37966/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37966&lt;/strong&gt;).&amp;nbsp; An attacker can exploit&amp;nbsp;the Apache remote integer overflow vulnerability&amp;nbsp;and execute arbitrary code.&amp;nbsp; Successful exploits will compromise affected computers.&amp;nbsp; Failed exploit attempts will result in a denial-of-service condition.&amp;nbsp; Note that this issue affects platforms on which 'sizeof(int)' is less than 'sizeof(long)'.&amp;nbsp; In particular, this occurs on some 64-bit architectures.&amp;nbsp; Versions prior to Apache 1.3.42 are vulnerable.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37966/info" target=%quot;_blank%quot;&gt;Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249608</guid><pubDate>Fri, 05 Feb 2010 15:49:36 -0500</pubDate>
        <category>apache vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>SANS Application Security 2010 Conference</title><link>http://blog.cenzic.com/public/item/249487</link><description>We hope to see you at the SANS Application Security 2010 Conference in San Francisco&lt;p&gt;I just got back from the cocktail reception that kicked off the &lt;a title="SANS 2010 Application Security Conference" href="https://www.sans.org/appsec-2010/summit.php#overview" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;SANS Application Security Conference&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; held at the Sheraton Fisherman&amp;rsquo;s Wharf Hotel in San Francisco this year.&amp;nbsp; &lt;/p&gt; &lt;p&gt;So stop tomorrow (Feb 4) for a free lunch at 12:30 PM in the President&amp;rsquo;s Ballroom and hear our esteemed CTO, Lars Ewe, present on &lt;strong&gt;&amp;ldquo;AJAX:&amp;nbsp; The Truth Behind the Hype&amp;rdquo;&lt;/strong&gt;.&amp;nbsp; Lars is also a panelist in the &lt;strong&gt;SANS vendor tools shootout&lt;/strong&gt; (along with IBM and Vericode) at 4:30 PM.&amp;nbsp; &lt;/p&gt; &lt;p&gt;&lt;strong&gt;Some of the things you&amp;rsquo;ll learn at the SANS Application Security Conference include:&lt;/strong&gt;&lt;/p&gt; &lt;ol&gt; &lt;li&gt;The essentials of a comprehensive Web site security program and how to secure a Website &lt;/li&gt; &lt;li&gt;The most current information on Web hacking techniques and how to guard against these prevalent Web vulnerabilities &lt;/li&gt; &lt;li&gt;Unique procurement practices that will help manage application security outsourcing and improve application security &lt;/li&gt; &lt;li&gt;The confessions of a professional Web application hacker &lt;/li&gt; &lt;li&gt;What your peers are doing to secure their Web applications and Web application best practices &lt;/li&gt; &lt;li&gt;What tools are available and how do they compare? Which tools should you have in your security toolbox to ensure your applications are locked up tight. &lt;/li&gt; &lt;/ol&gt; &lt;p&gt;Looking forward to seeing you there!&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://www.sans.org/appsec-2010/summit.php#overview" target=%quot;_blank%quot;&gt;SANS Security Summit&lt;/a&gt;&lt;br/&gt;Attend the Feb 4-5 SANS Security Summit held in San Francisco, CA&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249487</guid><pubDate>Wed, 03 Feb 2010 18:16:18 -0500</pubDate>
        <category>application security</category><category>SANS</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>2010 Cyber Security Expo</title><link>http://blog.cenzic.com/public/item/249429</link><description>Attend the 2010 Cyber Security in Washington DC today and tomorrow&lt;p&gt;February 2-3, 2010 marks the annual &lt;a title="2010 Cyber Security Event in DC" href="http://www.fbcinc.com/event.aspx?eventid=Q6UJ9A00LT7G" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Cyber Security Expo&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; in Washington DC this week.&amp;nbsp; So if you&amp;rsquo;re in town, stop by the &lt;strong&gt;Cenzic booth #52&lt;/strong&gt; and attend the show to learn about cyber security threats / vulnerabilities and defensive capabilities available.&amp;nbsp; The event is located at the Ronald Reagan Building &amp;amp; International Trade Center.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.fbcinc.com/event.aspx?eventid=Q6UJ9A00LT7G" target=%quot;_blank%quot;&gt;2010 Cyber Security Expo&lt;/a&gt;&lt;br/&gt;Attend this year's Cyber Security Expo event in DC&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249429</guid><pubDate>Tue, 02 Feb 2010 21:07:58 -0500</pubDate>
        <category>cyber security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects 3 Apache Tomcat Vulnerabilities</title><link>http://blog.cenzic.com/public/item/249243</link><description>Weekly product update – Cenzic detects 3 Apache Tomcat Vulnerabilities&lt;p&gt;As of January 29, 2010 Cenzic now detects 3 Apache Tomcat vulnerabilities in its product suite.&amp;nbsp; All of the vulnerabilities affect the following Apache versions: &lt;/p&gt; &lt;p&gt;Tomcat 5.5.0 through 5.5.28&lt;br /&gt;Tomcat 6.0.0 through 6.0.20&lt;/p&gt; &lt;ol&gt; &lt;li&gt;&lt;a title="Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability" href="http://www.securityfocus.com/bid/37942/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37942&lt;/strong&gt;)&lt;br /&gt;Apache Tomcat is prone to an authentication-bypass vulnerability.&amp;nbsp; An attacker can gain unauthorized access to files and directories. Successful exploits may lead to other attacks. &lt;/li&gt; &lt;li&gt;&lt;a title="Apache Tomcat WAR File Directory Traversal Vulnerability" href="http://www.securityfocus.com/bid/37944/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache Tomcat WAR File Directory Traversal Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (&lt;strong&gt;BugtraqID 37944&lt;/strong&gt;)&lt;br /&gt;Apache Tomcat is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.&amp;nbsp; Exploiting this issue allows attackers to delete or overwrite arbitrary files within the context of the webserver. &lt;/li&gt; &lt;li&gt;&lt;a title="Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability" href="http://www.securityfocus.com/bid/37945/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability&lt;/u&gt; &lt;/strong&gt;&lt;/a&gt;(&lt;strong&gt;BugtraqID 37945&lt;/strong&gt;),&lt;br /&gt;Apache Tomcat is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.&amp;nbsp; Exploiting this issue allows attackers to delete arbitrary files within the context of the current working directory. &lt;/li&gt; &lt;/ol&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37942/info" target=%quot;_blank%quot;&gt;Apache Tomcat Directory Host Appbase Authentication Bypass Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37944/info" target=%quot;_blank%quot;&gt;Apache Tomcat WAR File Directory Traversal Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37945/info" target=%quot;_blank%quot;&gt;Apache Tomcat Host Working Directory WAR File Directory Traversal Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249243</guid><pubDate>Fri, 29 Jan 2010 14:38:01 -0500</pubDate>
        <category>apache tomcat vulnerability</category><category>apache vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>OWASP, Risk, &amp; the Adult Film Industry</title><link>http://blog.cenzic.com/public/item/249240</link><description>What do the OWASP Bay Area chapter, risk, and the adult film industry have in common?&lt;p&gt;&lt;img alt="Lars at the Bay Area OWASP event Jan 2010" hspace="10" src="http://www.cenzic.com/images/blog/sans_conference_lars.jpg" align="right" vspace="10" /&gt;You don&amp;rsquo;t know what these 3 things have in common?&amp;nbsp; Are you serious?&amp;nbsp; Where do I start?&amp;nbsp; Long story short, I was looking for a funny way to introduce my presentation on application security risk at the &lt;strong&gt;Bay Area OWASP event&lt;/strong&gt; a couple of weeks ago.&amp;nbsp; After all it was late in the evening and I was seriously concerned that folks might fall asleep on me.&amp;nbsp; Never a very encouraging thing when you present.&amp;nbsp; In any event, after talking to some colleagues of mine prior to my presentation a great idea occurred to me (or so I thought at the time).&amp;nbsp; &lt;/p&gt; &lt;p&gt;So I informed the audience that I just returned from Cenzic&amp;rsquo;s 2010 sales kick off meeting at the Venetian Hotel in Las Vegas, NV which happened to coincide with the &lt;strong&gt;Adult Film Industry Conference&lt;/strong&gt;.&amp;nbsp; And all that visual stimulation gave me the idea to create my presentation slides on risk and how to &lt;strong&gt;&amp;ldquo;measure&amp;rdquo; risk &lt;/strong&gt;(get it?) and how Cenzic arrived at our HARM score (&lt;strong&gt;Hailstorm Application Risk Metric).&lt;/strong&gt;&amp;nbsp; &lt;/p&gt; &lt;p&gt;OK &amp;ndash; I&amp;rsquo;m the first one to admit, it was sort of cheesy.&amp;nbsp; But I was hoping they&amp;rsquo;d humor me with a few grunts of laughter instead of snoring.&amp;nbsp; All I got was crickets.&amp;nbsp; Then one hand rose out of the crowd and asked, &amp;ldquo;&lt;strong&gt;Were you in Vegas during the Consumer Electronics Show&lt;/strong&gt;?&amp;rdquo;&amp;nbsp; Hmm, so I guess the audience was way more easy than I had thought they&amp;rsquo;d be. No need to talk about what&amp;rsquo;s new in the adult film industry, just a good discussion around web application risk management. So my presentation wasn&amp;rsquo;t boring after all.&amp;nbsp; Glad I had such an easy audience. ;-) And I&amp;rsquo;m happy to say that I didn&amp;rsquo;t notice anybody snoring&amp;hellip; &lt;/p&gt; &lt;p&gt;In any event, if you&amp;rsquo;d like a copy of my &lt;strong&gt;slides on how Cenzic quantifies risk analysis&lt;/strong&gt; in Web applications, contact marketing for the PDF file (&lt;a href="mailto:eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;).&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Lars Ewe, CTO&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Lars@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Lars@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249240</guid><pubDate>Fri, 29 Jan 2010 13:26:36 -0500</pubDate>
        <category>adult film</category><category>OWASP</category><category>risk</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Adam Meyers, Sr Cyber Security Engineer at SRA International Featured on Application Security MythBusters Series</title><link>http://blog.cenzic.com/public/item/249211</link><description>Podcast on application security MythBusters featuring Adam Meyers&lt;p&gt;As part of its Application Security MythBusters series, Cenzic interviewed &lt;a title="Adam Meyers" href="http://www.scmagazineus.com/adam-meyers-principal-information-assurance-division-sra-international/article/146700/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Adam Meyers&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;, a security expert from SRA International.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;When Cenzic&amp;rsquo;s Chief Marketing Officer, Mandeep Khera, asks Adam about his general observation of the state of Web application security, he believes that awareness is improving, but gaps still exist.&amp;nbsp; &lt;/p&gt; &lt;p&gt;He agrees that all the following are the big myths in Web application security, including:&lt;/p&gt; &lt;ol&gt; &lt;li&gt;SSL is the &amp;quot;end all / be all&amp;quot; protection&amp;nbsp;against hacker attacks&amp;nbsp;&lt;/li&gt; &lt;li&gt;PCI Compliance is just a check box&lt;/li&gt; &lt;li&gt;You're&amp;nbsp;safe if your company has never&amp;nbsp;been hacked&amp;nbsp; &lt;/li&gt; &lt;li&gt;Application security is costly and extremely hard to implement &lt;/li&gt; &lt;/ol&gt; &lt;p&gt;Listen to the full 7.5 minute podcast today!&lt;/p&gt; &lt;p&gt;If you have any other questions or topic suggestions about the latest myths out there, send an email to:&amp;nbsp; &lt;a href="mailto:MythBusters@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;MythBusters@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/downloads/podcast/adam_meyers_2010.mp3" target=%quot;_blank%quot;&gt;Adam Meyers, Sr Cyber Security Engineer at SRA International Featured on Application Security MythBusters Series&lt;/a&gt;&lt;br/&gt;Listen to latest podcast in application security today&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.scmagazineus.com/adam-meyers-principal-information-assurance-division-sra-international/article/146700/" target=%quot;_blank%quot;&gt;Bio on Adam Meyers&lt;/a&gt;&lt;br/&gt;Learn more about this security expert&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249211</guid><pubDate>Thu, 28 Jan 2010 21:18:38 -0500</pubDate>
        <category>application security</category><category>application security mythbusters</category><category>podcast</category>
        
        
        
        
       
        <enclosure url="http://www.cenzic.com/downloads/podcast/adam_meyers_2010.mp3" length="4552623" type="audio/mp3"/>
        
        
        
        
       </item><item><title>Web Application Security Press for Cenzic</title><link>http://blog.cenzic.com/public/item/249205</link><description>Cenzic had a busy week in the press with lots of Web application security news&lt;p&gt;Cenzic issued 3 press releases this week, all focused on Web application security and celebrating today&amp;rsquo;s Data Privacy Day.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Monday featured our &lt;a title="Perfect Storm Cyber security" href="http://www.cenzic.com/pr_20100125/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;&amp;ldquo;Perfect Storm&amp;rdquo; story&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; on how cyber attacks will significantly increase due to the number of new applications using Web 2.0 technologies and vulnerabilities.&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;Cenzic announced on Tuesday that we&amp;rsquo;d scan any &lt;a title="No Website Left Behind" href="http://www.cenzic.com/pr_20100126/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;charitable Website collecting funds for Haiti relief&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;, extending our &amp;ldquo;No Website Left Behind&amp;rdquo; program.&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;And finally, as a way to celebrate today&amp;rsquo;s Data Privacy Day, we are offering a &lt;a title="Data Privacy Day" href="http://www.cenzic.com/pr_20100127/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;free Website &amp;ldquo;HealthCheck&amp;rdquo;&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; to any company who wants to test their security posture.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Here&amp;rsquo;s a summary of the releases &amp;ndash; we hope you take advantage of our offers soon.&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;strong&gt;January 27, 2010&lt;/strong&gt;&lt;br /&gt;Cenzic Offers Free Website &amp;quot;HealthCheck&amp;quot; In Support of Data Privacy Day &lt;/li&gt; &lt;li&gt;&lt;strong&gt;January 26, 2010&lt;/strong&gt;&lt;br /&gt;Cenzic Extends &amp;quot;No Website Left Behind&amp;quot; Program to Include Any Charitable Site Collecting Funds for Haiti Relief &lt;/li&gt; &lt;li&gt;&lt;strong&gt;January 25, 2010&lt;/strong&gt;&lt;br /&gt;&amp;quot;Perfect Storm&amp;quot; Forming for Cyberattacks in the Next Decade &lt;/li&gt; &lt;/ul&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/pr_20100125/" target=%quot;_blank%quot;&gt;"Perfect Storm" Forming for Cyberattacks in the Next Decade&lt;/a&gt;&lt;br/&gt;Web Application Security Will Grow to be a Bigger Area of Concern&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/pr_20100126/" target=%quot;_blank%quot;&gt;Cenzic Extends "No Website Left Behind" Program to Include Any Charitable Site Collecting Funds for Haiti Relief&lt;/a&gt;&lt;br/&gt;Haiti Relief Non-profits to Get Website Security Scans Free&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/pr_20100127/" target=%quot;_blank%quot;&gt;Cenzic Offers Free Website "HealthCheck" In Support of Data Privacy Day&lt;/a&gt;&lt;br/&gt;Application Security Assessment Identifies Security Holes In Websites and Provides Remediation Help&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249205</guid><pubDate>Thu, 28 Jan 2010 14:37:58 -0500</pubDate>
        <category>web application security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cost of a Data Breach: 2010 Ponemon Report</title><link>http://blog.cenzic.com/public/item/249107</link><description>Download 2010 Ponemon report on the latest cost of a data breach&lt;p&gt;The 2010 Ponemon Report was issued yesterday on the cost of a data breach and guess what &amp;hellip; that number just got larger:&amp;nbsp; from &lt;a title="2010 Ponemon Report Summary" href="http://www.bankinfosecurity.com/articles.php?art_id=2112" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;$6.6 million to $6.75 million&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; &lt;/p&gt; &lt;p&gt;For the entire 2009 year, malicious criminal attacks have doubled and the average cost of a data breach has increased from $202 to $204 per compromised record.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Download the &lt;a title="2010 Ponemon Report PDF" href="http://www.encryptionreports.com/" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;37 page PDF report today&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; and read all the dirty details yourself.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.bankinfosecurity.com/articles.php?art_id=2112" target=%quot;_blank%quot;&gt;Data Breach Report: Malicious Attacks Doubled in 2009&lt;/a&gt;&lt;br/&gt;Average Cost of a Breach is Now $204 Per Record&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.encryptionreports.com/" target=%quot;_blank%quot;&gt;2010 Ponemon Report - The Cost of a Data Breach&lt;/a&gt;&lt;br/&gt;Download the report here&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/249107</guid><pubDate>Tue, 26 Jan 2010 21:50:22 -0500</pubDate>
        <category>data breach</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects a Java System Web Server Remote Code Execution Vulnerability</title><link>http://blog.cenzic.com/public/item/248984</link><description>Weekly product update – Cenzic detects a Java System Web Server Remote Code Execution Vulnerability&lt;p&gt;As of January 22, 2010 Cenzic now detects a &lt;a title="Java System Web Server Remote Code Execution Vulnerability" href="http://www.securityfocus.com/bid/37641/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Java System Web Server Remote Code Execution Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37641&lt;/strong&gt;).&amp;nbsp; Sun Java System Web Server is prone to a remote code execution vulnerability.&amp;nbsp; Attackers can exploit this issue to execute code within the context of the affected application.&amp;nbsp; Sun Java System Web Server 7.0 Update 6 is vulnerable, however other versions may also be affected.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37641/info" target=%quot;_blank%quot;&gt;Java System Web Server Remote Code Execution Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/248984</guid><pubDate>Fri, 22 Jan 2010 14:20:29 -0500</pubDate>
        <category>java</category><category>web vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>RSA 2010: Web Security Coming Early</title><link>http://blog.cenzic.com/public/item/248983</link><description>Attend the annual RSA 2010 event to learn the latest in Web security&lt;p&gt;Occurring earlier than usual in the year, the &lt;a title="RSA 2010" href="http://www.rsaconference.com/index.htm" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;RSA 2010 event&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; commences on March 1-5, 2010 at the Moscone Center in San Francisco.&amp;nbsp; &lt;/p&gt; &lt;p&gt;Drop by the Cenzic booth &lt;strong&gt;(#2624)&lt;/strong&gt; for some literature, product demonstrations, and great conversation regarding Web security.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Angel@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Angel@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.rsaconference.com/index.htm" target=%quot;_blank%quot;&gt;RSA 2010 - Web Security Event&lt;/a&gt;&lt;br/&gt;Attend the annual Web security event of the year - RSA&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/248983</guid><pubDate>Fri, 22 Jan 2010 13:06:55 -0500</pubDate>
        <category>RSA 2010</category><category>web security</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Rob Pate, CISO of Renesys Featured on Application Security MythBusters Series</title><link>http://blog.cenzic.com/public/item/248859</link><description>Podcast on application security MythBusters featuring Rob Pate&lt;p&gt;As part of its Application Security MythBusters series, Cenzic interviewed Rob Tate, the CISO at Renesys.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;When Cenzic&amp;rsquo;s Chief Marketing Officer, Mandeep Khera, asks Rob about his general observation about the state of Web application security, he answers &amp;ldquo;poor&amp;rdquo;.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;Mr. Pate claims that poorly designed applications in the market space have led to a spike in data breaches.&amp;nbsp; Despite the industry moving in the right direction in terms of improved processes, there isn't much&amp;nbsp;light at the end of the tunnel.&amp;nbsp; &lt;/p&gt; &lt;p&gt;In order for middle managers to convice&amp;nbsp;upper management to provide adequate budget for Web application security, Mr. Pate suggests three things:&lt;/p&gt; &lt;ol&gt; &lt;li&gt;&lt;strong&gt;Education &lt;/strong&gt;&amp;ndash; everyone who has a vested interest in security needs to be properly educated about the risks inherent to Website security &lt;/li&gt; &lt;li&gt;&lt;strong&gt;Metrics &lt;/strong&gt;&amp;ndash; middle management must have a way to measure progress towards a security goal &lt;/li&gt; &lt;li&gt;&lt;strong&gt;ROI&lt;/strong&gt; &amp;ndash; once metrics are in place, an ROI is far easier to establish, or at the very least,&amp;nbsp;a decent case can be made for such investment dollars. &lt;/li&gt; &lt;/ol&gt; &lt;p&gt;Listen to the full 8 minute podcast today!&lt;/p&gt; &lt;p&gt;If you have any other questions or topic suggestions about the latest myths out there, send an email to:&amp;nbsp; &lt;a href="mailto:MythBusters@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;MythBusters@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson, Marketing&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/downloads/podcast/rob_pate_2010.mp3" target=%quot;_blank%quot;&gt;Rob Pate, CISO of Renesys Featured on Application Security MythBusters Series&lt;/a&gt;&lt;br/&gt;Listen to the latest podcast on application security&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.infragardmembers.org/modules/content/index.php?id=77" target=%quot;_blank%quot;&gt;Learn more about Rob Pate&lt;/a&gt;&lt;br/&gt;Bio on Rob Pate&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.renesys.com/about/management.shtml" target=%quot;_blank%quot;&gt;About Renesys management team&lt;/a&gt;&lt;br/&gt;Rob Pate, CISO at Renesys&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/248859</guid><pubDate>Tue, 19 Jan 2010 18:48:05 -0500</pubDate>
        <category>application security</category><category>podcast</category>
        
        
        
        
       
        <enclosure url="http://www.cenzic.com/downloads/podcast/rob_pate_2010.mp3" length="4623615" type="audio/mp3"/>
        
        
        
        
       </item><item><title>Web Seminar: Practical Web Application Pen Testing Kung Fu</title><link>http://blog.cenzic.com/public/item/248621</link><description>Attend this Web seminar hosted by PaulDotCom on Practical Web Application Pen Testing Kung Fu&lt;p&gt;&lt;img alt="PaulDotCom Web Seminar Jan 2010" hspace="10" src="http://www.cenzic.com/images/blog/pauldotcom.jpg" align="right" vspace="10" /&gt;If you are a Web application tech geek, then you&amp;rsquo;ve got attend this live Web Seminar on &lt;a title="PDC Pen Testing Kung Fu" href="https://www1.gotomeeting.com/register/290940024" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Pen Testing Kung Fu&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; presented by PaulDotCom.&amp;nbsp;&amp;nbsp; &lt;/p&gt; &lt;p&gt;In this event, John &amp;amp; Paul will help you perform more successful web application penetration testing. You&amp;rsquo;ll learn how to balance automated tools with manual testing, strike vulnerabilities with the highest chance of exploitation, and more!&amp;nbsp; Our own CTO and VP of Engineering, Lars Ewe, will also be a featured speaker.&lt;/p&gt; &lt;p&gt;So please attend!&lt;/p&gt; &lt;p align="left"&gt;Date:&amp;nbsp; &lt;br /&gt;&lt;strong&gt;Tuesday, January 26, 2010&lt;/strong&gt;&lt;/p&gt; &lt;p align="left"&gt;Time:&amp;nbsp; &lt;br /&gt;&lt;strong&gt;2:00 - 3:00 PM EST&lt;/strong&gt;&lt;/p&gt; &lt;p align="left"&gt;Register Here: &amp;nbsp;&lt;br /&gt;&lt;a href="https://www1.gotomeeting.com/register/290940024"&gt;&lt;strong&gt;&lt;u&gt;https://www1.gotomeeting.com/register/290940024&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="https://www1.gotomeeting.com/register/290940024" target=%quot;_blank%quot;&gt;Pen Testing Kung Fu&lt;/a&gt;&lt;br/&gt;PDC Web seminar on Pen Testing Kung Fu&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/248621</guid><pubDate>Mon, 18 Jan 2010 18:49:13 -0500</pubDate>
        <category>web application</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cenzic Detects a Java System Information Disclosure Vulnerability</title><link>http://blog.cenzic.com/public/item/248565</link><description>Weekly product update – Cenzic detects a Java System Information Disclosure Vulnerability&lt;p&gt;As of January 15, 2010 Cenzic now detects a &lt;a title="Sun JAVA Information Disclosure Vulnerability" href="http://www.securityfocus.com/bid/37648/info" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Sun Java System Web Server Information Disclosure Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 37648&lt;/strong&gt;).&amp;nbsp; The Sun Java System Web Server is prone to a remote information-disclosure vulnerability.&amp;nbsp; Attackers can exploit this issue to obtain potentially sensitive information that may aid in further attacks.&amp;nbsp; Sun Java System Web Server 7.0U6 is vulnerable, however other versions may also be affected.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to better detect &amp;quot;holes&amp;quot; in Web applications.&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt; &lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/37648/info" target=%quot;_blank%quot;&gt;Sun Java System Web Server Information Disclosure Vulnerability&lt;/a&gt;&lt;br/&gt;Learn more about this vulnerability on Security Focus&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/248565</guid><pubDate>Fri, 15 Jan 2010 17:33:35 -0500</pubDate>
        
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>