<?xml version="1.0" encoding="UTF-8" standalone="yes"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:atom="http://www.w3.org/2005/Atom" xml:base="http://blog.cenzic.com/public/" version="2.0"><!--

MyST Blogsite® RSS Web Feed | Powered by MySmartChannels™ Weblog Application Server

MyST Blogsite and MySmartChannels are services of MyST Technology Partners, Inc.
For more information, including standard terms of service, see:
http://myst-technology.com and http://blogsite.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Customize this feed by adding any of the following URL parameters:

  description=none|summary|full (default=full)
  channelDescription=none|summary|full (default=value of 'description' parameter)
  itemDescription=none|summary|full (default=value of 'description' parameter)
  enhanced=true|false (default=false)
  limit=n (default=15)
  score=none|emoticon|simple|stars|text (default=text)
  smartPoints=true|false (default=true)
  sortKey=CreateTime|ModifyTime|Name|...any MyST-ML child element... (default=CreateTime)
  sortOrder=ascending|descending (default=descending)
--><channel>
     <title>What's New | Cenzic Security Blog</title><link>http://blog.cenzic.com/public/blog/202621</link><description>The Latest Postings for Cenzic Security Blog</description><atom:link type="application/rss+xml" rel="self" href="http://blog.cenzic.com/public/rss/202621?"/><language>en-us</language><copyright>Copyright (C) 2008 Cenzic, Inc--All Rights Reserved -- This channel is part of the Cenzic Security Blog blogsite--Powered by MyST Blogsite®.</copyright><pubDate>Thu, 01 May 2008 13:00:52 -0400</pubDate><lastBuildDate>Fri, 05 Sep 2008 22:59:16 -0400</lastBuildDate><generator>MySmartChannels V3.0 (MyST Web Service Platform V5.00.0827)</generator><image><url>http://blog.cenzic.com/styles/blogsite/Cenzic/images/rss.jpg</url><height>31</height><width>88</width><link>http://blog.cenzic.com/public/blog/202621</link><title>What's New | Cenzic Security Blog</title><description>This blogsite contains information on all security topics ranging from web application security, security software, vulnerabilities, enterprise security, penetration testing and hacker news, to trends in the security industry.</description></image>
       <category>latest news</category><category>recent posts</category><category>Cenzic Security Blog</category>
       
       
      
    
     <item><title>PHP 5 'posix_access()' Function 'safe_mode' Bypass Directory Traversal Vulnerability</title><link>http://blog.cenzic.com/public/item/212320</link><description>Cenzic provides enhanced support for PHP 5 'posix_access()' Function 'safe_mode' Bypass Directory Traversal Vulnerability&lt;p&gt;Cenzic&amp;rsquo;s SmartAttack arsenal now has enhanced support for &lt;a href="http://www.cenzic.com/lib-updates/5.7j.php"&gt;&lt;strong&gt;&lt;u&gt;PHP 5 'posix_access()' Function 'safe_mode' Bypass Directory Traversal Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 29797&lt;/strong&gt;).&amp;nbsp; &lt;/p&gt;&lt;p&gt;To learn more details on how you can automatically update your Cenzic Hailstorm product, visit our &lt;a title="Cenzic SmartAttack homepage" href="http://www.cenzic.com/cia_research/lib-updates.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Website&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;br /&gt;&lt;/strong&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to use when it emulates a hacker and attacks our customer&amp;rsquo;s Websites to detect their security posture.&amp;nbsp;&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/lib-updates/5.7j.php" target=%quot;_blank%quot;&gt;Cenzic SmartAttack Library Updates&lt;/a&gt;&lt;br/&gt;Weekly updates made to Cenzic's product suite&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/212320</guid><pubDate>Fri, 05 Sep 2008 20:44:57 -0400</pubDate>
        <category>cenzic</category><category>PHP vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Visit Cenzic Booth #303 at the Forrester Security Forum</title><link>http://blog.cenzic.com/public/item/212194</link><description>Attending this week’s Forrester Security Forum in Boston? Then visit Cenzic booth #303.&lt;p&gt;If you are in Boston during September 4-5 and are attending &lt;a title="Forrester's Security Summit" href="http://www.forrester.com/events/eventdetail?eventID=2234" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Forrester&amp;rsquo;s Security Summit&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; at the Westin Waterfront Hotel, then stop by the Cenzic booth (&lt;strong&gt;#303&lt;/strong&gt;) for a chance to meet with analysts and audience members.&amp;nbsp; Forrester expects &lt;strong&gt;250-300 people to attend&lt;/strong&gt; tomorrow&amp;rsquo;s event.&amp;nbsp; And one of our favorite analysts, Chenxi Wang, Ph.D. will be speaking.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Here&amp;rsquo;s a summary of the Forrester event:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Conquer today's most difficult security threats.&lt;/strong&gt;&amp;nbsp; Learn how to manage risk as technologies such as Web 2.0, mobile computing, and virtualization disrupt standard security models.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Gain influence at the executive level.&lt;/strong&gt;&amp;nbsp; Develop processes that consistently align with business priorities and deliver measurable results.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Build operational risk, security, and compliance excellence.&lt;/strong&gt; &amp;nbsp;Meet current challenges and prepare for next-generation security threats by focusing on operational excellence. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Angel Oberoi&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:AOberoi@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;AOberoi@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.forrester.com/events/eventdetail?eventID=2234" target=%quot;_blank%quot;&gt;Forrester Security Forum 2008&lt;/a&gt;&lt;br/&gt;Learn more details about this week's Forrester Security Forum&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/212194</guid><pubDate>Wed, 03 Sep 2008 15:53:39 -0400</pubDate>
        <category>Cenzic</category><category>Forrester</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Apache Tomcat 'HttpServletResponse.sendError()' Cross-Site Scripting Vulnerability</title><link>http://blog.cenzic.com/public/item/212021</link><description>Cenzic provides enhanced support for Apache Tomcat 'HttpServletResponse.sendError()' Cross-Site Scripting Vulnerability&lt;p&gt;Cenzic&amp;rsquo;s SmartAttack arsenal now has enhanced support for &lt;a title="Cenzic SmartAttack library updates" href="http://www.cenzic.com/lib-updates/5.7i.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache Tomcat 'HttpServletResponse.sendError()' Cross-Site Scripting Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 30496&lt;/strong&gt;).&amp;nbsp; &lt;/p&gt;&lt;p&gt;By the way, this vulnerability marks a brand new SmartAttack that&amp;nbsp;Cenzic now supports:&amp;nbsp; &lt;strong&gt;LDAP Exception&lt;/strong&gt;.&amp;nbsp; &lt;/p&gt;&lt;p&gt;To learn more details on how you can automatically update your Cenzic Hailstorm product, visit our &lt;a title="Cenzic SmartAttack library updates" href="http://www.cenzic.com/cia_research/lib-updates.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Website&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to use when it emulates a hacker and attacks our customer&amp;rsquo;s Websites to detect their security posture.&amp;nbsp;&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;Have a great Labor Day Weekend, everyone!&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/lib-updates/5.7i.php" target=%quot;_blank%quot;&gt;Apache Tomcat 'HttpServletResponse.sendError Vulnerability&lt;/a&gt;&lt;br/&gt;SmartAttack Update for Apache Tomcat 'HttpServletResponse.sendError&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/cia_research/lib-updates.php" target=%quot;_blank%quot;&gt;Cenzic SmartAttack Library Updates&lt;/a&gt;&lt;br/&gt;Weekly updates made to Cenzic's product suite&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/212021</guid><pubDate>Fri, 29 Aug 2008 15:38:34 -0400</pubDate>
        <category>cross-site scripting</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>IDC White Paper on Application Security: No Room for False Positives</title><link>http://blog.cenzic.com/public/item/212019</link><description>Read white paper from IDC on the high costs of false positives in application security scanners&lt;p&gt;&lt;img alt="IDC White Paper on Web application security" hspace="10" src="http://www.cenzic.com/images/blog/IDCWhitePaper.jpg" align="right" vspace="10" border="0" /&gt;Get this informative white paper from IDC to see how false positives in application security scanners can costs organizations up to &lt;strong&gt;$25,000 for each application&lt;/strong&gt;.&amp;nbsp; And that doesn&amp;rsquo;t include the worse outcome.&amp;nbsp; When companies realize their products are yielding wildly inaccurate results, they usually discard Web application testing altogether.&amp;nbsp; And when that happens, the actual cost is immeasurable when a breach occurs. &lt;/p&gt;&lt;p&gt;I&amp;rsquo;m busy placing this white paper behind our usual Web registration form, but as a faithful Cenzic blog reader, you can get it by a simple email request.&amp;nbsp; I look forward to hearing from you.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/212019</guid><pubDate>Fri, 29 Aug 2008 14:34:40 -0400</pubDate>
        <category>application security</category><category>IDC</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Application Security: Free Software &amp; Evals from Cenzic</title><link>http://blog.cenzic.com/public/item/211919</link><description>Looking to secure your applications? Request an evaluation or get free software from Cenzic.&lt;p&gt;Secure your Web applications against Hacker attacks with Cenzic&amp;rsquo;s risk management solutions.&amp;nbsp; We go beyond signature-based technology to automatically find more *real* vulnerabilities fast.&amp;nbsp;&lt;/p&gt;&lt;p&gt;We&amp;rsquo;ve provided you with 4 free options to prove to you how quick and easy it is to protect your applications.&amp;nbsp; Request an evaluation of our enterprise or professional products or download our Core and Starter products.&amp;nbsp; See the comparisons below.&lt;/p&gt;&lt;p&gt;So take our products for a test drive &amp;ndash; what do you have to lose?&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;b&gt;Erin Swanson&lt;br /&gt;&lt;/b&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;b&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;table class="MsoTableGrid" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none; BORDER-COLLAPSE: collapse; mso-table-layout-alt: fixed; mso-border-alt: solid windowtext .5pt; mso-yfti-tbllook: 480; mso-padding-alt: 0in 5.4pt 0in 5.4pt; mso-border-insideh: .5pt solid windowtext; mso-border-insidev: .5pt solid windowtext" cellspacing="0" cellpadding="0" border="1"&gt;&lt;tbody&gt;&lt;tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes"&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: #b3b3b3; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 1.2in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-border-alt: solid windowtext .5pt" valign="top" width="115"&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: #b3b3b3; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 1in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" valign="top" width="96"&gt;&lt;p&gt;&lt;b&gt;&lt;a title="Cenzic Hailstorm ARC" href="https://www.cenzic.com/support/info_req_submit.php?product=arc" target="_blank"&gt;Hailstorm&amp;reg; Enterprise ARC&amp;trade;&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: #b3b3b3; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;&lt;b&gt;&lt;a title="Cenzic Hailstorm Pro" href="https://www.cenzic.com/support/info_req_submit.php?product=pro" target="_blank"&gt;Hailstorm&amp;reg; Professional&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: #b3b3b3; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;&lt;b&gt;&lt;a title="Cenzic Hailstorm Core" href="https://www.cenzic.com/forms/product.php?id=2" target="_blank"&gt;Hailstorm&amp;reg; Core&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: windowtext 1pt solid; PADDING-LEFT: 5.4pt; BACKGROUND: #b3b3b3; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;&lt;b&gt;&lt;a title="Cenzic Hailstorm Starter" href="https://www.cenzic.com/forms/product.php?id=3" target="_blank"&gt;Hailstorm&amp;reg; Starter&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 1"&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 1.2in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="115"&gt;&lt;p&gt;&lt;b&gt;Shared Database&lt;/b&gt;&lt;/p&gt;&lt;p /&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 1in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="96"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No (desktop only)&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No (desktop only)&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No (desktop only)&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 2"&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 1.2in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="115"&gt;&lt;p&gt;&lt;b&gt;Dashboard&lt;/b&gt;&lt;/p&gt;&lt;p /&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 1in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="96"&gt;&lt;p&gt;Full&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;Partial&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 3"&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 1.2in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="115"&gt;&lt;p&gt;&lt;b&gt;SmartAttacks&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 1in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="96"&gt;&lt;p&gt;Complete&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;Complete&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;Limited: 5 attacks&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;Limited: 1 attack&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 4"&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 1.2in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="115"&gt;&lt;p&gt;&lt;b&gt;Web UI&lt;/b&gt;&lt;/p&gt;&lt;p /&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 1in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="96"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 5"&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 1.2in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="115"&gt;&lt;p&gt;&lt;b&gt;Available for re-sale&lt;/b&gt;&lt;/p&gt;&lt;p /&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 1in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="96"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="mso-yfti-irow: 6"&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 1.2in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="115"&gt;&lt;p&gt;&lt;b&gt;User Admin&lt;/b&gt;&lt;/p&gt;&lt;p /&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 1in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="96"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="HEIGHT: 5.35pt; mso-yfti-irow: 7"&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 1.2in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="115"&gt;&lt;p&gt;&lt;b&gt;SmartAttack&amp;trade; Editor &lt;/b&gt;(editing capabilities)&lt;b&gt;&lt;/b&gt;&lt;/p&gt;&lt;p /&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 1in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="96"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;Yes&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr style="HEIGHT: 5.35pt; mso-yfti-irow: 8; mso-yfti-lastrow: yes"&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: windowtext 1pt solid; WIDTH: 1.2in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="115"&gt;&lt;p&gt;&lt;b /&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 1in; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="96"&gt;&lt;p&gt;&lt;a href="https://www.cenzic.com/support/info_req_submit.php?product=arc"&gt;&lt;stroke joinstyle="miter" /&gt;&lt;formulas /&gt;&lt;f eqn="if lineDrawn pixelLineWidth 0" /&gt;&lt;f eqn="sum @0 1 0" /&gt;&lt;f eqn="sum 0 0 @1" /&gt;&lt;f eqn="prod @2 1 2" /&gt;&lt;f eqn="prod @3 21600 pixelWidth" /&gt;&lt;f eqn="prod @3 21600 pixelHeight" /&gt;&lt;f eqn="sum @0 0 1" /&gt;&lt;f eqn="prod @6 1 2" /&gt;&lt;f eqn="prod @7 21600 pixelWidth" /&gt;&lt;f eqn="sum @8 21600 0" /&gt;&lt;f eqn="prod @7 21600 pixelHeight" /&gt;&lt;f eqn="sum @10 21600 0" /&gt;&lt;/formulas /&gt;&lt;u&gt;&lt;b&gt;Request Evaluation&lt;/b&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;&lt;a title="Cenzic Hailstorm Pro Eval" href="https://www.cenzic.com/support/info_req_submit.php?product=pro" target="_blank"&gt;&lt;b&gt;&lt;u&gt;Request Evaluation&lt;/u&gt;&lt;/b&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;&lt;a href="http://www.cenzic.com/forms/product.php?id=2"&gt;&lt;u&gt;&lt;b&gt;Download&lt;/b&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;td style="BORDER-RIGHT: windowtext 1pt solid; PADDING-RIGHT: 5.4pt; BORDER-TOP: #ece9d8; PADDING-LEFT: 5.4pt; PADDING-BOTTOM: 0in; BORDER-LEFT: #ece9d8; WIDTH: 81pt; PADDING-TOP: 0in; BORDER-BOTTOM: windowtext 1pt solid; HEIGHT: 5.35pt; BACKGROUND-COLOR: transparent; mso-border-alt: solid windowtext .5pt; mso-border-left-alt: solid windowtext .5pt; mso-border-top-alt: solid windowtext .5pt" valign="top" width="108"&gt;&lt;p&gt;&lt;a href="http://www.cenzic.com/forms/product.php?id=3"&gt;&lt;u&gt;&lt;b&gt;Download&lt;/b&gt;&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/p&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/211919</guid><pubDate>Wed, 27 Aug 2008 21:13:15 -0400</pubDate>
        <category>application security</category><category>cenzic</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Win Love in Rusia</title><link>http://blog.cenzic.com/public/item/211833</link><description>Russian hackers attack Georgian servers&lt;p&gt;This was the cryptic message found in HTTP, SYN, and ICMP floods against Georgian servers: &amp;quot;Win+love+in+Rusia.&amp;quot;&amp;nbsp; While I won&amp;rsquo;t comment in detail about the &lt;a title="Georgia Presidents web site under DDos attack from Russian hackers" href="http://blogs.zdnet.com/security/?p=1533" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;cyber attacks&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; I will say that at face value something seems wrong with that message. Russia is misspelled. With at least a correlation between the attacks and RBN owned addresses, clearly the attackers I believe know how to spell the name &amp;quot;Russia.&amp;quot; So I put the string through an anagram generator and got some interesting results, namely, &lt;strong&gt;&amp;quot;Rival Wise Union.&amp;quot;&lt;/strong&gt; &lt;/p&gt;&lt;p&gt;Am I 100% sure that this was a secret message embedded within the attacks? No. But it&amp;rsquo;s an interesting data point to be sure.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Tom Stracener&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Tom@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Tom@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://blogs.zdnet.com/security/?p=1533" target=%quot;_blank%quot;&gt;Georgia President's web site under DDoS attack from Russian hackers&lt;/a&gt;&lt;br/&gt;ZDNet Blog article on Russian hackers&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/211833</guid><pubDate>Tue, 26 Aug 2008 09:47:51 -0400</pubDate>
        <category>win love in rusia</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Apache Tomcat UTF-8 Directory Traversal Vulnerability</title><link>http://blog.cenzic.com/public/item/211640</link><description>Cenzic provides enhanced support for Apache Tomcat UTF-8 Traversal vulnerability&lt;p&gt;&lt;img alt="Apache Tomcat vulnerability added to Cenzic SmartAttack library" hspace="10" src="http://www.cenzic.com/images/blog/apache_tomcat.jpg" align="right" vspace="10" border="0" /&gt;Cenzic&amp;rsquo;s SmartAttack arsenal now has enhanced support for &lt;a title="Apache Tomcat UTE-8 Directory Traversal vulnerability" href="http://www.cenzic.com/lib-updates/5.7h.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache Tomcat UTF-8 Directory Traversal vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 30633&lt;/strong&gt;).&amp;nbsp; &lt;/p&gt;&lt;p&gt;To learn more details on how you can automatically update your Cenzic Hailstorm product, visit our &lt;a title="Apache Tomcat UTF-8 Directory Traversal vulnerability" href="http://www.cenzic.com/cia_research/lib-updates.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Website&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of product is updated with the latest vulnerabilities (custom, commercial, and open-source) to use when it emulates a hacker and attacks our customer&amp;rsquo;s Websites to detect their security posture.&amp;nbsp;&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/lib-updates/5.7h.php" target=%quot;_blank%quot;&gt;Apache Tomcat UTF-8 Directory Traversal vulnerability&lt;/a&gt;&lt;br/&gt;Cenzic SmartAttack now has Apache Tomcat UTF-8 Directory Traversal vulnerability&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/cia_research/lib-updates.php" target=%quot;_blank%quot;&gt;Cenzic SmartAttack Library Updates&lt;/a&gt;&lt;br/&gt;Weekly updates made to Cenzic's product suite&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/211640</guid><pubDate>Fri, 22 Aug 2008 15:04:48 -0400</pubDate>
        <category>apache tomcat</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Q2 2008 Trends Report from Cenzic</title><link>http://blog.cenzic.com/public/item/211522</link><description>Web application security trends report for Q2 2008 from Cenzic&lt;p&gt;Cenzic, the leading Web application security provider, released their &lt;a href="http://www.cenzic.com/cia_research/resources.php"&gt;&lt;strong&gt;&lt;u&gt;Q2 2008&amp;nbsp;Trends Report&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; on August 25.&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;Here&amp;rsquo;s a summary&amp;nbsp;of what the report entails.&lt;/p&gt;&lt;p&gt;Cenzic analyzed reported information for &lt;strong&gt;April 2008 through June 2008&lt;/strong&gt; from vulnerability sources such as SecurityFocus, CVE, SANS, USCERT, SecurityTracker, and other third party databases and found these top 10 vulnerabilities listed below.&amp;nbsp; Among the top 10 issues, the usual suspects like &lt;strong&gt;Adobe, IBM, Sun, and QuickTime&lt;/strong&gt; show the most vulnerabilities.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Top 10 Vulnerabilities for Q2 2008&lt;/strong&gt;&amp;nbsp; &lt;/p&gt;&lt;ol&gt;&lt;li&gt;Adobe Flash Player cross-site request forgery vulnerability&lt;/li&gt;&lt;li&gt;Adobe Flash Player DeclareFunction2 arbitrary code execution&amp;nbsp;&lt;/li&gt;&lt;li&gt;Bugzilla Cross-Site Scripting Vulnerability via &amp;lsquo;id&amp;rsquo; parameter&amp;nbsp;&lt;/li&gt;&lt;li&gt;QuickTime Heap Overflow in PICT file processing lets remote attackers execute arbitrary code&lt;/li&gt;&lt;li&gt;IBM Lotus Domino HTTP header buffer overflow&amp;nbsp;&lt;/li&gt;&lt;li&gt;Sun Java System Web Server Cross-Site Scripting&lt;/li&gt;&lt;li&gt;Quicktime AAC-Encoded media handling bug lets remote attackers execute arbitrary code.&amp;nbsp;&lt;/li&gt;&lt;li&gt;IBM Workspace vulnerabilities allow a remote attacker to conduct Cross-Site Scripting and Cross-Site Request Forgery.&lt;/li&gt;&lt;li&gt;Adobe Acrobat and Adobe Reader arbitrary code execution.&lt;/li&gt;&lt;li&gt;Sun Java System Access Manager allows remote code execution via malformed XML Signature&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Eswanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Eswanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/cia_research/resources.php" target=%quot;_blank%quot;&gt;Cenzic Quarterly Trends Reports&lt;/a&gt;&lt;br/&gt;Read the Cenzic quarterly trends reports&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/211522</guid><pubDate>Wed, 20 Aug 2008 22:31:10 -0400</pubDate>
        <category>Cenzic</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cross-Site Scripting v Blind SQL Injection: What’s More Harmful?</title><link>http://blog.cenzic.com/public/item/211430</link><description>In the battle of vulnerabilities, Cross-Site Scripting beats Blind SQL Injection every time&lt;p&gt;The most common question we get from customers and prospects alike is, &amp;ldquo;Why does Cross-Site Scripting beat Blind SQL Injection?&amp;rdquo;&amp;nbsp; In the the battle of vulnerabilities, Cross-Site Scripting will outweigh a gruesome database manipulation every time.&amp;nbsp; &lt;/p&gt;&lt;p&gt;As the person who created Cenzic&amp;rsquo;s HARM (Hailstorm Application Risk Metric) scoring system, let me start with the short answer:&amp;nbsp; &lt;strong&gt;Cross-Site Scripting is a vulnerability that you can do more with because it gives you more choices&lt;/strong&gt;.&amp;nbsp; You can spoof a form and steal login credentials; you can redirect the browser and trojan the browser or rootkit the machine; you can create a little iframe and steal information from the page; you can steal a session cookie and take over a user's session; and if you are really feeling lucky, you can redirect the user thorugh a reverse proxy and exploit a browser flaw to rewrite the address bar and slurp all the tasty details of their session.&amp;nbsp; Simply put: it presents more attack vectors.&amp;nbsp; Oh, and with a script source tag you can hijack the browser and create a browser zombie. &lt;strong&gt;Quantify that.&lt;/strong&gt; &lt;/p&gt;&lt;p&gt;I just created a white paper for all Cenzic customers on how I designed the Cenzic HARM scoring system, including algorithms and impact area weighting.&amp;nbsp; Nice and technical.&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;p&gt;So if you are a Cenzic customer, speak to Erin Swanson in Marketing (&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;) and provide her with your full contact information (including work email) and she&amp;rsquo;ll give you a copy. &lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Tom Stracener&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:Tom@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;Tom@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/211430</guid><pubDate>Tue, 19 Aug 2008 19:12:59 -0400</pubDate>
        <category>blind SQL injection</category><category>cross-site scripting</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability</title><link>http://blog.cenzic.com/public/item/211246</link><description>Cenzic provides enhanced support for Apache Tomcat SingleSignOn remote information disclosure vulnerability&lt;p&gt;Cenzic&amp;rsquo;s SmartAttack arsenal now has enhanced support for &lt;a title="Cenzic SmartAttack Library Updates" href="http://www.cenzic.com/lib-updates/5.7g.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache Tomcat SingleSignOn remote information disclosure vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 27365&lt;/strong&gt;).&amp;nbsp; &lt;/p&gt;&lt;p&gt;To learn more details on how you can automatically update your Cenzic Hailstorm product, visit our &lt;a title="Cenzic SmartAttack Library Updates" href="http://www.cenzic.com/cia_research/lib-updates.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Website&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of product is updated with the latest vulnerabilities (custom, commercial, and open-source) to use when it emulates a hacker and attacks our customer&amp;rsquo;s websites to detect their security posture.&amp;nbsp;&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/lib-updates/5.7g.php" target=%quot;_blank%quot;&gt;Apache Tomcat SingleSignOn remote information disclosure vulnerability&lt;/a&gt;&lt;br/&gt;Cenzic SmartAttack adds Apache Tomcat SingleSignOn remote information disclosure vulnerability&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/cia_research/lib-updates.php" target=%quot;_blank%quot;&gt;Cenzic SmartAttack Library Updates&lt;/a&gt;&lt;br/&gt;Weekly updates made to Cenzic's product suite&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/211246</guid><pubDate>Fri, 15 Aug 2008 20:39:06 -0400</pubDate>
        <category>Apache Tomcat SingleSignOn</category><category>Apache vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>BlackHat Vegas 2008 Capsule</title><link>http://blog.cenzic.com/public/item/211245</link><description>Summary of the recently held BlackHat event in Vegas&lt;p&gt;We had another successful BlackHat event this year - the Caesars Hotel hosted over &lt;strong&gt;5,000 attendees and a tons of sessions&lt;/strong&gt;.&amp;nbsp; The event keeps growing in popularity and organizers do a decent job of keeping everything under control.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Like last year, I didn't get a chance to attend too many sessions since most of my time was spent networking and talking to people which is usually more interesting anyway.&amp;nbsp; Some people commented to me that a lot of the sessions were similar to last year and there wasn't a lot of new content.&amp;nbsp; We can't be running out of content!&lt;/p&gt;&lt;p&gt;I did get a chance to attend the &lt;strong&gt;&amp;quot;Get Rich or Try Dying&amp;quot;&lt;/strong&gt; session by Jeremiah Grossman&amp;nbsp; and Trey Ford and&amp;nbsp; &lt;strong&gt;&amp;quot;Google Gadget Security&amp;quot;&lt;/strong&gt; by Tom Stracener of Cenzic and RSnake.&amp;nbsp; Both of these sessions were very well attended with standing room only and were very interesting. &lt;/p&gt;&lt;p&gt;The speaker party on Tuesday night (sponsored by Cenzic and Google) was very successful.&amp;nbsp; We had over &lt;strong&gt;300 attendees on the rooftop Penthouse suite&lt;/strong&gt;. After a few drinks, people even braved the 100 degrees temperature with high humidity.&amp;nbsp; I guess it goes with the territory -- when you are in the &lt;strong&gt;security world, you have to brave situations tougher than 100 degrees&lt;/strong&gt;. &lt;/p&gt;&lt;p&gt;Based on all my conversations, one revelation for me was that there are still a lot of companies who aren't doing anything for application security.&amp;nbsp; In fact, of the &lt;strong&gt;200+ people I talked to, over two-thirds of them are starting to look at app security now&lt;/strong&gt; and are hoping to have something in place by the end of the year.&amp;nbsp; &lt;/p&gt;&lt;p&gt;That means both bad and good news.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Bad news is that there are still millions of applications vulnerable and ripe for hackers.&amp;nbsp; Good news is that a lot of companies are starting to take steps toward securing their applications.&amp;nbsp; Whether it's driven by PCI or brand protection, we'll take good intentions in any shape or form.&amp;nbsp; Hopefully by next BlackHat, we'll be talking to people who have secured their apps and are talking about wireless or some other security issues. &lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Mandeep Khera&lt;/strong&gt;&lt;br /&gt;Chief Marketing Officer&lt;br /&gt;Cenzic, Inc.&lt;/p&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/211245</guid><pubDate>Fri, 15 Aug 2008 20:18:52 -0400</pubDate>
        <category>BlackHat</category><category>blackhat</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Got HP SPI Dynamics? Consider Cenzic.</title><link>http://blog.cenzic.com/public/item/211101</link><description>20/20 program for all HP SPI Dynamics customers to switch to Cenzic Hailstorm&lt;p&gt;&lt;a href="http://www.cenzic.com/c/2020"&gt;&lt;img height="238" alt="Got HP SPI? Consider Cenzic." hspace="10" src="http://www.cenzic.com/images/blog/eye_chart.gif" width="205" align="right" border="0" /&gt;&lt;/a&gt;If you are currently using HP SPI Dynamics for your Web application security needs, Cenzic is has a special &lt;a title="20/20 Program for HP SPI Dynamics customers switching to Cenzic Hailstorm" href="http://www.cenzic.com/c/2020" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;20/20 program&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;!&amp;nbsp; &lt;/p&gt;&lt;p&gt;We are so confident in our Web application security product (Cenzic Hailstorm) that we can guarantee finding &lt;strong&gt;20% more &amp;ldquo;real&amp;rdquo; vulnerabilities and render at least 20% less false positives&lt;/strong&gt; than HP SPI Dynamics.&amp;nbsp; &lt;/p&gt;&lt;p&gt;If we live up to this challenge,&amp;nbsp;we&amp;rsquo;ll give you a credit of&amp;nbsp;50% off&amp;nbsp;your original SPI purchase (up to $20,000) towards your new Cenzic Hailstorm solution. &lt;/p&gt;&lt;p&gt;If we don&amp;rsquo;t, then you&amp;rsquo;ll receive a &lt;strong&gt;complimentary Cenzic Hailstorm solution&lt;/strong&gt; (at no charge) for one person for one full year.&amp;nbsp; &lt;/p&gt;&lt;p&gt;Either way you win and get better vision into real Web application security.&amp;nbsp; &lt;/p&gt;&lt;p&gt;So what are you waiting for?&amp;nbsp; Fill in the &lt;a title="20/20 Program for HP SPI Dynamics customers wanting to switch to Cenzic Hailstorm" href="http://www.cenzic.com/c/2020" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Web registration form&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; to get Cenzic&amp;rsquo;s superior product today.&amp;nbsp; The longer you wait, the more susceptible you are to a hacker attack. &lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/c/2020" target=%quot;_blank%quot;&gt;Get 20/20 Vision into Web Application Security&lt;/a&gt;&lt;br/&gt;Swap out your inaccurate HP SPI Dynamics solution for Cenzic Hailstorm&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/211101</guid><pubDate>Thu, 14 Aug 2008 22:28:29 -0400</pubDate>
        <category>HP SPI Dynamics</category><category>SPI Dynamics</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Cross-Site Scripting Vulnerability for Apache ‘mod_proxy_ftp’ Wildcard Characters</title><link>http://blog.cenzic.com/public/item/211099</link><description>Cenzic provides enhanced support for cross-site scripting vulnerability&lt;p&gt;Cenzic&amp;rsquo;s SmartAttack arsenal now has enhanced support for &lt;a title="Cenzic SmartAttack Library weekly updates" href="http://www.cenzic.com/lib-updates/5.7f.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 30560&lt;/strong&gt;).&amp;nbsp; &lt;/p&gt;&lt;p&gt;To learn more details on how you can automatically update your Cenzic Hailstorm product, visit our &lt;a title="Cenzic SmartAttack library updates" href="http://www.cenzic.com/cia_research/lib-updates.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Website&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of product is updated with the latest vulnerabilities (custom, commercial, and open-source) to use when it emulates a hacker and attacks our customer&amp;rsquo;s websites to detect their security posture.&amp;nbsp;&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/lib-updates/5.7f.php" target=%quot;_blank%quot;&gt;Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability&lt;/a&gt;&lt;br/&gt;Cenzic SmartAttack library adds Apache Cross-Site Scripting Vulnerability&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/cia_research/lib-updates.php" target=%quot;_blank%quot;&gt;Cenzic SmartAttack Library Updates&lt;/a&gt;&lt;br/&gt;Weekly updates made to Cenzic's product suite&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/211099</guid><pubDate>Thu, 14 Aug 2008 21:24:40 -0400</pubDate>
        <category>cross-site scripting</category><category>cross-site scripting vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Get Application Security for $1500 from Cenzic</title><link>http://blog.cenzic.com/public/item/210475</link><description>Get application security for $1500 using Cenzic Hailstorm Core&lt;p&gt;&lt;a href="http://www.cenzic.com/forms/product.php?id=1"&gt;&lt;img alt="Purchase Cenzic Hailstorm Core for $1500" hspace="10" src="http://www.cenzic.com/images/blog/core_purchase.jpg" align="right" vspace="10" border="0" /&gt;&lt;/a&gt;If you want to have a great way to test your Web application security, then fill out the Web form&amp;nbsp;to &lt;a title="Purchase Cenzic Hailstorm Core for $1500" href="http://www.cenzic.com/forms/product.php?id=1" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;purchase our Cenzic Hailstorm Core product for $1500&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&amp;nbsp; It&amp;rsquo;s a great price for a single-user, Windows application that gives you a glimpse of the power of our Hailstorm product suite.&amp;nbsp; Core utilizes 5 different SmartAttack modules that assess your applications for common vulnerabilities.&amp;nbsp; These attacks include:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Cross site scripting&lt;/li&gt;&lt;li&gt;SQL error message&lt;/li&gt;&lt;li&gt;Application exception&lt;/li&gt;&lt;li&gt;Cookie vulnerabilities&amp;nbsp;&lt;/li&gt;&lt;li&gt;Web server vulnerabilities&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;So fill out the &lt;a title="Web form for Cenzic Hailstorm Core purchase" href="http://www.cenzic.com/forms/product.php?id=1" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Web form now&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; to receive an email with the link to download the product as well as the license key.&amp;nbsp; You&amp;rsquo;ll be able to start assessing your applications right away.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Jon Zucker, Product Management&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:JZucker@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;JZucker@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/forms/product.php?id=1" target=%quot;_blank%quot;&gt;Cenzic Hailstorm Core Purchase Page&lt;/a&gt;&lt;br/&gt;Purchase Cenzic Hailstorm Core for $1500&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/210475</guid><pubDate>Mon, 04 Aug 2008 17:03:41 -0400</pubDate>
        <category>application security</category><category>cenzic</category>
        
        
        
        
       
        
        
        
        
        
       </item><item><title>Web Server Vulnerability</title><link>http://blog.cenzic.com/public/item/210474</link><description>Cenzic provides enhanced support for Web server vulnerabilities&lt;p&gt;Cenzic&amp;rsquo;s SmartAttack arsenal now has enhanced support for &lt;a title="Cenzic SmartAttack Library" href="http://www.cenzic.com/lib-updates/5.7e.php" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Sun Java System Web Server Unauthorized Access Vulnerability&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt; (&lt;strong&gt;BugtraqID 22993&lt;/strong&gt;) that includes updates to our &lt;strong&gt;Form Caching&lt;/strong&gt;, &lt;strong&gt;Weak Password&lt;/strong&gt;, and &lt;strong&gt;Web Server Vulnerability&lt;/strong&gt; SmartAttacks.&amp;nbsp; &lt;/p&gt;&lt;p&gt;To learn more details on how you can automatically update your Cenzic Hailstorm product, visit our Website.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of product is updated with the latest vulnerabilities (custom, commercial, and open-source) to use when it emulates a hacker and attacks our customer&amp;rsquo;s websites to detect their security posture.&amp;nbsp;&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;h3&gt;See Also&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/lib-updates/5.7e.php" target=%quot;_blank%quot;&gt;Sun Java System Web Server Unauthorized Access Vulnerability&lt;/a&gt;&lt;br/&gt;Cenzic SmartAttack library adds Sun Java Web Server vulnerability&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.cenzic.com/cia_research/lib-updates.php" target=%quot;_blank%quot;&gt;Cenzic SmartAttack Library Updates&lt;/a&gt;&lt;br/&gt;Weekly updates made to Cenzic's product suite&lt;/li&gt;&lt;/ul&gt;</description><guid isPermaLink="true">http://blog.cenzic.com/public/item/210474</guid><pubDate>Mon, 04 Aug 2008 16:43:12 -0400</pubDate>
        <category>web server vulnerability</category>
        
        
        
        
       
        
        
        
        
        
       </item>
    </channel></rss>