Securing Enterprise Applications - Cenzic Contact Us
Call 1-866-4-CENZIC (423-6942)
or email request@cenzic.com
cia_research

Get Better Security

graphic
spacer

CIA RESEARCH

Cenzic Intelligent Analysis (CIA) Research

The Cenzic Intelligent Analysis (CIA) team specializes in continuous research into application vulnerabilities and the latest tools and techniques used within the field of application security. The CIA team monitors the latest vulnerabilities and trends affecting application security by keeping watch over internet newsgroups, forums, mailing lists, and underground websites where vulnerability information is released. In addition to its research focus, CIA experts also perform vulnerability assessment, penetration testing, and security testing.

Cenzic has dedicated experts whose sole job is to perform ongoing research to find not only common vulnerabilities but also new or undisclosed vulnerabilities in custom, commercial, and open-source applications, and to make this information available to our customers and to the community at large in the form of publications and security alerts.

This section includes:

Security publications

Top Vulnerabilities

Alerts


Openness of Web Applications

Port 80 and 443 are wide open — do you know who's logged into your applications?

So, you have protected your perimeter by placing Intrusion Detection Systems, Firewalls, Anti-Virus, and other tools in your DMZ and internal network. Are you truly secure? Although network security is an important step toward a strong security posture, it's not nearly enough. It's like locking all the doors but putting the key under a transparent mat. Over 75% of attacks are occurring through Ports 80 and 443 (SSL), which are wide open.

The Problem

The problem is that corporate firewalls have to keep those ports to be open in order to do business online and interact with customers and partners. Unfortunately, cyber attackers exploit these open ports and wreak havoc. With numerous hacking tools readily available on line, even unsophisticated hackers can hack into your web applications.

The Solution

The solution is not to shut these ports down but to thwart attackers from causing harm once they have accessed your web site. Application vulnerabilities are big holes that are exploited by the crackers to attack your environment, which can result in embarrassment due to web defacement to major business disruption to loss of future business and brand.

Although most companies use security testing to find and fix flaws in their applications, the focus is still only on commonly known security vulnerabilities. Security vulnerabilities in custom web applications are often neglected, leaving companies totally exposed despite their best efforts.

Cenzic Hailstorm allows companies to find and fix not only known security vulnerabilities but also unknown vulnerabilities in their custom web applications. By enabling organizations to have a disciplined approach to vulnerability assessment and penetration testing, we give the power and control to our customers who can create a vulnerability management program for the entire software development lifecycle.

back to top
Technical Resources
> Datasheet: Hailstorm Enterprise ARC
> Datasheet: Hailstorm Pro
> Datasheet: Hailstorm Starter
> Datasheet: Hailstorm Core
> White Paper: Beyond Simple Vulnerabilities Scanning
> White Paper: Cross Frame Scripting
> White Paper: Cenzic Imperative Assessment Plan
> White Paper: Enabling Security in the Software Development Lifecycle (PDF)

web application security
Subscribe
From the Industry
Application security

COMPANY   |   PRODUCTS & SERVICES   |   SUPPORT   |   NEWS   |   CUSTOMERS   |   PARTNERS   |   CIA RESEARCH   |   CONTACT   |   LEGAL   |   PRIVACY   |   SITE MAP   |   HOME

© Copyright 2008 Cenzic