
CIA RESEARCH
Cenzic Intelligent Analysis (CIA) Research
The Cenzic Intelligent Analysis (CIA) team specializes
in continuous research into application vulnerabilities and the latest
tools and techniques used within the field of application security. The
CIA team monitors the latest vulnerabilities and trends affecting application
security by keeping watch over internet newsgroups, forums, mailing lists,
and underground websites where vulnerability information is released.
In addition to its research focus, CIA experts also perform vulnerability
assessment, penetration testing, and security testing.
Cenzic has dedicated experts whose sole job is to perform
ongoing research to find not only common vulnerabilities but also new
or undisclosed vulnerabilities in custom, commercial, and open-source
applications, and to make this information available to our customers
and to the community at large in the form of publications and security
alerts.
This section includes:
Security
publications
Top
Vulnerabilities
Alerts
| Openness of Web Applications
Port 80 and 443 are wide open
do you know who's logged into your applications?
So, you have protected your perimeter by
placing Intrusion Detection Systems, Firewalls, Anti-Virus, and
other tools in your DMZ and internal network. Are you truly secure?
Although network security is an important step toward a strong security
posture, it's not nearly enough. It's like locking all the doors
but putting the key under a transparent mat. Over 75% of attacks
are occurring through Ports 80 and 443 (SSL), which are wide open.
The Problem
The problem is that corporate firewalls
have to keep those ports to be open in order to do business online
and interact with customers and partners. Unfortunately, cyber attackers
exploit these open ports and wreak havoc. With numerous hacking
tools readily available on line, even unsophisticated hackers can
hack into your web applications.
The Solution
The solution is not to shut these ports
down but to thwart attackers from causing harm once they have accessed
your web site. Application vulnerabilities are big holes that are
exploited by the crackers to attack your environment, which can
result in embarrassment due to web defacement to major business
disruption to loss of future business and brand.
Although most companies use security testing
to find and fix flaws in their applications, the focus is still
only on commonly known security vulnerabilities. Security vulnerabilities
in custom web applications are often neglected, leaving companies
totally exposed despite their best efforts.
Cenzic Hailstorm allows companies to find
and fix not only known security vulnerabilities but also unknown
vulnerabilities in their custom web applications. By enabling organizations
to have a disciplined approach to vulnerability assessment and penetration
testing, we give the power and control to our customers who can
create a vulnerability management program for the entire software
development lifecycle. |

|